Re: SSH brute forcers

EBIOS SysOp <[email protected]> Mon, 6 Jun 2005 14:08:45 +0200 (CEST)
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Hello

When talking about ISPs and their misbehaving clients - what about
blacklisting ISPs, or a ranking them according to their professional
response when alerted about abusers coming out of their IP space?
Any bad/good feelings about it ?


Best regards
Wojciech Królik

On Thu, 2 Jun 2005, Smith, Donald wrote:

>
> Most of us do. I can not speak for all ISPs nor even for qwest.
> But here are some general comments.
>
> Most dynamic IPs are tracked back to an account not a MAC.
> To do that we need the ip, logs (proof) and time stamps with Timezone
> info.
>
> Depending on the ISP's AUP users may get several warnings before being
> disabled.
> Depending on the ISP's abuse staff load this might take a day or two.
>

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions