[95938] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Abuse procedures... Reality Checks

daemon@ATHENA.MIT.EDU (J. Oquendo)
Wed Apr 11 13:59:30 2007

Date: Wed, 11 Apr 2007 13:49:40 -0400
From: "J. Oquendo" <sil@infiltrated.net>
To: nanog@merit.edu
Cc: Warren Kumari <warren@kumari.net>
In-Reply-To: <90B28D53-46ED-4E1A-841F-87805D418ADF@kumari.net>
Errors-To: owner-nanog@merit.edu


This is a cryptographically signed message in MIME format.

--------------ms040008060800070803000306
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Warren Kumari wrote:
>
> So, I have always wondered -- how do you customers really react when 
> they can no longer reach www.example.com, a site hosted a few IPs away 
> from www.badevilphisher.net? And do you really think that you blocking 
> them is going to make example.com contact their provider to get things 
> fixed?
>
You confused two things.

1) I do my best to stop malicious traffic from leaving my network. With
this said, if someone cannot get out somewhere, they're obviously going
to get in touch with me as to why. Once this is done, it is explained
to them that either their machine, or a machine on their network was
doing something fuzzy therefore they were blocked. Most are actually
thankful that it was pointed out to them as opposed to having to wait
for Security Company X to update its virus/spamware definitions.

2) I do not block getting TO company X at first signs of garbage coming
into my network from them. I've always contacted someone to some degree
so don't misconstrue my actions as "I block the first packets I see."
On the contrary I only block CIDR's after about 3 attempts at getting
someone to assess their network. After that, I begin with services.
This is my network so this is how it pans out... Spam? A CIDR to my
email ports are blocked. SSH brute forcing, etc., those ports are
blocked. Network who's blocked on ports continues, everything is then
blocked.

>
> Have you considered that being a little politer and not insulting 
> everyone on the list might be a more constructive way of getting your 
> point across -- if I were to call you a "big, fat, doodoo head" you 
> would probably be less receptive than if I didn't...
>
What does being polite and "matter of factly" have to do with
administrators cleaning up their networks? Should I beg an
administrator of some network to be polite and not refer me to their
generic abuse desk who'll do nothing about the issue?

I actually am a little too polite in the fact that 1) I'm doing
network operators a favor pointing them out to rogue hosts on
THEIR networks not mines. If they want to continue hosting said
rogue idiots, their problem. I won't be allowing it into my range.
If you knew me personally, or have dealt with me, I can guarantee
you within minutes of you contacting me for something I would be
on it. I as an admin/engineer whatever you want to call me would
want to make sure that nothing internal to me is affecting anyone
else since it is likely to make things more difficult for me if
left unchecked.

So on issues of politeness, I am being polite contacting people.
I'm being double polite posting evil doing networks on my personal
site so others can be aware that "These networks are infected.
Here are there hosts if you want to block them." I do this on my
own spare time, my own expense, and my own filtering of the
denials of service that ensue when some botnet reject sees me
post a percentage of his botnet. So please don't my messages as
anything other than "Hey... When is someone going to deal with
this?" frustration targeted at those with the power to do actually
something about it instead of waiting for someone else to take
the first move.

Analogy: You live in a house and sweep your property. Your
neighbors don't. Would you stop sweeping your house? Would you
keep your house dirty simply because the majority around you
do? I'm sure if you convinced the most visible neighbor to
make a change, the others would follow suit. Heck in some
areas those neighbors who didn't comply would face fines
after some point. Why not bring this chain of thought to a
network you maintain/manage.

As for documentation on this... There is PLENTY of it. Why should
I write another document no one would follow. If some can't follow
normal standards set by governmental bodies (for lack of better
terms), what makes you think someone would say "Gee... That
Oquendo sure wrote a nice document... Let me follow it" How
about following standards and using good old fashioned common
sense.

-- 
====================================================
J. Oquendo
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x1383A743
sil . infiltrated @ net http://www.infiltrated.net 

The happiness of society is the end of government.
John Adams


--------------ms040008060800070803000306
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIQGDCC
BIowggNyoAMCAQICECf06hH0eobEbp27bqkXBwcwDQYJKoZIhvcNAQEFBQAwbzELMAkGA1UE
BhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0w
NTA2MDcwODA5MTBaFw0yMDA1MzAxMDQ4MzhaMIGuMQswCQYDVQQGEwJVUzELMAkGA1UECBMC
VVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5l
dHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93d3cudXNlcnRydXN0LmNvbTE2MDQGA1UEAxMtVVRO
LVVTRVJGaXJzdC1DbGllbnQgQXV0aGVudGljYXRpb24gYW5kIEVtYWlsMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsjmFpPJ9q0E7YkY3rs3BYHW8OWX5ShpHornMSMxqmNVN
NRm5pELlzkniii8efNIxB8dOtINknS4p1aJkxIW9hVE1eaROaJB7HHqkkqgX8pgV8pPMyaQy
lbsMTzC9mKALi+VuG6JG+ni8om+rWV6lL8/K2m2qL+usobNqqrcuZzWLeeEeaYji5kbNoKXq
vgvOdjp6Dpvq/NonWz1zHyLmSGHGTPNpsaguG7bUMSAsvIKKjqQOpdeJQ/wWWq8dcdcRWdq6
hw2v+vPhwvCkxWeM1tZUOt4KpLoDd7NlyP0e03RiqhjKaJMeoYV+9Udly/hNVyh00jT/MLbu
9mIwFIws6wIDAQABo4HhMIHeMB8GA1UdIwQYMBaAFK29mHo0tCb3+sQmVO8DveAky1QaMB0G
A1UdDgQWBBSJgmd9xJ0mcABLtFBIfN49rgRufTAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/
BAUwAwEB/zB7BgNVHR8EdDByMDigNqA0hjJodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9BZGRU
cnVzdEV4dGVybmFsQ0FSb290LmNybDA2oDSgMoYwaHR0cDovL2NybC5jb21vZG8ubmV0L0Fk
ZFRydXN0RXh0ZXJuYWxDQVJvb3QuY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQAZ2IkRbyispgCi
54fBm5AD236hEv0e8+LwAamUVEJrmgnEoG3XkJIEA2Z5Q3H8+G+v23ZF4jcaPd3kWQR4rBz0
g0bzes9bhHIt5UbBuhgRKfPLSXmHPLptBZ2kbWhPrXIUNqi5sf2/z3/wpGqUNVCPz4FtVbHd
WTBK322gnGQfSXzvNrv042n0+DmPWq1LhTq3Du3Tzw1EovsEv+QvcI4l+1pUBrPQxLxtjftz
Mizpm4QkLdZ/kXpoAlAfDj9N6cz1u2fo3BwuO/xOzf4CjuOoEwqlJkRl6RDyTVKnrtw+ymsy
XEFs/vVdoOr/0fqbhlhtPZZH5f4ulQTCAMyOofK7MIIFwTCCBKmgAwIBAgIQCtGhjfhz35st
CJNIS5OrJzANBgkqhkiG9w0BAQUFADCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcw
FQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3Jr
MSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VS
Rmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbDAeFw0wNjEwMDUwMDAwMDBa
Fw0wNzEwMDUyMzU5NTlaMIHZMTUwMwYDVQQLEyxDb21vZG8gVHJ1c3QgTmV0d29yayAtIFBF
UlNPTkEgTk9UIFZBTElEQVRFRDFGMEQGA1UECxM9VGVybXMgYW5kIENvbmRpdGlvbnMgb2Yg
dXNlOiBodHRwOi8vd3d3LmNvbW9kby5uZXQvcmVwb3NpdG9yeTEfMB0GA1UECxMWKGMpMjAw
