[Dshield] Fightback program

Johannes B. Ullrich jullrich at euclidian.com
Tue May 29 13:51:01 GMT 2001

   You are not able to mark/unmark distinct records for 
'fightback'. However, you can switch your fightback option on
and off at any time. 

   As a solution, I maintain a list of known portscan services
(e.g. Shields Up, cablemodemhelp.com, hackerwhacker) that will
not be included as attackers in DShield. Whenever data is
imported, records implicating these IPs will be automatically
deleted. If you send me a list of IPs you wish to have included,
send it to me with some explanation and if possible some way of
verifying that these IPs are used by a security service. (e.g.
a web page that lists these IPs).

Johannes Ullrich            Join http://www.dshield.org
jullrich at euclidian.com
GPG Key ID: AE692033  Key: http://johannes.homepc.org/pgp.htm
Behalf Of Michael Boman
Sent: Tuesday, May 29, 2001 8:28 AM
To: dshield at dshield.org
Subject: [Dshield] Fightback program

Hello everyone,

I am just wondering if it is possible to use the fightback program 
selectivly? The thing is that I expect "hack attempts" from certain
(I've paid for it even!) and I don't want to cause them any problem..

I also wonder if I at a later stage (after the sign up procedure)
change my 
fightback option.

If anyone could answer these questions I'll probibly sign up for an
adding a quite large number of NIDS/Firewall locations (have NIDS 
sensors/firewalls all over the world).

Best regards
 Michael Boman

 I need to sort out my .signature someday....

