<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DoItQuick: Fast Domains for Dirty Deeds</title>
	<atom:link href="http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sun, 19 May 2013 00:39:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: John</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-97237</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 14 Aug 2012 22:24:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-97237</guid>
		<description><![CDATA[They might not be carded.  Registrars have the ability to test domains for a couple days.  Domain squatters use this frequently to test out new domains for traffic.]]></description>
		<content:encoded><![CDATA[<p>They might not be carded.  Registrars have the ability to test domains for a couple days.  Domain squatters use this frequently to test out new domains for traffic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-97003</link>
		<dc:creator>C</dc:creator>
		<pubDate>Mon, 13 Aug 2012 22:04:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-97003</guid>
		<description><![CDATA[FWIW, WHOIS for doitquick.net now leads to 

Registrant:
    N/A
    Dmitry Kunickiy        (javofasta@gmail.com)
    ul podlesnaya d.29
    Perm
    ,614097
    RU
    Tel. +7.9656018062]]></description>
		<content:encoded><![CDATA[<p>FWIW, WHOIS for doitquick.net now leads to </p>
<p>Registrant:<br />
    N/A<br />
    Dmitry Kunickiy        (javofasta@gmail.com)<br />
    ul podlesnaya d.29<br />
    Perm<br />
    ,614097<br />
    RU<br />
    Tel. +7.9656018062</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC.Tech</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-96974</link>
		<dc:creator>PC.Tech</dc:creator>
		<pubDate>Mon, 13 Aug 2012 19:56:25 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-96974</guid>
		<description><![CDATA[FYI...

Something evil on 178.63.195.128/26
- http://blog.dynamoo.com/2012/08/something-evil-on-1786319512826.html
&quot;...A look at the 178.63.195.128/26 range (178.63.195.128 - 178.63.195.191) shows several suspicious websites with domains apparently generated by -DoItQuick- ... quite a lot of suspect sites have recently been moved from this range to point at 127.0.0.1 instead, a common trick when malcious domains needs to be pointed somewhere else quickly.
The registrant for this block is:
inetnum: 178.63.195.128 - 178.63.195.191
address: RUSSIAN FEDERATION
178.63.195.163...
178.63.195.167...
178.63.195.168...
178.63.195.170...
178.63.195.171...&quot;
.]]></description>
		<content:encoded><![CDATA[<p>FYI&#8230;</p>
<p>Something evil on 178.63.195.128/26<br />
- <a href="http://blog.dynamoo.com/2012/08/something-evil-on-1786319512826.html" rel="nofollow">http://blog.dynamoo.com/2012/08/something-evil-on-1786319512826.html</a><br />
&#8220;&#8230;A look at the 178.63.195.128/26 range (178.63.195.128 &#8211; 178.63.195.191) shows several suspicious websites with domains apparently generated by -DoItQuick- &#8230; quite a lot of suspect sites have recently been moved from this range to point at 127.0.0.1 instead, a common trick when malcious domains needs to be pointed somewhere else quickly.<br />
The registrant for this block is:<br />
inetnum: 178.63.195.128 &#8211; 178.63.195.191<br />
address: RUSSIAN FEDERATION<br />
178.63.195.163&#8230;<br />
178.63.195.167&#8230;<br />
178.63.195.168&#8230;<br />
178.63.195.170&#8230;<br />
178.63.195.171&#8230;&#8221;<br />
.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-94242</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Fri, 03 Aug 2012 12:51:15 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-94242</guid>
		<description><![CDATA[But why would they just not by domains the normal way, through godaddy or something?

And also what on earth to card thieves do anyway, they cant buy anything because the bank tracks them, its not like they send stuff to their house do they, that would be madness.

Awesome job with the blog Brian.]]></description>
		<content:encoded><![CDATA[<p>But why would they just not by domains the normal way, through godaddy or something?</p>
<p>And also what on earth to card thieves do anyway, they cant buy anything because the bank tracks them, its not like they send stuff to their house do they, that would be madness.</p>
<p>Awesome job with the blog Brian.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-92118</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Wed, 25 Jul 2012 01:21:03 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-92118</guid>
		<description><![CDATA[DoltQuick?  So it&#039;s a service targeting ricers?]]></description>
		<content:encoded><![CDATA[<p>DoltQuick?  So it&#8217;s a service targeting ricers?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-92067</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Tue, 24 Jul 2012 17:24:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-92067</guid>
		<description><![CDATA[A carded domain, I believe, means they use a stolen credit card to register the domain name, which get revoked in short order when the stolen credit card&#039;s charges get reversed.

