Home
Home

Directory
Directory

Articles
Internet News
Security News
Ecommerce News
Domain News

Site Tools
Site Speed Test
Keyword Research
Resolve Hostname
DNS Tools
Register Domains
Affiliate Programs
Open Source

Shopping Carts
Cart Reviews
SSL Certificates

Enter your email address to subscribe to our updates:

Delivered by FeedBurner


Venue Charts
Channel Traffic Rankings
OAI Stock Quotes and Charts
eBay's Worst Feedback

Forum
Forum Home
TulipTools News
Advertising
Blogging
Computer Hardware
Domain Names
Ecommerce
Financing
Int'l Trading
Graphics and HTML
Internet Access
Legal Issues
Internet Business
Auction Sites
Classified Ad Sites
Fixed Price Venues
Operating Systems
Programming
Search Engines
Internet Security
Software
Web Hosting
Webmaster Issues
Reviews
Announcements
Off Topic Discussion

Web Hosting
TulipHosting

Domain Names
TulipDomains

Web Stats
TulipStats

Forum Rules
Forum Rules
Privacy Policy

Site Map
Forum Sitemap
Sitemap Topics




Directory| Forums| Internet News|Cart Reviews| DNS Tools| Keyword Research| Site Speed Test| Security| | Domain Marketplace| Domain Blog
TulipTools Internet Business Owners and Online Sellers Community
  • Home
  • Search
  • Member List
  • Calendar
Hello There, Guest! Login Register
TulipTools Internet Business Owners and Online Sellers Community › Security › Internet Security › SSL Certificates
Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates

  
Threaded Mode | Linear Mode
Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
09-05-2010, 08:21 PM, (This post was last modified: 09-05-2010, 10:28 PM by regic.)
Post: #1
regic Offline
Administrator
*******
Posts: 2,825
Joined: Jul 2005
Reputation: 0
Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
recommendation: do not buy an SSL certificate, or any service from the spammers at Comodo / PositiveSSL / InstantSSL

We received a total of 31 spam emails (subject line: "SSL CERTIFICATE IS EXPIRING. GET A NEW SSL FOR $...")  from the spammers at Comodo / PositiveSSL /InstantSSL   this weekend advertising their PositiveSSL SSL certificates ....and did I mention the 40 plus spam emails we received from them in August, or the countless unsolicited sales calls from them? 

They're sending their spam emails  to email addresses like mail@..., admin@... etc. that w've never even used.  Their spam sales calls are being made to our store's customer service phone numbers (which is not the same phone number as the domain contact phone number listed on the WHOIS records of the sites they've spammed).

We've never done business with Comodo or any company affiliated with them, and we've never contacted them or signed up for any mailing list offered by them so the mass unsolicited emails from them are definitely spam.

Congratulations boinktards at Comodo, due to your spam emails and phone calls, the 24 SSL certificates we buy annually will always be bought from your competitors not from you. Thefinger

Link to file FTC complaints if you've been spammed by Comodo:
http://esupport.fcc.gov/complaints.htm?sid=d1e640&id=d1e697

Complaints may also be filed with the BBB, New Jersey State Attorney General, and Comodo's upstream providers.

The nameservers for the positivessl.com domain name advertised in the emails are comododns.com and comododns.net

Comodo's comododns.com domain name  is registered through Dotster.  You can file a spam complaint with Dotster at:
https://secure.dotster.com/services/comp...iteid=4798 (file the complaint against comododns.com )

Comodo's comododns.net domain name/name server shows the same UK registrant street address as the positivessl.com name's WHOIS but the registrant of the .net name  is listed as "Melih Abdulhayoglu" (the registrant for the comododns.com is listed as "Comodo IP Limited" and the registrant for positivessl.com is listed as "Comodo CA Ltd").  The registrar for the .net name is 123-reg.co.uk.  Abuse complaints against comododns.net can be filed by emailing your complaint to:  abuse @ 123-reg.co.uk.

edited to add: http://www.google.com/search?q=Melih+Abdulhayoglu
Reply
09-06-2010, 12:49 PM, (This post was last modified: 09-06-2010, 01:15 PM by regic.)
Post: #2
regic Offline
Administrator
*******
Posts: 2,825
Joined: Jul 2005
Reputation: 0
Re: Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
10 more spams from Comodo this morning making a total of 41 this holiday weekend.

