Security Incidents mailing list archives
Re: scan log and subsequent response from the host's ISP
From: Talisker () NETWORKINTRUSION CO UK (Talisker)
Date: Mon, 10 Jul 2000 10:54:53 +0100
----- Original Message ----- From: "Dan Hollis" <goemon () SASAMI ANIME NET> To: <INCIDENTS () securityfocus com> Sent: Thursday, July 06, 2000 12:13 AM Subject: Re: scan log and subsequent response from the host's ISP
Now that I think about it, are there any RBL-type BGP services for known rogue networks? Eg networks which originate attacks and refuse to take any action? If so I submit 212.216.184.0 - 212.216.191.255 as the first netblock to be blackholed. -Dan
I could be tempted into maintaining such a list, my concerns are:
Does such a list exist already and if so, where is it?
Denial of Service, the scope for DOS is extreme therefore each submitted
range would need to be verified with the guilty ISP to test their response.
This will take time. A detailed mechanism of verification would need to be
built, perhaps a pending and a verified list. Any ideas?
Legal issues, if such a list was to prove popular, the business effect
on the blakholed ISPs may be terminal, leaving myself open to possible
prosecution. (oh well I've nothing to lose)
Does anyone else want to do it? because I'm already pretty busy with my IDS
site.
Andy
www.networkintrusion.co.uk
Current thread:
- scan log and subsequent response from the host's ISP Bradley Woodward (Jul 02)
- Fwd: [Fw: Ive been broken into ] JEFF WATSON (Jul 05)
- version.bind from zen.isi.edu Patrick Oonk (Jul 05)
- Re: scan log and subsequent response from the host's ISP Patrick Oonk (Jul 05)
- Re: scan log and subsequent response from the host's ISP Dan Hollis (Jul 05)
- Re: scan log and subsequent response from the host's ISP Dan Hollis (Jul 05)
- Re: scan log and subsequent response from the host's ISP Talisker (Jul 10)
- Re: scan log and subsequent response from the host's ISP Pauel Loshkin (Jul 05)
- how to close security holes from nessus vulnerability scan report ? Chew Poh Chang (CAPL) (Jul 06)
- Snort SMTP expn-root Oxenreider, Jeff (Jul 06)
- Re: Snort SMTP expn-root Joe McAlerney (Jul 06)
- Re: Snort SMTP expn-root Bill Pennington (Jul 06)
- Re: Snort SMTP expn-root dyer (Jul 06)
- Simultaneous Attacks Harlan S. Barney, Jr. (Jul 06)
- Re: Simultaneous Attacks Valdis Kletnieks (Jul 07)
- Re: Simultaneous Attacks Ryan Russell (Jul 07)
- Ehm... what? (Re: Simultaneous Attacks) Martin Macok (Jul 11)
