Security Incidents mailing list archives

Re: IP Black list?


From: EPerrin () METROLAND COM (Elliot Perrin)
Date: Tue, 16 May 2000 09:37:37 -0400


How about IP spoofing, TCP/IP hijacking?

Let's say you get someone who doesn't like a specific business,
hacks them, and initiates scans from their networks.

Legitimate business with a disgruntled former employee......
How can guarantee that only the "bad hosts" or the "bad networks"
will be blocked?

_______________________
Elliott Perin
eperrin () metroland com


I don't think it's a very wise idea to do this.
First think of al the dynamic ip's there are with ISP'S.
Blocking them
will hurt "good" users also. And also how do you classify a
bad host ?
A host that is just performing a port scan, DoSsing the
server, .... ?

I have the same feeling against this as i have against the DUL-list
(http://maps.vix.com/dul/). It is gonna hurt users who are just
normally using the internet and not doing anything bad.

cu,

Patrick

P.S I appologise for any bad English. English is not my native
language.

Certainly there would be an uproar among the blocked
customers of the ISP,
but who would hear about it?..  The ISP.  In the end, the
only way the ISP
will survive will be to fix the problem.  This may involve
implementing a
stricter user policy, dealing with incidents reasonably, or
fixing router
misconfigurations.

A push from the inside will help to settle things much
faster.  Once that
is done, take 'em off the list.  Everyone benefits from the
end results.
We are safer, the ISP has less incidents to hear about and
deal with, and
the ISP customers continue on their merry way.

-Joe M.



Current thread: