Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

asn.haus - threat reporting for whole asns

aluyaluy Member, Patron Provider

https://asn.haus/

I made a small site where you can report ASNs for malicious activity. its right now in alpha state because i need a lot of testing, dont expect reports to stay forever. i created it due to spamhaus just not being community based and i thought its just missing. the name is obviously stolen from urlhaus, huge kudos to them.

another site i wanna just leave here is spamshit.org, a good friend made it ^^

i hope i can get a bit of feedback on it and what i could improve. also please tell me if you find issues.

i didnt make one for ips since abuseipdb exists even though it needs a rework since the reports are not very reliable..

«134

Comments

  • tentortentor Member, Host Rep

    @aluy said: i created it due to spamhaus just not being community based

    https://submit.spamhaus.org

    ???

  • onraetonraet Member
    edited June 2025

    Can't make this shit up lol
    https://krebsonsecurity.com/2023/03/german-police-raid-ddos-friendly-host-flyhosting/ (this is OP)

    What the fuck are you even doing anymore? Team up with Elad Cohen, I'm sure he would appreciate a buddy to grift with.
    Team "Fuck Spamhaus" isn't sending their best, so far.

  • sillycatsillycat Member
    edited June 2025

    @onraet said: (this is OP)

    Since you seem to be too stupid to provide proof for your statements, I'll do it for you.

    AS202437 is FlyHosting's ASN. FLYHOSTING LTD has "Julian ACHTER" as the director, which is OP.
    https://ipinfo.io/AS202437
    https://find-and-update.company-information.service.gov.uk/company/14523194/officers

    Treesmokah, if you go out of your way to make burners, at least make them worth while by making people trust your statements at least a tiny lil bit.

    Reguards.

    Thanked by 2kait ServerBachelor
  • onraetonraet Member
    edited June 2025

    -

  • zmeuzmeu Member
    edited June 2025

    Please ban all ASNs but exclude mine. Thank you. 🫣

    @emgh

    Thanked by 3emgh COLBYLICIOUS kode9
  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said: i created it due to spamhaus just not being community based

    https://submit.spamhaus.org

    ???

    always needs verifying by spamhaus, never does shit

  • aluyaluy Member, Patron Provider

    @sillycat said:

    @onraet said: (this is OP)

    Since you seem to be too stupid to provide proof for your statements, I'll do it for you.

    AS202437 is FlyHosting's ASN. FLYHOSTING LTD has "Julian ACHTER" as the director, which is OP.
    https://ipinfo.io/AS202437
    https://find-and-update.company-information.service.gov.uk/company/14523194/officers

    Treesmokah, if you go out of your way to make burners, at least make them worth while by making people trust your statements at least a tiny lil bit.

    Reguards.

    past is past, got dropped anyways. No lawsuit nothing

  • tentortentor Member, Host Rep

    @aluy said:

    @tentor said:

    @aluy said: i created it due to spamhaus just not being community based

    https://submit.spamhaus.org

    ???

    always needs verifying by spamhaus, never does shit

    We both would agree that trusting third-party reporters as their report is 100% genuine is the worst idea possible (see abuseipdb being spammed by "tcp syn portscan" type of bs reports).

  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said:

    @tentor said:

    @aluy said: i created it due to spamhaus just not being community based

    https://submit.spamhaus.org

    ???

    always needs verifying by spamhaus, never does shit

    We both would agree that trusting third-party reporters as their report is 100% genuine is the worst idea possible (see abuseipdb being spammed by "tcp syn portscan" type of bs reports).

    thats exactly why port scans arent something that can be reported. and i can always delete stuff that is invalid. its also why reporting via api isnt possible

  • tentortentor Member, Host Rep

    @aluy said: thats exactly why port scans arent something that can be reported.

    another wrong idea. you can report port scan, but only if you have evidence that it can't be spoofed, tcp handshake is a savior. but arguably some might call this activity "banner grabbing", however I do think that it is still can be categorized as port scan

    @aluy said: its also why reporting via api isnt possible

    Do you expect anyone report each SSH bruteforce manually? What is the point then? It makes sense only if you run CERT/CSIRT and consider an information security incident something that actually breached the system, but asn.haus doesn't look like one

    Thanked by 1mandala
  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said: thats exactly why port scans arent something that can be reported.

    another wrong idea. you can report port scan, but only if you have evidence that it can't be spoofed, tcp handshake is a savior. but arguably some might call this activity "banner grabbing", however I do think that it is still can be categorized as port scan

    @aluy said: its also why reporting via api isnt possible

    Do you expect anyone report each SSH bruteforce manually? What is the point then? It makes sense only if you run CERT/CSIRT and consider an information security incident something that actually breached the system, but asn.haus doesn't look like one

    a tcp handshake is usually not being used for scanning, zmap and masscan use tcp syn.

    you can only report an asn once, all further reports require you to edit your previous report

    Thanked by 1mandala
  • aluyaluy Member, Patron Provider

    also obviously not everything is fully done yet, it states in post this is alpha. i am lookinf for bugs and having real people try it is the best way

  • kaitkait Member

    This is gay, especially coming from this german.

    Thanked by 2zmeu tentor
  • tentortentor Member, Host Rep

    @aluy said: a tcp handshake is usually not being used for scanning, zmap and masscan use tcp syn.

