Great Circle Associates List-Managers
(January 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Tracing the ISP of (a Particularly Hideous) Subscriber
From: merlin @ netlink . co . uk (Darren Wyn Rees)
Date: Sat, 10 Jan 1998 01:57:51 GMT
To: List Managers <list-managers @ GreatCircle . COM>

I have a problem that mainly concerns a small 'culture' list I manage
(VALLEYS-L, on the South Wales Valleys). Here's a synopsis of the 
situation, roughly in chronological order :

* I received some pretty vicious materials by email (main themes of abuse :
references to drugs, blood, religion, and lots of psychobabble) a month and
a half ago.  The emails was in response to a message I posted to another
list (where I'm a subscriber) and I'm in the process of contacting that
lists owners to explain the situation. (I'm not sure of the other list
manager's obligations in this respect?)

* The abuser sends a message with sicko imagery... this time _to_ the list.
[Thank God] I was experimenting with the list at the time and it was only
open to subscribers to post... His message was bounced.

* I do not respond to a single one of his messages, so he takes his 
abuse elsewhere :

* A list-post of mine is sent to a newsgroup. This was no big deal .
However, he has also posted a lot of Usenet posts in the same newsgroup
that are quite libellous/provocative. This may affect people's perception
of the list (see below, for why it's difficult to respond to this critic)
in the long term... If people perceive that there's a nutter loose on a
list, then I do not think they would wish to join.

* I started getting v-e-r-y paranoid (this guy makes subtle references
that suggest he has done some research) changing passwords on accounts,
checking all logs in detail from past emails.  I discover that the Abuser
joined a list (it lasted 2 months, but fulfilled its role) I was involved
in early Summer, 1997... his email message to me gives me a 'lead' : The
originating IP Address comes from the Web Proxy Server of the biggest
British ISP, Demon.  Could it be spoofed/faked... I don't know, I have no
idea how clever this time-waster is, and it's too damned technical for me.

* He uses a Hotmail Com email address.  All his messages (except the one
from Demon) have this "X-Originating-IP: [209.75.196.2]" on it, or variants
on that.  A DNS reverse lookup gives "sol.infonex.com" and that suggests
the http://www.anonymizer.com.  They're sent via myriad.alias.net, when 
they go to Usenet.

* Contacted Hotmail Com but they've been soooo reluctant to do anything...
giving me some rubbish about "you didn't send all the Path headers in your
email to abuse@hotmail.com" which was not true as I quoted every single
iota of mail received from the Hotmail Customer.

* Contacted Demon Net Ltd... but they deny that this is from their
Customer.  Highly convenient for them, I daresay.

* I've used 'he' and 'guy' as I'm almost certain this is a male.  

Managing my list, my main worres are that the Abuser (i) could do the same
thing to other people on my list with possible legal repercussions for
myself (see iii); (ii) worryingly, has done this type of thing  before but
now is going a little more 'professional' (experimenting with a simple
web/'anon' interface for a Hotmail account; (iii) the VALLEYS-L list is
small, in its infancy, and this guy could really kill any growth potential;

(iv) time wasted dealing with this pest could be better spent experimenting
with a Majordomo/Linux platform to move my list to.

If this post is off-topic, or too long here then please accept my sincere
apologies.  I've read nearly _all_ the archives, especially with interest
the bits about methods/stategies of catching people who re-post list
material to Usenet et. al.

I really haven't got a clue where to start on this problem, so _any_ help
would be gratefully appreciated.  If you want precise details though, I
would rather that be by email.  At this stage, if I could prove that this
guy is posting from Demon Net Ltd., then the problem is solved because he's
broken their Acceptable Usage Policy and his account is terminated.

Sincerely, 	
-- 
Darren Rees	mailto:merlin@netlink.co.uk


Follow-Ups:
Indexed By Date Previous: List software
From: Fyodor <fygrave@freenet.bishkek.su>
Next: Re: Tracing the ISP of (a Particularly Hideous) Subscriber
From: Cyndi Norman <cnorman@best.com>
Indexed By Thread Previous: List software
From: Fyodor <fygrave@freenet.bishkek.su>
Next: Re: Tracing the ISP of (a Particularly Hideous) Subscriber
From: Cyndi Norman <cnorman@best.com>

Google
 
Search Internet Search www.greatcircle.com