Please forgive me if this is off-topic, I don't know anywhere else to ask for help. How does one get the attention of the abuse people at Xtra? A mailing list that I administer is being attacked by viruses that originate at a Jetstream address (details below). I sent email to abuse(a)xtra.co.nz a couple of days ago and have not had the courtesy of a response, not even a "sod off" answer, or even a bounce. The viruses come in batches from a consistent IP address - the address has changed a couple of times but I think it's the same infected machine because the messages have a consistent "look and feel". The received header looks like this: Received: from srunjn.com (210-86-89-213.jetstream.xtra.co.nz [210.86.89.213]) by [munged] with SMTP id iB1CGab26947; Thu, 2 Dec 2004 01:16:36 +1300 (NZDT) The envelope "from" appears to be randomly generated nonsense as it is different every time, but the originating IP address is consistent for each batch. The messages are designed to look like bounces from various ISPs and companies but in fact contain virus attachments. The latest originating address is 210.86.90.246, as at Sat, 4 Dec 2004 08:36:21 +1300 (NZDT) -- Lesley Walker, Wellington, New Zealand LRW(a)clear.net.nz http://home.clear.net.nz/pages/lrw http://walkinguphills.blogspot.com/
Have you called them? 0800 289 987 =========================================================== Quoting Original Message - On Sat, 04 Dec 2004 14:27, Lesley Walker wrote: | Please forgive me if this is off-topic, I don't know anywhere else to | ask for help. | | How does one get the attention of the abuse people at Xtra? A mailing | list that I administer is being attacked by viruses that originate at a | Jetstream address (details below). I sent email to abuse(a)xtra.co.nz a | couple of days ago and have not had the courtesy of a response, not | even a "sod off" answer, or even a bounce. <snip>
Andrew Walters wrote:
Have you called them? 0800 289 987
"If you are an existing Xtra customer, press 1" No, I'm not. "If you want to talk to a salesdroid, press 2" No, I don't. So I press 0. They know about that trick, and I get the same message again. I press various numbers, eventually get a "press 3 for anything else", so I press 3 and get a message saying there's going to be a long delay due the popularity of something or other. I don't have time for this nonsense! Anyone got a better number? -- Lesley Walker, Wellington, New Zealand LRW(a)clear.net.nz http://home.clear.net.nz/pages/lrw http://walkinguphills.blogspot.com/
Just press 1 then who ever takes the call can put you on to the right
person;)
Regards
Adam Fenech
www.dreamnet.co.nz
----- Original Message -----
From: "Lesley Walker"
Andrew Walters wrote:
Have you called them? 0800 289 987
"If you are an existing Xtra customer, press 1" No, I'm not. "If you want to talk to a salesdroid, press 2" No, I don't.
So I press 0. They know about that trick, and I get the same message again.
I press various numbers, eventually get a "press 3 for anything else", so I press 3 and get a message saying there's going to be a long delay due the popularity of something or other.
I don't have time for this nonsense! Anyone got a better number?
-- Lesley Walker, Wellington, New Zealand LRW(a)clear.net.nz http://home.clear.net.nz/pages/lrw http://walkinguphills.blogspot.com/
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
Lesley Walker wrote:
"If you are an existing Xtra customer, press 1" No, I'm not. "If you want to talk to a salesdroid, press 2" No, I don't.
So I press 0. They know about that trick, and I get the same message again.
;)
I press various numbers, eventually get a "press 3 for anything else", so I press 3 and get a message saying there's going to be a long delay due the popularity of something or other.
I don't have time for this nonsense! Anyone got a better number?
