[166819] in North American Network Operators' Group
Re: Automatic abuse reports
daemon@ATHENA.MIT.EDU (Brandon Galbraith)
Wed Nov 13 00:16:50 2013
In-Reply-To: <CAP-guGVjXrOqTgCKgwoHgMmuc+tussaMw4mWhNqO=Zx_URDasw@mail.gmail.com>
Date: Tue, 12 Nov 2013 23:16:14 -0600
From: Brandon Galbraith <brandon.galbraith@gmail.com>
To: William Herrin <bill@herrin.us>
Cc: sam@circlenet.us, "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Tue, Nov 12, 2013 at 10:03 PM, William Herrin <bill@herrin.us> wrote:
>> Now it would be trivial to setup syslog and sshd to give only the sessions
>> that complete the handshake, however I'm also not sure how responsive some
>> of the abuse contacts may be. I'll keep my restrictive network settings for
>> the time being.
>
> That's the main problem: you can generate the report but if it's about
> some doofus in Dubai what are the odds of it doing any good?
And then we're right back to sending the offending packets to a black
hole. *sigh*