MESSAGE
DATE | 2013-03-28 |
FROM | Ron Guerin
|
SUBJECT | Re: [NYLXS - HANGOUT] [SECURE1@cablevision.com: case # 157902]
|
From owner-hangout-outgoing-at-mrbrklyn.com Thu Mar 28 15:52:00 2013 Return-Path: X-Original-To: archive-at-mrbrklyn.com Delivered-To: archive-at-mrbrklyn.com Received: by mrbrklyn.com (Postfix) id 8B589161C8E; Thu, 28 Mar 2013 15:51:59 -0400 (EDT) Delivered-To: hangout-outgoing-at-mrbrklyn.com Received: by mrbrklyn.com (Postfix, from userid 28) id 7448D161C91; Thu, 28 Mar 2013 15:51:59 -0400 (EDT) Delivered-To: hangout-at-mrbrklyn.com Received: from mail.vnetworx.net (mail.vnetworx.net [50.116.48.152]) by mrbrklyn.com (Postfix) with ESMTP id A0140161C8E for ; Thu, 28 Mar 2013 15:51:58 -0400 (EDT) Received: from [192.168.4.4] (ool-44c4e07e.dyn.optonline.net [68.196.224.126]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.vnetworx.net (Postfix) with ESMTPSA id D6ED71700251 for ; Thu, 28 Mar 2013 15:51:57 -0400 (EDT) Message-ID: <51549F5C.6040908-at-vnetworx.net> Date: Thu, 28 Mar 2013 15:51:56 -0400 From: Ron Guerin User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.11) Gecko/20121122 Icedove/10.0.11 MIME-Version: 1.0 To: hangout-at-mrbrklyn.com Subject: Re: [NYLXS - HANGOUT] [SECURE1-at-cablevision.com: case # 157902] References: <20130328163921.GA26843-at-panix.com> <51547BAF.7040200-at-vnetworx.net> <20130328182308.GA1358-at-panix.com> In-Reply-To: <20130328182308.GA1358-at-panix.com> X-TagToolbar-Keys: D20130328155156622 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-AV-Checked: ClamAV using ClamSMTP by generator.vnetworx.net Sender: owner-hangout-at-mrbrklyn.com Precedence: bulk Reply-To: hangout-at-mrbrklyn.com
On 03/28/2013 02:23 PM, Ruben Safir wrote: >>> We have been notified of 116 OOL ips involved in DNS abuse based attack on Spamhaus. These appear to be all Static IPs (Businesses) of ours that have DNS resolver mis-configured / unsecured. Many of our customers were unaware of the issue and have since corrected the problem on their side. >> >> Are they saying you're one of those 116? I didn't get one of these. >> >> In any event, shed no tears for Spamhaus, they stopped being the >> good guys long ago. There are no good people to root for in this >> dispute. >> > > How is it that Spamhuas is bad guys?
They started a spite listing list called the DBL where they routinely list things that have no business being listed (ie: well run services not emitting spam), except that the operators of Spamhaus don't like them. Call that what you like, I call it network abuse. They have become the thing they claim to despise.
> You know, the bottom line is these mother fuckers at cyberbunker layed > into the internet during the holiday and ran my DNS into the fucking > ground because they have a dispute with the community at spamhaus.
That's wrong for them to do, in any event.
> Then Cablevision says I don't need a recursive DNS. Really? So how do > I become an authoritative server for 23 domains.
You don't need a recursive server to serve authoritatively. That's what's meant by being authoritative. You don't look up the infomation elsewhere.
I believe the issue is you're recursive for everyone, and not just your own users. You need to run a recursive service for yourself, but you don't want to let the Internet at large to make use of it.
Forgive me if there was something in that PDF I should have read (I glanced at it). My eyes (and various other parts of me) are itching like there's no tomorrow, and I'm having to use them judiciously.
- Ron
|
|