No, but try asking the person exhorting you to fire up Intarweb Exploder to check if your Bonzi Buddy is working to put you through to "Complex Support". Be prepared to wait for a while though. -- Juha
Anyone you speak to within Xtra Tech Support will tell you 'email logs to abuse(a)xtra.co.nz'. Noone you talk to over the telephone is going to give you real time support on a virus infection issue. The Possible Exception may be the Complex Tech Support team who are on 0800 BUSINESS (287 463). + tech support IVR option. They are however a tech team and not a security team, so don't be suprised if they give you the same canned response. Their security team do deal with all valid emails to abuse@ even if they don't acknowledge them directly. Also please bear in mind that nomatter what ISP is involved, all customers need time to be warned, and get fixed, before theyll have their accounts nuked. Its a tough call to take someone off the internet when their only hope is software that needs to be downloaded _from_ the internet... Disclaimer: I don't represent Xtra or Telecom or anyone else except yours truly. This is based on my experiences as an Xtra customer and someone who has reported virus to Xtra Abuse Team many times! PS: The 'Dial 0' trick is a cop out. With a company as big as Xtra, you can't realistically expect them to leave a Dial 0 option in there _and then_ expect to keep call durations down - you wont get the answer you want from a receptionist, will you?. If their support staff are busy, theyre busy. Sit on hold, try again later, or email them. (And hope that they realise their Queues are busy (and they will, theres enough software there tracking their Queue stats) and modify staffing levels as a result (also standard callcentre practise.) Mark. On Sat, 4 Dec 2004, Juha Saarinen wrote:
Lesley Walker wrote:
"If you are an existing Xtra customer, press 1" No, I'm not. "If you want to talk to a salesdroid, press 2" No, I don't.
So I press 0. They know about that trick, and I get the same message again.
;)
I press various numbers, eventually get a "press 3 for anything else", so I press 3 and get a message saying there's going to be a long delay due the popularity of something or other.
I don't have time for this nonsense! Anyone got a better number?
No, but try asking the person exhorting you to fire up Intarweb Exploder to check if your Bonzi Buddy is working to put you through to "Complex Support". Be prepared to wait for a while though.
-- Juha
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
Reporting-MTA: dns; desire.actrix.co.nz
Arrival-Date: Tue, 2 Nov 2004 10:42:16 +1300 (NZDT)
Final-Recipient: rfc822; abuse(a)xtra.co.nz
Action: failed
Status: 5.0.0
Diagnostic-Code: X-Postfix; host mta.xtra.co.nz[203.96.92.132] said: 550
Invalid recipient:
Their security team do deal with all valid emails to abuse@ even if they don't acknowledge them directly. Also please bear in mind that nomatter what ISP is involved, all customers need time to be warned, and get fixed, before theyll have their accounts nuked. Its a tough call to take someone off the internet when their only hope is software that needs to be downloaded _from_ the internet...
blakjak(a)babylon:~$ telnet smtp.xtra.co.nz 25
Trying 203.96.92.131...
Connected to smtp.xtra.co.nz.
Escape character is '^]'.
220 mta1-rme.xtra.co.nz ESMTP server ready Sat, 4 Dec 2004 17:55:38 +1300
helo xtra.co.nz
250 mta1-rme.xtra.co.nz
mail from: blakjak(a)mydomain
250 Sender
Reporting-MTA: dns; desire.actrix.co.nz Arrival-Date: Tue, 2 Nov 2004 10:42:16 +1300 (NZDT) Final-Recipient: rfc822; abuse(a)xtra.co.nz Action: failed Status: 5.0.0 Diagnostic-Code: X-Postfix; host mta.xtra.co.nz[203.96.92.132] said: 550 Invalid recipient:
(in reply to RCPT TO command) That's of course when the address is actually functioning.
Mark Foster wrote:
Their security team do deal with all valid emails to abuse@ even if they don't acknowledge them directly. Also please bear in mind that nomatter what ISP is involved, all customers need time to be warned, and get fixed, before theyll have their accounts nuked. Its a tough call to take someone off the internet when their only hope is software that needs to be downloaded _from_ the internet...
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
We (Massey Unversity) have been running an automated notification system for sometime now(only where the sender is a virus and the ip of origin is clearly identifiable and belongs to an NZ or Australian ISP). As one would expect, Xtra get a fair few notifications and I must admit that I was more than a little surprised to find that their 'abuse team' are the most responsive of all the ISPs in NZ !! They acknowledge the notifications by automated return mail and as each incident is closed we get a closure report. I spoke with them by phone when we were getting the system setup and they were very supportive and helpful. Most of the ISPs we send the notifications to are taking them seriously and do do something. Private companies that have no abuse, no postmaster address etc are proving to be a pain and there are quite a few of them. Glen.
On Sun, 2004-12-05 at 09:05 +1300, Glen Eustace wrote:
As one would expect, Xtra get a fair few notifications and I must admit that I was more than a little surprised to find that their 'abuse team' are the most responsive of all the ISPs in NZ !! They acknowledge the notifications by automated return mail and as each incident is closed we get a closure report. I spoke with them by phone when we were getting the system setup and they were very supportive and helpful.
