Re: Compromised Hosts?

2004-03-22 Thread Richard A Steenbergen
On Mon, Mar 22, 2004 at 10:53:29AM -0600, Ejay Hire wrote: > > We get a lot of automated complaints. A human reads all of > them, and act on some of them. I'm particularly fond of the > dozen-a-week "Source quench" attack emails we get, where Joe > Guy's IDS identifies the single source quench

RE: Compromised Hosts?

2004-03-22 Thread Ejay Hire
time we should give our ICMP control messages friendlier names. :) -Ejay > -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On > Behalf Of Dan Ellis > Sent: Sunday, March 21, 2004 6:51 PM > To: [EMAIL PROTECTED] > Subject: RE: Compromised Hos

Re: Compromised Hosts?

2004-03-22 Thread Richard Cox
On 22 Mar 2004 00:26 UTC Deepak Jain <[EMAIL PROTECTED]> asked: > Would any broadband providers that received automated, detailed > (time/date stamp, IP information) with hosts that are being used to > attack (say as part of a DDOS attack) actually do anything about it? We are a broadband provid

Re: Compromised Hosts?

2004-03-21 Thread Mike Tancsa
At 07:26 PM 21/03/2004, Deepak Jain wrote: Nanogers - Would any broadband providers that received automated, detailed (time/date stamp, IP information) with hosts that are being used to attack (say as part of a DDOS attack) actually do anything about it? From my experiences, some are muc

Re: Compromised Hosts?

2004-03-21 Thread Paul Vixie
[EMAIL PROTECTED] (Deepak Jain) writes: > Would any broadband providers that received automated, detailed > (time/date stamp, IP information) with hosts that are being used to > attack (say as part of a DDOS attack) actually do anything about it? while not a broadband provider, i would b

RE: Compromised Hosts?

2004-03-21 Thread Dan Ellis
:26 PM To: [EMAIL PROTECTED] Subject:Compromised Hosts? Nanogers - Would any broadband providers that received automated, detailed (time/date stamp, IP information) with hosts that are being used to attack (say as part of a DDOS attack) actually do anything about it? Would the

Re: Compromised Hosts?

2004-03-21 Thread Dan Hollis
On Sun, 21 Mar 2004, Deepak Jain wrote: > Would any broadband providers that received automated, detailed > (time/date stamp, IP information) with hosts that are being used to > attack (say as part of a DDOS attack) actually do anything about it? Most of them dont even do anything when yo

Compromised Hosts?

2004-03-21 Thread Deepak Jain
Nanogers - Would any broadband providers that received automated, detailed (time/date stamp, IP information) with hosts that are being used to attack (say as part of a DDOS attack) actually do anything about it? Would the letter have to include information like "x.x.x.x/32 has been blackho

RE: BL of Compromised Hosts?

2004-02-23 Thread Michel Py
>> Michel Py wrote: >> There is a regrouping of BGP feeds for various "questionable" >> hosts and networks around AS29467; > william(at)elan.net wrote: > That is actually not correct. The AS29467 will stay as being > used for BOGON and similar data. It is quite likely that other > ASNs would be

Re: BL of Compromised Hosts?

2004-02-23 Thread Tom (UnitedLayer)
On Mon, 23 Feb 2004, william(at)elan.net wrote: > I find that most admins that decides on RBL lists are well educated about > what lists they choose to use are (the end-users are however not always > well informed about it and that is where most of the complaints are > coming from). The fact that

Re: BL of Compromised Hosts?

2004-02-22 Thread william(at)elan.net
On 22 Feb 2004, Robert E. Seastrom wrote: > "Michel Py" <[EMAIL PROTECTED]> writes: > > > There is a regrouping of BGP feeds for various "questionable" hosts and > > networks around AS29467; That is actually not correct. The AS29467 will stay as being used for BOGON and similar data. It is qu

RE: BL of Compromised Hosts?

2004-02-22 Thread Michel Py
. -Original Message- From: Robert E. Seastrom [mailto:[EMAIL PROTECTED] Sent: Sunday, February 22, 2004 3:20 PM To: Michel Py Cc: Deepak Jain; [EMAIL PROTECTED] Subject: Re: BL of Compromised Hosts? "Michel Py" <[EMAIL PROTECTED]> writes: > There is a regrouping of

Re: BL of Compromised Hosts?

2004-02-22 Thread Robert E. Seastrom
"Michel Py" <[EMAIL PROTECTED]> writes: > There is a regrouping of BGP feeds for various "questionable" hosts and > networks around AS29467; read > http://arneill-py.sacramento.ca.us/draft-py-idr-redisfilter-01.txt and > feel free to contact the authors. It behooves the prospective user of sai

Re: BL of Compromised Hosts?

2004-02-22 Thread Andrew - Supernews
> "Avleen" == Avleen Vig <[EMAIL PROTECTED]> writes: >> Would anyone be interested in receiving a text or BGP feed of IPs of >> hosts known/suspected to be compromised and used as parts of DDOS >> attacks? Would anyone be interested in contributing their BGP views? Avleen> Hey Deepak,

Re: BL of Compromised Hosts?

2004-02-22 Thread Avleen Vig
On Sun, Feb 22, 2004 at 11:12:38AM -0500, Deepak Jain wrote: > Would anyone be interested in receiving a text or BGP feed of IPs of > hosts known/suspected to be compromised and used as parts of DDOS > attacks? Would anyone be interested in contributing their BGP views? Hey Deepak, It's not a

RE: BL of Compromised Hosts?

2004-02-22 Thread Michel Py
> Deepak Jain wrote: > Would anyone be interested in receiving a text or BGP > feed of IPs of hosts known/suspected to be compromised > and used as parts of DDOS attacks? Would anyone be > interested in contributing their BGP views? There is a regrouping of BGP feeds for various "questionable" h

Re: BL of Compromised Hosts?

2004-02-22 Thread Rafi Sadowsky
## On 2004-02-22 19:20 +0100 Daniel Concepcion typed: DC> DC> DC> Hi Deepak, DC> DC> Check DC> http://www.cymru.com/BGP/bogon-rs.html DC> They are doing a good job in this issue. Not quite - That is a list of BOGON networks (such as non-allocated, private(RFC1918), ... ) You're probably

Re: BL of Compromised Hosts?

2004-02-22 Thread Daniel Senie
At 11:12 AM 2/22/2004, Deepak Jain wrote: Would anyone be interested in receiving a text or BGP feed of IPs of hosts known/suspected to be compromised and used as parts of DDOS attacks? Would anyone be interested in contributing their BGP views? We have (and I'm sure we're not isolated) been s

Re: BL of Compromised Hosts?

2004-02-22 Thread Daniel Concepcion
Hi Deepak, Check http://www.cymru.com/BGP/bogon-rs.html They are doing a good job in this issue. Regards, Daniel On Sunday 22 February 2004 17:12, Deepak Jain wrote: > Would anyone be interested in receiving a text or BGP feed of IPs of > hosts known/suspected to be compromised and used as p

BL of Compromised Hosts?

2004-02-22 Thread Deepak Jain
Would anyone be interested in receiving a text or BGP feed of IPs of hosts known/suspected to be compromised and used as parts of DDOS attacks? Would anyone be interested in contributing their BGP views? We have (and I'm sure we're not isolated) been seeing attacks from several thousand/tens