If anyone else has been spammed by Comodo, received telemarketing calls from them, or had your contact info harvested by them, here are a few Comodo email addresses, telephone numbers, and IP addresses you can block:

Telephone numbers used by Comodo's telemarketers:
(888) 266-6361
(703) 581-6361
(201) 963-0004
(201) 716-4468

Spammer Comodo's Fax
1 (201) 963-9003

Spammer Comodo's email
EnterpriseSolutions@comodo.com
sales@comodo.com
sales@comodojapan.com
mfpenco@comodo.com
sales@comodoISRAEL.com
domain-admin@comodogroup.com
melih@abdulhayoglu.com
infra@comodo.net

IP addresses used by spammer Comodo's servers:
91.199.212.0 - 91.199.212.255 -ip block controlled by Comodo (add 91.199.212.0/24 to your firewall to block their bots)
38.104.66.254 -mail.nj.office.comodo.net

IP addresses Comodo's spam emails have been sent from:
216.83.51.201
184.82.44.50
174.34.166.149
64.120.27.63
67.213.69.54
....and several other IPs
*@instantssl-ev.com -spam email addresses used in emails
*.secureinternetnews.net -spam sender host addresses

In classic spammer tradition, they're very careful not to send the spam directly from the IP block their websites are hosted on, and both instantssl-ev.com and secureinternetnews.net hide their WHOIS data.

Ironically, the spammers at Comodo distribute free antispam software to unsuspecting people :Smile
Reply
09-06-2010, 06:19 PM,
Post: #3
regic Offline
Administrator
*******
Posts: 2,825
Joined: Jul 2005
Reputation: 0
Re: Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
2 more spams from Melih Abdulhayoglu's Comodo spam gang bringing the total to 43.  All 43 have been reported to Spamcop and Comodo's upstream providers.

This is the text of the spam:

Quote:You received this email because we thought you would benefit from the increased SSL protection. This is an advertisement. If you wish to unsubscribe from receiving e-mail offers from Comodo or if this message has been sent to you in error, please click on the unsubscribe link to be removed from our mailing list....

A reminder to  anyone who receives an email from spammers:  do not click on the unsubscribe in the spam email  because by entering your email address on the spammer's site it will only verify to the spammer that the email address they spammed is functioning and you will likely see an increase in spam.
Reply
09-07-2010, 02:01 AM, (This post was last modified: 09-07-2010, 02:54 AM by jezebel.)
Post: #4
jezebel Offline
Tulip Fanatic
*******
Posts: 1,385
Joined: Jul 2005
Reputation: 0
Re: Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
Melih, dude, your company wouldn't need to spam to get customers if you'd just button your damn shirt and stop forcing visitors to Comodo's home page to look at your scrawny chicken chest!  First impressions are everything! Happy001

P.S. to everyone else, check your server logs. Comodo's harvester bot is "mkt-search.comodo.com". IP addresses [size=12px]91.212.12.58, [/size]91.209.196.80

274,000 sites visited by the spammers' bot
http://www.google.com/search?q=mkt-search.comodo.com

block: [size=10px]91.209.196.0/24 [/size]http://www.robtex.com/cnet/91.209.196.html
block: [size=10px]91.212.12.0/24 [/size]http://www.robtex.com/cnet/91.212.12.html
block: [size=10px]91.199.212.0/24 [/size]http://www.robtex.com/cnet/91.199.212.html
block: [size=10px]67.51.175.0/24 [/size]http://www.robtex.com/cnet/67.51.175.html
block: [size=10px]149.5.128.0/24 [/size]http://www.robtex.com/cnet/149.5.128.html
block: [size=10px]208.116.56.0/24 [/size]http://www.robtex.com/cnet/208.116.56.html

