LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


View Poll Results: Do you email abuse departments of people abusing your network?
Only if they are in the US 2 11.76%
Everyone but China 3 17.65%
Everyone 2 11.76%
No 10 58.82%
Voters: 17. You may not vote on this poll

Reply
  Search this Thread
Old 11-18-2009, 09:50 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Do you email abuse departments of people abusing your network?


Do you email abuse departments of people abusing your network?

IE. Port scanning, failed logins, etc.
 
Old 11-19-2009, 04:38 AM   #2
ammorais
Member
 
Registered: Nov 2009
Location: Lisbon, Portugal
Distribution: Gentoo, CentOs, Ubuntu, Debian
Posts: 182

Rep: Reputation: 49
Your poll assumes everyone here lives in US.
You should change your first option to something like "Only if they are in my living country".

Not responding for the lack of options.
 
Old 11-19-2009, 05:50 AM   #3
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
I report only the truly persistent ones, that I notice they have been trying really hard to get in. However, I don't think anything is ever done about it, no matter what country it is.
 
Old 11-19-2009, 07:08 AM   #4
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
I used to, but as far as I can tell every abuse @somedomain.com.net.gov.edu is sent directly to the bit bucket.
 
Old 11-19-2009, 11:52 AM   #5
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
I use automated tools.

I've used mynetwatchman.com's agent to monitor and report automatically (not that it helps a lot but at least it is reported). Dshield also has a logging agent that will donate your logs (for crunching trend reports) and also report abusers.

I saw one that originated from a major security company that scanned my home network. I reported it to them (instead of their ISP) and they responded back and apologized, saying that they'd mis-configured their scan.

Sometimes, reporting does help.
 
Old 11-19-2009, 12:17 PM   #6
Quakeboy02
Senior Member
 
Registered: Nov 2006
Distribution: Debian Linux 11 (Bullseye)
Posts: 3,400

Rep: Reputation: 141Reputation: 141
I've had some luck with emailing the registrar for the offending domain as listed by whois. In a few cases, all it took was copies of the offending emails to get spammers kicked. Of course they probably just moved somewhere else, but I stopped getting the emails. However, the Chinese registrars don't respond. This assumes it's a rogue domain rather than just a rogue operator within a large domain, of course.

Edit:
Never mind, your question is for server scanning, and my response was for getting spam.

Last edited by Quakeboy02; 11-19-2009 at 12:22 PM.
 
Old 11-23-2009, 11:11 AM   #7
nelgin
LQ Newbie
 
Registered: Nov 2009
Posts: 8

Rep: Reputation: 0
If I see a pretty persistent scan, I'll just block the whole damn network. Doesn't matter any to me.
 
Old 11-24-2009, 08:24 AM   #8
mlnutt
Member
 
Registered: May 2006
Posts: 34

Rep: Reputation: 15
I report port scanning, attempted relaying, spam, brute force authentication, etc to the registered owner of an IP. As I run a small private host, many countries are already blocked (china, hong kong, russia, etc). It is important to report illegal/unsolicited email, port scanning, etc in order to help combat these activities. I always threaten the registered owner with the possibility of legal action. If spam or the like chronically persists from these organizations they are black listed. Many administrators report back that an investigation has been launched.

If everybody reported illegal/unsolicited activity the registered owners of IP ranges would do more.
 
Old 11-24-2009, 08:52 AM   #9
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by mlnutt View Post
If everybody reported illegal/unsolicited activity the registered owners of IP ranges would do more.
I seriously doubt this. The world is very big and the laws within country X are usually different than country Y. What's not allowed here is allowed there. Everyone's experience in network security is different, so an e-mail threatening legal action regarding "an attack" may well go over their head. Then there's the issue of spammers knowing that they are scanning and spamming...they flat-out ignore correspondence.

Unless it is something outside of the norm of what I log, I'm not going to manually engage each and every IP/network owner. That's why I have Mynetwatchman, but most owners don't respond to those notices, either. If the IP/network owners don't respond, then there's nothing I can do about that without wasting time and resources that I don't really have.

That's just my 2 cents on the issue.
 
1 members found this post helpful.
Old 11-29-2009, 11:07 AM   #10
archtoad6
Senior Member
 
Registered: Oct 2004
Location: Houston, TX (usa)
Distribution: MEPIS, Debian, Knoppix,
Posts: 4,727
Blog Entries: 15

Rep: Reputation: 234Reputation: 234Reputation: 234
Quote:
Originally Posted by ammorais View Post
Your poll assumes everyone here lives in US.
You should change your first option to something like "Only if they are in my living country".
Another option you forgot was "Only if I have time on my hands".

Quote:
Originally Posted by ammorais View Post
Not responding for the lack of options.
Me too.
 
Old 11-29-2009, 11:33 AM   #11
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quote:
Originally Posted by archtoad6 View Post
Another option you forgot was "Only if I have time on my hands".
And another: "Only if I have blood on my hands".
 
1 members found this post helpful.
Old 11-29-2009, 04:47 PM   #12
tredegar
LQ 5k Club
 
Registered: May 2003
Location: London, UK
Distribution: Debian 11
Posts: 6,133

Rep: Reputation: 419Reputation: 419Reputation: 419Reputation: 419Reputation: 419
@ abefroman

You started this thread, with a question that has been helpfully answered by useful and informative replies from the users at LQ.

You have not come back to the thread that you started.

Meanwhile, you have been very active on LQ, starting other threads, but not responding to this one that you started (or the others, but I cannot be bothered to search further):

http://www.linuxquestions.org/questi...d.php?t=772016
http://www.linuxquestions.org/questi...d.php?t=771983
http://www.linuxquestions.org/questi...d.php?t=771745
http://www.linuxquestions.org/questi...d.php?t=771591

Can you think of any reason that I (we) should not add you into the LQ_Useless_Posters file?

Your reply and explanation will be well received. Perhaps I have misunderstood something, but if you would like further help, please explain yourself.
 
0 members found this post helpful.
Old 11-29-2009, 05:52 PM   #13
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
tredegar:

His question was:

Quote:
Do you email abuse departments of people abusing your network?
IMO, the answer is either yes or no. Even the poll selections aren't to your liking, you can either opt out of answering or leave a comment.

I don't think he's looking for anything in particular, even if I attempt to read into his question. It's a poll question, not something that he appears to have any particular issue with.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Email Relay abuse novice06 Linux - Security 7 03-29-2006 06:53 PM
email abuse ice99 General 3 11-20-2005 09:55 AM
Email abuse Jon Doe Linux - Security 25 07-01-2005 03:59 PM
abuse@email.com security warnings emetib Linux - Security 5 09-24-2004 06:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration