[ / / / / / / / / / / / / / ] [ dir / caco / dempart / druz / jenny / kurakao / lounge / tingles / vietnam ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
Verification *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

File (hide): 426d5aa58144d81⋯.png (376.51 KB, 512x384, 4:3, ClipboardImage.png) (h) (u)

[–]

 No.1060045[Watch Thread][Show All Posts]

Spamhaus is blocking port scanning

Vincent Canfield has been conducting a campaign to highight the wrongdoing of the aforementioned organisation

>Spamhaus has started a nasty campaign against Internet Researchers, and until now has gone mostly unnoticed outside the port scanning communities.

>Port scanning is a crucial activity for Internet Researchers. Port scanning allows researchers to know what services are running on the Internet, and in its simplest case a port scanning probe is a single TCP SYN packet. Market researchers port scan to calculate market share of various products.

>Spamhaus is an incredibly influential company. They have gained popularity with enough large tech companies that being listed by Spamhaus is a death sentence.

>The Spamhaus Block List (SBL) has historically been used to list IP addresses used to send spam, who attempt to hack into servers, and who host botnet controllers and infrastructure. Unlike with these activities, there is no way to prove that port scanning actually originates from a given IP address, meaning malicious actors are able to spoof port scanning traffic and inflict a sort of "blacklist attack" by causing innocent IP addresses to be listed.

>Spamhaus is listing all port scanning traffic without verifying the traffic comes from where it says. Instead of checking for e.g. banner scans, which require a TCP handshake or two-way UDP interaction, Spamhaus' honeypot servers are blacklisting all TCP SYNs it sees.

>https://vc.gg/spamhaus-post-draft.txt

>http://archive.fo/r1eeE

>https://www.theregister.co.uk/2019/04/16/spamhaus_port_scans/

>http://archive.fo/RxOFn

>https://twitter.com/gexcolo/status/1119046139020496896

 No.1060046>>1060048

lol. Did varg post this?

Anyways Vincent is based and Brian Krebs is massively unbased.


 No.1060048

>>1060046

>lol. Did varg post this?

Yes, and if you were so strongly bothered by the quality of the other thread, you could have done the same. In the rules list, there used to be one stating that between duplicate threads, the one of better quality gets to stay. https://8ch.net/metatech/rules.html Not sure why it's not there anymore...

Polite sage for off-topic.




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
2 replies | 0 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / caco / dempart / druz / jenny / kurakao / lounge / tingles / vietnam ][ watchlist ]