nanog mailing list archives

Re: RBL-type BGP service for known rogue networks?


From: Valdis.Kletnieks () vt edu
Date: Thu, 06 Jul 2000 15:39:02 -0400

On Thu, 06 Jul 2000 12:22:09 PDT, Dan Hollis said:
Im not talking about spammer networks im talking about script kiddie
networks. We already have several systems for dealing with spammers but
none for script kiddies. (I cant be the only person who sees a problem
with this picture?)

The biggest problem is that it's a lot easier to verify that a given site
is a spamhaus.  Remember that source IP addresses (which is all that your
border router sees) are forgeable - making for a nice DOS attack.  Forge
packets from a competitor's site, get them labelled as a skriptz kiddie site,
and BGP-blackholed.
-- 
                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech


Attachment: _bin
Description:


Current thread: