Vulnerability Development mailing list archives
Re: Publishing Nimda Logs
From: "Laurence Brockman" <laurence () fluxinc com>
Date: Wed, 8 May 2002 07:09:57 -0600
Whois works great. Try the following: whois -h whois.arin.net x.x.x.x where x.x.x.x is the attacking IP. Or you can visit www.arin.net and look for the whois link there. Same thing, but through a web interface if you don't have access to a unix box. Laurence ----- Original Message ----- From: "ash" <ashcrow () phreaker net> To: "Laurence Brockman" <laurence () fluxinc com> Cc: <vuln-dev () securityfocus com> Sent: Tuesday, May 07, 2002 10:59 PM Subject: Re: Publishing Nimda Logs
Ah, thanks for clearing that up. Is there a central place that says who owns what IP range blocks so Ican further investigate where attacks come from (besides whoising each address)? Ash Laurence Brockman wrote:24.x isn't just Road Runner, it's most cable companies. It's Shaw (In Canada), Rogers (AT&T), Road runner, etc, etc. These blocks were given to lots of cable ISP's when @Home was big, so sending logs into Road runner
for
any 24.x.x.x IP is useless in most cases (As the majority doesn't belong
to
them). Laurence
Current thread:
- Re: Publishing Nimda Logs, (continued)
- Re: Publishing Nimda Logs Blue Boar (May 07)
- Re: Publishing Nimda Logs zeno (May 07)
- Re: Publishing Nimda Logs unprivileged user (May 07)
- RE: Publishing Nimda Logs Paul_Asadoorian (May 07)
- RE: Publishing Nimda Logs Matt Andreko (May 07)
- Re: Publishing Nimda Logs Johannes B. Ullrich (May 07)
- Re: Publishing Nimda Logs Blue Boar (May 07)
- Re: Publishing Nimda Logs ash (May 07)
- Re: Publishing Nimda Logs Laurence Brockman (May 08)
- Re: Publishing Nimda Logs ash (May 08)
- Re: Publishing Nimda Logs Laurence Brockman (May 08)
- is: whois tricks was : Publishing Nimda Logs Matthew McGehrin (May 08)
- RE: whois tricks was : Publishing Nimda Logs Steve Zenone (May 08)
- Re: whois tricks was : whois is what? Matthew McGehrin (May 08)
- RE: whois tricks was : whois is what? Steve Zenone (May 09)
- Re: Publishing Nimda Logs Bernie Cosell (May 08)
- Re: Publishing Nimda Logs Pavel Lozhkin (May 08)
- Re: Publishing Nimda Logs Bernie Cosell (May 07)
- RE: Publishing Nimda Logs Tech Support (May 07)
- Re: Publishing Nimda Logs Blue Boar (May 07)
- Re: Publishing Nimda Logs Bernie Cosell (May 07)