I echo Glen's comments. As security officer for another large university I have had to deal with most of the NZ ISPs at one time or another and have always found Xtra's abuse folk responsive. I normally get an automated response on receipt and on the odd occasion that I have had to follow up I have had response on closure. As someone (Mark ?) pointed out don't expect anything to happen for a day or two. ISPs have to give customers a reasonable amount of time to get their act together before taking drastic action like suspending the account. Cheers, Russell --
On 4 Dec 2004, at 18:13, Russell Fulton wrote:
On Sun, 2004-12-05 at 09:05 +1300, Glen Eustace wrote:
As one would expect, Xtra get a fair few notifications and I must admit that I was more than a little surprised to find that their 'abuse team' are the most responsive of all the ISPs in NZ !! They acknowledge the notifications by automated return mail and as each incident is closed we get a closure report. I spoke with them by phone when we were getting the system setup and they were very supportive and helpful.
I echo Glen's comments. As security officer for another large university I have had to deal with most of the NZ ISPs at one time or another and have always found Xtra's abuse folk responsive. I normally get an automated response on receipt and on the odd occasion that I have had to follow up I have had response on closure.
And while we're taking time out from the scheduled shrieking about DSL pricing and allegations of anti-competitive behaviour to say good things about Telecom, I would like to mention that in my experience AS 4648 run one of the most contactable (and thereby useful) NOCs in New Zealand. They always answer the phone when I call them using INOC-DBA, and if I send them e-mail about something (whether on behalf of a customer or not) I get clueful responses from actual engineers in a pleasantly short period of time. If any Telecom netops people come to the NZNOG meeting in February, I hereby promise to buy them beer. Joe
Joe Abley wrote:
If any Telecom netops people come to the NZNOG meeting in February, I hereby promise to buy them beer.
It appears 2day.com is sponsoring dinner drinks, so we will pay for everybody elses beer :-) regards -- Peter Mott Chief Engineer 2DAY INTERNET LIMITED http://www.2day.com "It's kind of fun to do the impossible!" Walt Disney
I too am receiveing a large amount of viruses from xtra customers, a lot more
over the weekend than ever before... take a look at the averages (this is a
small mail server)...
Virus stats: http://ns.unix.co.nz/mrtg/virus/virus.html
Email flow: http://ns.unix.co.nz/mrtg/mesgs/mesgs.html
Current threat: Sober.j(a)MM virus
Spam / virus / clean: http://ns.unix.co.nz/~icepick/spamstats.png
The last link shows the amount of TRUE email that comes through, not much at
all.
Barry
Quoting Lesley Walker
Please forgive me if this is off-topic, I don't know anywhere else to ask for help.
How does one get the attention of the abuse people at Xtra? A mailing list that I administer is being attacked by viruses that originate at a Jetstream address (details below). I sent email to abuse(a)xtra.co.nz a couple of days ago and have not had the courtesy of a response, not even a "sod off" answer, or even a bounce.
The viruses come in batches from a consistent IP address - the address has changed a couple of times but I think it's the same infected machine because the messages have a consistent "look and feel".
The received header looks like this:
Received: from srunjn.com (210-86-89-213.jetstream.xtra.co.nz [210.86.89.213]) by [munged] with SMTP id iB1CGab26947; Thu, 2 Dec 2004 01:16:36 +1300 (NZDT)
The envelope "from" appears to be randomly generated nonsense as it is different every time, but the originating IP address is consistent for each batch.
The messages are designed to look like bounces from various ISPs and companies but in fact contain virus attachments.
The latest originating address is 210.86.90.246, as at Sat, 4 Dec 2004 08:36:21 +1300 (NZDT)
-- Lesley Walker, Wellington, New Zealand LRW(a)clear.net.nz http://home.clear.net.nz/pages/lrw http://walkinguphills.blogspot.com/
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
------------------------------------------------------------- This mail sent through UnixCo Webmail: http://www.unix.co.nz/
participants (11)
-
Andrew Walters
-
barry@unix.co.nz
-
Dream Net Internet
-
Glen Eustace
-
Joe Abley
-
Juha Saarinen
-
Lesley Walker
-
Mark Foster
-
Mike Cooper
-
Peter Mott
-
Russell Fulton