[Dshield] RE: Kornet.Net (et al)

michael nancarrow michael.nancarrow at ac3.com.au
Fri Mar 8 01:20:02 GMT 2002

My first post in here but I have been following for a number of months.
Regarding the Kornet Issue, I receive by my statistics more Hack attempts
from the U.S. than Korea and China, excluding spam. What's more the US
ISP's are just as bad, I still have after 6 months a Verizon customer
who has their DNS configured wrong and continually polls a non-used IP
address on my subnet. Emails to Verizon have resulted in his link being
reset, so I get a 5 minute break before he starts at a different ip address.
I sent an email to verizon saying his DNS is misconfigured and what happens,
his link gets reset again. I tell them contact the customer, his link gets
reset again. I try scanning him, his link resets again, every time a
IP. So please don't assume the US ISP' are any different from a global
perspective. I also raised this to CERT is the U.S. as well, what happened
a got an email back saying they contected Verizon, guess what his link was

Mike Nancarrow