Since (as Brian has previously reported) credit cards are available in bulk for less than $5 each, a portion (large portion?) of the &quot;registration fee&quot; is going straight into the scammer&#039;s pocket.]]></description>
		<content:encoded><![CDATA[<p>A carded domain, I believe, means they use a stolen credit card to register the domain name, which get revoked in short order when the stolen credit card&#8217;s charges get reversed.</p>
<p>Since (as Brian has previously reported) credit cards are available in bulk for less than $5 each, a portion (large portion?) of the &#8220;registration fee&#8221; is going straight into the scammer&#8217;s pocket.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nic</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-92045</link>
		<dc:creator>Nic</dc:creator>
		<pubDate>Tue, 24 Jul 2012 16:43:16 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-92045</guid>
		<description><![CDATA[Exactly.  As noted, it&#039;s running on 127.0.0.1.  (But I enjoyed the attempted dig at my competence!) :-)

That said, I do believe almost everyone should block .su (the Soviet Union) in their resolvers, which is recommended by abuse.ch, one of the most respected sites in abuse.  It&#039;s an illegitimate TLD and an abuse factory.

http://www.abuse.ch/?p=3581

Small businesses would probably do well blocking all of .ru as well depending on their users and customer base.  Not possible for universities and other large networks.

I&#039;ve been blocking all of .ru since yesterday.  No bad interactions so far.]]></description>
		<content:encoded><![CDATA[<p>Exactly.  As noted, it&#8217;s running on 127.0.0.1.  (But I enjoyed the attempted dig at my competence!) <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>That said, I do believe almost everyone should block .su (the Soviet Union) in their resolvers, which is recommended by abuse.ch, one of the most respected sites in abuse.  It&#8217;s an illegitimate TLD and an abuse factory.</p>
<p><a href="http://www.abuse.ch/?p=3581" rel="nofollow">http://www.abuse.ch/?p=3581</a></p>
<p>Small businesses would probably do well blocking all of .ru as well depending on their users and customer base.  Not possible for universities and other large networks.</p>
<p>I&#8217;ve been blocking all of .ru since yesterday.  No bad interactions so far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michele</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-91959</link>
		<dc:creator>Michele</dc:creator>
		<pubDate>Tue, 24 Jul 2012 12:38:37 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-91959</guid>
		<description><![CDATA[$5 is way below the price charged by the registry, so I&#039;m not 100% sure how they could charge so little.. While it would be possible to use the AGP to get a refund on *some* domains, you couldn&#039;t use it that extensively]]></description>
		<content:encoded><![CDATA[<p>$5 is way below the price charged by the registry, so I&#8217;m not 100% sure how they could charge so little.. While it would be possible to use the AGP to get a refund on *some* domains, you couldn&#8217;t use it that extensively</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-91957</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Tue, 24 Jul 2012 12:31:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-91957</guid>
		<description><![CDATA[About double that. I believe the previous commenter is right: The black domains are carded; there really isn&#039;t any other explanation for domains that would be revoked in 2 days.]]></description>
		<content:encoded><![CDATA[<p>About double that. I believe the previous commenter is right: The black domains are carded; there really isn&#8217;t any other explanation for domains that would be revoked in 2 days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neej</title>
		<link>http://krebsonsecurity.com/2012/07/service-secures-domains-for-black-deeds/comment-page-1/#comment-91910</link>
		<dc:creator>Neej</dc:creator>
		<pubDate>Tue, 24 Jul 2012 08:10:43 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15751#comment-91910</guid>
		<description><![CDATA[$5 is a pretty decent price for a .org domain.  Just out of curiosity how much were the &quot;white&quot; domains going for?]]></description>
		<content:encoded><![CDATA[<p>$5 is a pretty decent price for a .org domain.  Just out of curiosity how much were the &#8220;white&#8221; domains going for?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 22/23 queries in 0.003 seconds using memcached
Object Caching 387/405 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-18 22:38:53 by W3 Total Cache -->