Re: [systems] Scans!

Andy Smith <[email protected]>
Newsgroups gmane.network.irc.blitzed.web
Message-ID <[email protected]>
Hi Michael,

We run opm.blitzed.org which is a DNS-based blacklist of hosts
running insecure proxy software.  Insecure proxies are a major
problem to the internet and are used for unsolicited email (spam)
and many other kinds of abuse.  Many other organisations use our
list to decide who they wish to accept connections from, the idea
being that they choose to not accept connections from insecure
proxies.

Approximately half of our list content comes from reports of IRC
abuse, and the other half comes from us investigating spam reports.
Whenever we receive a report we test each of the IP addresses within
to see if they run insecure proxies.  Any we find go into our
blacklist.

This was the reason for your firewall message; your IP address(es)
showed up as possible sources of unsolicited email (spam).

On Fri, Jan 31, 2003 at 09:02:28PM -0500, Michael S. McKallip wrote:
> 
>    Dear Sir/Madam,
> 
> 
> 
>    I'm  really  getting tired of seeing your source address in all my IDS
>    and  firewall logs. If you could please discontinue doing port scans I
>    would appreciate it.

Yes we can stop.  I will exempt you now.  However we do have several
copies of spam sent through your network, are you interested in
seeing them?  It is highly likely that you have users/customers who
are sending these emails.

I have attached two of these emails, more available on request.  Note:

Received: from [66.95.147.14] (helo=yatesco01.nhyates.com)
        by RS01.mondialteknology.com with esmtp (Exim 4.05)
        id 18bsyN-0001Bv-00; Fri, 24 Jan 2003 03:49:35 +0200

and:

Received: from [66.95.147.14] (helo=yatesco01.nhyates.com)
        by RS01.mondialteknology.com with esmtp (Exim 4.05)
        id 18cRqn-0007cc-00; Sat, 25 Jan 2003 17:04:05 +0200

>    Previously you said your service was just looking
>    for  mail  realys,  so  why  is  it that ports other than 25 are being
>    scanned?

I am not sure who said that, I can't immediately see any discussion with you
prior to today.  However, we do not test for open mail relays, our focus is
upon insecure proxies, which can exist in many forms on many ports.  Today,
some would say they pose a greater risk than open mail relays.

>    If this action does not stop, I will be forced to report your
>    actions to the authorities.

That will not be necessary.  By itself the act of testing hosts to
see if they are insecure proxies is illegal neither in your country
nor mine, and our upstream provider knows of our mission and that we
are not abusive.  However one of our rules is that we will exempt
from testing anyone who asks, and this has now been done.  If you
would like to provide details of your full IP range(s) then I will
exempt them all, rather than just the single IP 209.225.3.198.


Regards,
Andy Smith
Blitzed OPM
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.