AS48447 COMODO CA Ltd http://www.robtex.com/as/as48447.html#bgp
Reply
09-07-2010, 11:43 AM,
Post: #5
mandy Offline
Administrator
*******
Posts: 9,932
Joined: Feb 2011
Reputation: 0
Re: Avoid the Mass Spammers at Comodo / PositiveSSL When Buying SSL Certificates
Quote:P.S. to everyone else, check your server logs. Comodo's harvester bot is "mkt-search.comodo.com". IP addresses 91.212.12.58, 91.209.196.80

274,000 sites visited by the spammers' bot http://www.google.com/search?q=mkt-search.comodo.com

There are 1.24 million results (see log spam definition) if you search for its UA name http://www.google.com/search?q=Comodo-Certificates-Spider#q=Comodo-Certificates-Spider&hl=en .

You can try to block it by disallowing its UA in robots.txt (User-agent: Comodo-Certificates-Spider
Disallow: /) but there are reports that in true spammerbot fashion it often ignores robots.txt:
http://www.projecthoneypot.org/ip_91.212.12.60

This quote is from a February 2010 discussion on Comodo's bot:
Quote:This bot has hit my server several times looking at SSL certs that are linked to validation scripts that show when the SSL cert expires. I have also been sent several emails about 90-days before my SSL cert expires offering to renew it with them. Once these folks even sent me an email warning me that there was a security issue related to my cert/server configuration and even though the server had been upgraded over a month before that they still claimed it was vulnerable.

Personally I find this type of spamming much like ambulance chasing lawyers and I for one will NEVER use their certs because of it...and now I block them from my server as well and like magic, no more spam from them either..Go figure!
http://www.webmasterworld.com/search_eng...002656.htm

They have another bot that does its spidering from servers in Beijing China, IP range 114.255.52.160 - 114.255.52.175
http://www.botsvsbrowsers.com/details/421883/index.html
http://www.robtex.com/ip/114.255.52.164.html#whois

Reply
« Next Oldest | Next Newest »




Possibly Related Threads…
Thread Author Replies Views Last Post
  No SSL = Lost business xwpopper 4 5,399 01-11-2010, 11:01 PM
Last Post: bargainbloodhound
  Think your store or auction site's implementation of SSL is secure? Think again mandy 0 3,149 07-31-2009, 08:31 AM
Last Post: mandy
  Configuring SSL Under Apache mandy 0 3,979 03-11-2008, 01:21 PM
Last Post: mandy
  Verisign Ignores Complaints of SSL Seal Misuse Kristijntje 0 3,773 12-02-2007, 02:18 PM
Last Post: Kristijntje
  Who is The SSL Certification Leader? mandy 7 9,219 10-05-2007, 03:48 PM
Last Post: regic
  Extended Validation SSL Certificates may create problems for Small Businesses mandy 10 11,217 06-16-2007, 06:07 PM
Last Post: valleygirl
  List of SSL Security Certificate Providers allmusicsearch 8 13,307 10-15-2006, 01:43 PM
Last Post: bargainbloodhound
  Ecommerce Sites Face New Security Problem: SSL-evading trojans and malware regic 0 3,849 06-01-2006, 02:02 PM
Last Post: regic
  SSL Certificate Issuer Verisign Acquires Rival GeoTrust for $125 million Kristijntje 0 4,087 05-20-2006, 01:01 PM
Last Post: Kristijntje
  California Court Certifies Class Action Against SSL Certificate Issuer Verisign Kristijntje 0 3,901 05-20-2006, 12:59 PM
Last Post: Kristijntje

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread
Forum Jump:


Users browsing this thread: 1 Guest(s)
  • Contact Us
  • TulipTools Internet Business Owners and Online Sellers Community
  • Return to Top
  • Lite (Archive) Mode
  • RSS Syndication
  • Help
Current time: 07-17-2026, 11:42 AM Powered By MyBB, © 2002-2026 MyBB Group. Theme created by Justin S.
powered by Apache

powered by Linuxpowered by CentOS

Copyright 2000-2013 TulipTools.com. All rights reserved.