[Dshield] Does anybody at DSHIELD understand whois

Johannes B. Ullrich jullrich at euclidian.com
Fri Mar 4 17:15:19 GMT 2005


I will see why these requests where not acted on. The 'URGENT' requests 
are usually responded to within a couple hours.

Our IP->Aubse mapping starts with whois, but we do have to cache these
records for a long time in order to not get locked out from whois servers.



Michael Nancarrow wrote:
> Actually not a list entry but a complaint.
> 
> We have received 5 DSHIELD emails in the last 40 days saying
> that we have a bad address scanning somebody in our range.
> Problem is that the addresses are not even close. Looks like
> DSHIELD have some lazy programming in that we have the top
> Address range as in 203.202.0.0 therefore it is assumed that
> 203.202.110.0 is one of our addresses. Wrong these are "C" class 
> address ranges. Maybe it is some other logic issue but I have replied
> stating "URGENT" and have not heard anything back.
> 
> Anyway can you please stop this.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
Url : http://www.dshield.org/pipermail/list/attachments/20050304/853e2b0c/signature.bin


More information about the list mailing list