Hello Andy,
On 31/12/12 16:51, Andy Smith wrote:
Hi Jan,
On Mon, Dec 31, 2012 at 04:47:45PM +0000, Jan Henkins wrote:
Hmm... Whois against
nss365.com comes up with
something interesting.
A small excerpt:
nns365.com
Registrant Contact Information :
Private
Registration
WhoisGuardService.com
nns365.com(a)whoisidprotected.com
Tian Hong Shan Zhuang, BLd. 7, Office 104
Nanjing
210049
86 2584752362
86 2584752360
One can start following the breadcrumbs from there and come up with
something that looks perhaps a little bit suspicious... :-/
What do you consider
suspicious? Privacy WHOIS addresses are very
common.
za.net has one, for example.
Privacy WHOIS addresses are not the issue. Weird DNS behaviour and
pointers to countries like China is enough to make me suspicious enough
to start digging around a bit. The fact that Gavin saw
ns1.nns365.com
and
ns2.nns365.com being used instead of (
ns1.csiplhosting.net and
ns2.csiplhosting.net, as well as the fact that I cannot replicate it at
this very point in time, makes me rather curious as to what happened at
the time Gavin had his problems.
--
Regards,
Jan Henkins