Security Incidents mailing list archives
Re: IP Black list?
From: ryan () SECURITYFOCUS COM (Ryan Russell)
Date: Tue, 16 May 2000 09:34:38 -0700
On Mon, 15 May 2000, Mike Shannon wrote:
What if a legitimate orginization shares the same address space as an offender? Should they pay for the actions of that offender even though they are not even associated with them? For example, 50 people lodge a complaint about 1.2.3.0/24 even though it is actually coming from something in the 1.2.3.0/28 address space. Not only that but finding a group of unbiased people would be a tough thing to do.
That somewhat mirrors the situation that SecurityFocus is in. The folks we get our address space from apparantly have a few customers running open mail relays, spread throughout the address space. The ORBS guys caught this, and added a couple of supernets for that space to their blacklist. Meanwhile, the ISP in question has blocked the ORBS guys' ability to scan mail relays, so they can't verify if the problem have been fixed. The ORBS answer to this is to keep the block in place. Naturally, we don't run open relays, but the ORBS guys can't verify that. This means that a few places won't accept mail from us, and the ISP and ORBS are at an impasse. The only thing I could do at present as a customer is change providers, which is part of the point of a blacklist. The end result is a mild annoyance, because the ORBS list isn't in wide enough use to cause any real change yet. I don't think there is a real solution to "bad guys" on the Internet. Even with authenticated traffic, some of the bad guys will control their own authentication/PKI servers. In addition, they'll still be able to bounce off other servers out there, and will authenticate as them. Ryan
Current thread:
- Re: IP Black list?, (continued)
- Re: IP Black list? Mike Shannon (May 15)
- LJK2 rootkit? Felix Schueren (May 16)
- Re: LJK2 rootkit? Jose Nazario (May 16)
- IP blacklists phi-incident () EXORSUS NET (May 16)
- Re: LJK2 rootkit? Omachonu Ogali (May 16)
- Re: LJK2 rootkit? Jose Nazario (May 18)
- Re: LJK2 rootkit? Omachonu Ogali (May 18)
- LJK2 rootkit? Felix Schueren (May 16)
- Re: LJK2 rootkit? Jens Hektor (May 17)
- Re: LJK2 rootkit? Egon Barfuß jun. (May 17)
- Korea Damian Gerow (May 17)
- Re: IP Black list? Mike Shannon (May 15)
- Re: IP Black list? Ryan Russell (May 16)
- Re: IP Black list? Tabor J. Wells (May 16)
- Re: IP Black list? Michael Damm (May 15)
- Re: IP Black list? jms (May 15)
- TCP/IP options flags? Matt Beck (May 16)
- unapproved update from [166.93.60.5].61946 James Ankenbrandt (May 17)
- Re: unapproved update from [166.93.60.5].61946 Jon Lewis (May 18)
- Sniffer files Wozz (May 16)