Live data from Hacker News

Sinkholed

susam.in

21–30 of 135 posts

Re: Sinkholed

#21
Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network.

I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing popped up, so I'm pretty sure nothing infected my devices.

Still, I wonder if I ended up hitting the sinkhole, Virgin was somehow notified and this triggered their email? Or maybe it's just a complete coincidence.

Edit: Sure looks like Virgin works with Shadowserver: https://www.ukfast.co.uk/it-security-news/virgin-media-to-in...

Re: Sinkholed

#23
post #21

Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network. I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing…

That is the purpose of sinkholes. That's why you don't just change the DNS record to 127.0.0.1 (or similar) - you want to log the traffic that you're seeing so that you know who is infected and can help them.

I'm unaware of this particular international cooperation arrangement but it's great to see.

Re: Sinkholed

#25
post #14
post #8

Earlier quoted context omitted.

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time. In fact, I appreciate the…

Yes, I get that the Shadowserver Foundation does good work. And that they acted quickly, after being pointed to your tweet.

However, if your tweet hadn't gotten traction, and if Namecheap hadn't been proactive, you'd likely have never gotten the domain back. I mean, you had the Namecheap CEO on the case! And for a business losing a domain like that, it'd probably be fatal.

I get that many think that Americans are hugely too litigious. But there is the argument that there ought to be compensation for damages.

You say that "[t]he primary loss I suffered was in terms of time". But arguably your time is worth something. Such as your customary billing rate, times three.

Edit: Or just send them an invoice. At perhaps 50% over your customary billing rate, given that it was a rush job.

Re: Sinkholed

#26
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

the server is down it seems

https://github.com/susam/susam.in/commit/91405150ff3f44fd094...

Re: Sinkholed

#27
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This was a really good write up, thank you. And congratulations on getting your domain back.

Re: Sinkholed

#28
post #13
post #8

Earlier quoted context omitted.

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Yes, sue them, and incentivize a worse, slower (because lawyers involved) and less transparent resolution of errors.

[deleted]

Re: Sinkholed

#29
post #23
post #21

Interesting. I noticed that the blog post mentions the Nymaim malware family. I read about Susam's case when it hit Twitter the other day and might have even followed a link to his URL. Then a few days later got an email from my ISP Virgin Media claiming they'd detected Nymain on my home network. I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing…

That is the purpose of sinkholes. That's why you don't just change the DNS record to 127.0.0.1 (or similar) - you want to log the traffic that you're seeing so that you know who is infected and can help them. I'm unaware of this particular international cooperation arrangement but it's great to see.

Yup. Looks like the system is working pretty well. Plus I'm pretty happy that I've got an explanation for the email I got!

Re: Sinkholed

#30
post #9

Earlier quoted context omitted.

The FBI and analogous TLAs do this all the time. And generally, there's no recourse. In many cases, sites have resorted to distributing their IP addresses.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

The National Internet Exchange of India shouldn't be a foreign entity for holders of .in domains.
Post reply on HN