• Re: URGENT: Security Compromise - DE-PEER novabbs.com infrastructure

    From Xavier M@xmendizabal@euskaltel.com to news.admin.peering on Wed Jul 9 05:46:43 2025
    From Newsgroup: news.admin.peering

    Richard Kettlewell wrote on Sat, 28 Jun 2025 10:14:37 +0100 :

    I don't peer with novabbs but I wouldn't disable a peer just because of
    an unauthenticated and unsupported claim on Usenet.

    May I ask a perhaps related question given in the past two days, someone/something has been spamming the crap out of the text newsgroups.

    Could it be related?

    It's tons of adobe product spam of binaries apparently, at least so far. <https://www.novabbs.com/interests/thread.php?group=alt.usage.english> <https://alt.usage.english.narkive.com/>

    Here's just one header.

    From: CPP <CPP-user@domain.com>
    Sender: CPP-user@domain.com
    Newsgroups: alt.tv.survivor,alt.usage.english,alt.usenet.kooks,alt.war.civil.usa,comp.lang.*,rec.arts.anime.misc,rec.autos.sport.f1,uk.rec.sheds
    Subject: (????) [1/7] - "Adobe Photoshop CC for Windows v25.7 with Free Tools.nzb" yEnc (1/1)
    Organization: Camelsystem
    X-Newsposter: Camelsystem Powerpost (Modified POWER-POST http://powerpost.camelsystem.nl)
    Lines: 79
    Message-ID: <uLibQ.495151$Ra5f.443045@fx13.iad>
    X-Complaints-To: abuse(at)newshosting.com
    NNTP-Posting-Date: Wed, 09 Jul 2025 00:31:22 UTC
    Date: Wed, 09 Jul 2025 00:31:22 GMT
    X-Received-Bytes: 10542
    X-Original-Bytes: 10490
    Xref: sewer alt.tv.survivor:17203 alt.usage.english:713140 alt.usenet.kooks:358676 alt.war.civil.usa:4517 rec.arts.anime.misc:5109 rec.autos.sport.f1:75975 uk.rec.sheds:204601


    --- Synchronet 3.21a-Linux NewsLink 1.2
  • From Urs =?UTF-8?Q?Jan=C3=9Fen?=@urs@akk.org to news.admin.peering on Wed Jul 9 11:53:53 2025
    From Newsgroup: news.admin.peering

    In Xavier M <xmendizabal@euskaltel.com> wrote:
    May I ask a perhaps related question given in the past two days, someone/something has been spamming the crap out of the text newsgroups. Could it be related?

    look at the Path-header of the article -> no

    | Path: ...!border-4.nntp.ord.giganews.com!border-1.nntp.ord.giganews.com!nntp.giganews.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx13.iad.POSTED!not-for-mail
    --- Synchronet 3.21a-Linux NewsLink 1.2