[112705] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Dynamic IP log retention = 0?

daemon@ATHENA.MIT.EDU (Chris Adams)
Sat Mar 14 16:35:33 2009

Date: Sat, 14 Mar 2009 15:35:19 -0500
From: Chris Adams <cmadams@hiwaay.net>
To: nanog@nanog.org
Mail-Followup-To: Chris Adams <cmadams@hiwaay.net>, nanog@nanog.org
In-Reply-To: <77e4079b0903140112u5de4108am142a04c3884c8da@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org

Once upon a time, Neil <kngspook@gmail.com> said:
> I think you are being a little naive.  Port scans, while possibly used for
> malicious ends, can very often be benign.

That sounds naive to me.  From what I've seen, the number of malicious
scans is much greater than the number of benign scans.  The vast
majority of end users have no idea what a port scan is or how to run one
(or how to make sense of the output if they saw one run).

In any case, this isn't really about the port scan.  This is about Covad
claiming they cannot identify who had an IP 48 hours ago.  What if it
wasn't a port scan; what if it was a DoS attack, spamming bot, etc.?

Do you think Covad would respond to a DMCA complaint like that?
-- 
Chris Adams <cmadams@hiwaay.net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


home help back first fref pref prev next nref lref last post