    Please read first paragraph of my previous post. It already addresses your concern.

    @aluy said: you can only report an asn once, all further reports require you to edit your previous report

    How would you distinguish between cases when big cloud providers are abused from different IP addresses (but handled/taken down fast) without accounting for IP addresses? Also, what happens on AS number reassignment to another party?

    Thanked by 1mandala
  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said: a tcp handshake is usually not being used for scanning, zmap and masscan use tcp syn.

    Please read first paragraph of my previous post. It already addresses your concern.

    @aluy said: you can only report an asn once, all further reports require you to edit your previous report

    How would you distinguish between cases when big cloud providers are abused from different IP addresses (but handled/taken down fast) without accounting for IP addresses? Also, what happens on AS number reassignment to another party?

    you are right you confirmed that but i think its fine to set that under intrusion attempts

    i have the ability to lock certain asns of being reported. while this destroys the free reporting its sometimes needed. i dont really know yet how to account for it, thas true.

    on reassignments the user can request removal of all reports

  • aluyaluy Member, Patron Provider

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

  • tentortentor Member, Host Rep

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    I think he meant that it looks like conflict of interests given your background.

    Spamhaus aren't saint either, but your alternative raises some good concerns as well and you will need to prove your worthiness first. Have a good luck with that!

    Thanked by 2sillycat kait
  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    I think he meant that it looks like conflict of interests given your background.

    Spamhaus aren't saint either, but your alternative raises some good concerns as well and you will need to prove your worthiness first. Have a good luck with that!

    wel im trying my best with as many projects as possible that could be useful, spamshit isnt by me but its kinda funny. they arent forgiving either. it will take time to gain a fair reputation again but at least im out of that stuff and want to continue legitimate

  • tentortentor Member, Host Rep

    @aluy said: wel im trying my best with as many projects as possible that could be useful

    I don't think it is good for you or projects. Focus on one single thing and do it well.

    As for spamhaus, so far I think they made the best efforts in lowering adoption by partially closing their DNSBL for big cloud networks like OVH, Hetzner, Azure etc... But if they took that decision, they might still have a bunch of well-paying corporate customers using their threat intelligence (and not for free!).

  • kaitkait Member

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    No you can't.

  • xemapsxemaps Member

    Please allow ip to search and convert it to ASN number automaticly.
    Will help a lot.

  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said: wel im trying my best with as many projects as possible that could be useful

    I don't think it is good for you or projects. Focus on one single thing and do it well.

    As for spamhaus, so far I think they made the best efforts in lowering adoption by partially closing their DNSBL for big cloud networks like OVH, Hetzner, Azure etc... But if they took that decision, they might still have a bunch of well-paying corporate customers using their threat intelligence (and not for free!).

    if they would just actually have anything to do with the community..

    i am mostly focused on al.uy yes, but some side ones dont hurt right?

    ig my past will even in 10 years get back to me. i made mistakes and they happened. im happy it all got dropped but i want gain that rep back. i will never stop trying though

    i am open for any suggestion or anything people might need more

  • aluyaluy Member, Patron Provider

    @kait said:

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    No you can't.

    i mistyped that, i meant i cant

  • aluyaluy Member, Patron Provider

    @xemaps said:

    Please allow ip to search and convert it to ASN number automaticly.
    Will help a lot.

    oka

    Thanked by 1xemaps
  • tentortentor Member, Host Rep

    @aluy said: i am mostly focused on al.uy yes, but some side ones dont hurt right?

    Sure it doesn't, but our time is limited as well as life energy. One need to sleep, touch grass *cough-cough* personal life, and meaningfully manage project stuff. Only you can decide how many is acceptable for you.

    Just a friendly reminder to not take too much responsibility and duties that you can't handle.

  • aluyaluy Member, Patron Provider

    @tentor said:

    @aluy said: i am mostly focused on al.uy yes, but some side ones dont hurt right?

    Sure it doesn't, but our time is limited as well as life energy. One need to sleep, touch grass *cough-cough* personal life, and meaningfully manage project stuff. Only you can decide how many is acceptable for you.

    Just a friendly reminder to not take too much responsibility and duties that you can't handle.

    this is true but at least i got a few friends to help with asn.haus :) hopefully thatll work for now

  • aluyaluy Member, Patron Provider

    @xemaps said:

    Please allow ip to search and convert it to ASN number automaticly.
    Will help a lot.

    added that thanks

    Thanked by 1xemaps
  • kaitkait Member

    @aluy said:

    @kait said:

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    No you can't.

    i mistyped that, i meant i cant

    Also means you can't change your future, you fucked up, you're doomed, you're fucked.

    Thanked by 1xemaps
  • AlyxAlyx Member, Host Rep

    @kait said:

    @aluy said:

    @kait said:

    @aluy said:

    @kait said:
    This is gay, especially coming from this german.

    im sorry it happened. i can change my past

    No you can't.

    i mistyped that, i meant i cant

    Also means you can't change your future, you fucked up, you're doomed, you're fucked.

    What is wrong with you? 🤨

  • xemapsxemaps Member

    @aluy said:

    @xemaps said:

    Please allow ip to search and convert it to ASN number automaticly.
    Will help a lot.

    added that thanks

    LET'S ROCK !!! TY

Sign In or Register to comment.