MyBDb21vZG8gTGltaXRlZDETMBEGA1UEAxMKSi4gT3F1ZW5kbzEiMCAGCSqGSIb3DQEJARYT
c2lsQGluZmlsdHJhdGVkLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAvcecKOQO
JDqytURULI+i0ju6GBa7bHBqxalyuhBT6jrSIwQmx+J5KpjuRaXQgSm73AJNSPx+qGGl1X65
w1gMZ8jHZ0nnVranOic31Um089ulE6pBY1V8MsVeiue+77xi6O/mEn8Jnea+ysIlTu+GZeQf
+W2RBTHXM6ErPKBES3UCAwEAAaOCAjAwggIsMB8GA1UdIwQYMBaAFImCZ33EnSZwAEu0UEh8
3j2uBG59MB0GA1UdDgQWBBRuQC562baQcF8itYR4eJVy0awkFzAOBgNVHQ8BAf8EBAMCBaAw
DAYDVR0TAQH/BAIwADAgBgNVHSUEGTAXBggrBgEFBQcDBAYLKwYBBAGyMQEDBQIwEQYJYIZI
AYb4QgEBBAQDAgUgMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQEBMCswKQYIKwYBBQUHAgEW
HWh0dHBzOi8vc2VjdXJlLmNvbW9kby5uZXQvQ1BTMIGlBgNVHR8EgZ0wgZowTKBKoEiGRmh0
dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRp
b25hbmRFbWFpbC5jcmwwSqBIoEaGRGh0dHA6Ly9jcmwuY29tb2RvLm5ldC9VVE4tVVNFUkZp
cnN0LUNsaWVudEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMIGGBggrBgEFBQcBAQR6MHgw
OwYIKwYBBQUHMAKGL2h0dHA6Ly9jcnQuY29tb2RvY2EuY29tL1VUTkFkZFRydXN0Q2xpZW50
Q0EuY3J0MDkGCCsGAQUFBzAChi1odHRwOi8vY3J0LmNvbW9kby5uZXQvVVROQWRkVHJ1c3RD
bGllbnRDQS5jcnQwHgYDVR0RBBcwFYETc2lsQGluZmlsdHJhdGVkLm5ldDANBgkqhkiG9w0B
AQUFAAOCAQEABj58KGEDtRZdukfsQ6F5wvMo4/yXdO/rpEYaPKEmBFOOu+o27qJ3pet9+ubi
cL5s6iPoq/pdonReD6bQKGyOmnUZdoznN7/S/sTJ65gjBogLk1BHc2JUiYsH79PuXT6kLqRJ
G3ufchBFNUuz4wSUs/j4hXRXz8vbWBncykNvtPmy1vIK4LSyccP1RIeU/uMMcneoZ5Urayso
YDlx8pAh3dL/12cTBpof3Iusl7e+TR5Vf/W3HmjzQrHyuMTueiB7lbwDhXyohjaB4FMHlhgm
lOf8SveLjvVKFZPJ5oJb/fVUKoDS6dInb0Vq09YMI0Jcwzj0CvajjtmUja/xpjcftjCCBcEw
ggSpoAMCAQICEArRoY34c9+bLQiTSEuTqycwDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNVBAYT
AlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoTFVRo
ZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3QuY29t
MTYwNAYDVQQDEy1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgRW1h
aWwwHhcNMDYxMDA1MDAwMDAwWhcNMDcxMDA1MjM1OTU5WjCB2TE1MDMGA1UECxMsQ29tb2Rv
IFRydXN0IE5ldHdvcmsgLSBQRVJTT05BIE5PVCBWQUxJREFURUQxRjBEBgNVBAsTPVRlcm1z
IGFuZCBDb25kaXRpb25zIG9mIHVzZTogaHR0cDovL3d3dy5jb21vZG8ubmV0L3JlcG9zaXRv
cnkxHzAdBgNVBAsTFihjKTIwMDMgQ29tb2RvIExpbWl0ZWQxEzARBgNVBAMTCkouIE9xdWVu
ZG8xIjAgBgkqhkiG9w0BCQEWE3NpbEBpbmZpbHRyYXRlZC5uZXQwgZ8wDQYJKoZIhvcNAQEB
BQADgY0AMIGJAoGBAL3HnCjkDiQ6srVEVCyPotI7uhgWu2xwasWpcroQU+o60iMEJsfieSqY
7kWl0IEpu9wCTUj8fqhhpdV+ucNYDGfIx2dJ51a2pzonN9VJtPPbpROqQWNVfDLFXornvu+8
Yujv5hJ/CZ3mvsrCJU7vhmXkH/ltkQUx1zOhKzygREt1AgMBAAGjggIwMIICLDAfBgNVHSME
GDAWgBSJgmd9xJ0mcABLtFBIfN49rgRufTAdBgNVHQ4EFgQUbkAuetm2kHBfIrWEeHiVctGs
JBcwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0lBBkwFwYIKwYBBQUHAwQG
CysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9MDsGDCsGAQQBsjEB
AgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0L0NQUzCBpQYD
VR0fBIGdMIGaMEygSqBIhkZodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9VVE4tVVNFUkZpcnN0
LUNsaWVudEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMEqgSKBGhkRodHRwOi8vY3JsLmNv
bW9kby5uZXQvVVROLVVTRVJGaXJzdC1DbGllbnRBdXRoZW50aWNhdGlvbmFuZEVtYWlsLmNy
bDCBhgYIKwYBBQUHAQEEejB4MDsGCCsGAQUFBzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNv
bS9VVE5BZGRUcnVzdENsaWVudENBLmNydDA5BggrBgEFBQcwAoYtaHR0cDovL2NydC5jb21v
ZG8ubmV0L1VUTkFkZFRydXN0Q2xpZW50Q0EuY3J0MB4GA1UdEQQXMBWBE3NpbEBpbmZpbHRy
YXRlZC5uZXQwDQYJKoZIhvcNAQEFBQADggEBAAY+fChhA7UWXbpH7EOhecLzKOP8l3Tv66RG
GjyhJgRTjrvqNu6id6Xrffrm4nC+bOoj6Kv6XaJ0Xg+m0Chsjpp1GXaM5ze/0v7EyeuYIwaI
C5NQR3NiVImLB+/T7l0+pC6kSRt7n3IQRTVLs+MElLP4+IV0V8/L21gZ3MpDb7T5stbyCuC0
snHD9USHlP7jDHJ3qGeVK2srKGA5cfKQId3S/9dnEwaaH9yLrJe3vk0eVX/1tx5o80Kx8rjE
7noge5W8A4V8qIY2geBTB5YYJpTn/Er3i471ShWTyeaCW/31VCqA0unSJ29FatPWDCNCXMM4
9Ar2o47ZlI2v8aY3H7YxggPPMIIDywIBATCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgT
AlVUMRcwFQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBO
ZXR3b3JrMSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVU
Ti1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbAIQCtGhjfhz35st
CJNIS5OrJzAJBgUrDgMCGgUAoIICYTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqG
SIb3DQEJBTEPFw0wNzA0MTExNzQ5NDBaMCMGCSqGSIb3DQEJBDEWBBQO10Nhqey+z3I2GIch
b4aeGlvbSDBSBgkqhkiG9w0BCQ8xRTBDMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDAN
BggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKDCB1AYJKwYBBAGCNxAEMYHG
MIHDMIGuMQswCQYDVQQGEwJVUzELMAkGA1UECBMCVVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBD
aXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93
d3cudXNlcnRydXN0LmNvbTE2MDQGA1UEAxMtVVROLVVTRVJGaXJzdC1DbGllbnQgQXV0aGVu
dGljYXRpb24gYW5kIEVtYWlsAhAK0aGN+HPfmy0Ik0hLk6snMIHWBgsqhkiG9w0BCRACCzGB
xqCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8v
d3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VSRmlyc3QtQ2xpZW50IEF1dGhl
bnRpY2F0aW9uIGFuZCBFbWFpbAIQCtGhjfhz35stCJNIS5OrJzANBgkqhkiG9w0BAQEFAASB
gEEydTM/N0mC+0QC6uPaex9BFNkx5kzBLk9BxkKsgsI3yY+tAOyP60sKxz5A8hTcsavPFrXB
rjlHyItZ2zr//t/jwunbXgaTn3Cdoqn9EbEjlQJO89ljM1bd/td70c6K6hDh5OhInH3Kwm3X
vup1KlN3Fc9sFS8ImGWRfvMLixQQAAAAAAAA
--------------ms040008060800070803000306--

home help back first fref pref prev next nref lref last post