This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/anti-abuse-wg@ripe.net/
[anti-abuse-wg] Adding a "Security Information" contact?
- Previous message (by thread): [anti-abuse-wg] addtess verification (was: personal data in the RIPE Database)
- Next message (by thread): [anti-abuse-wg] Adding a "Security Information" contact?
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Max Grobecker
max.grobecker at ml.grobecker.info
Tue Jun 7 11:45:05 CEST 2022
Moin-Moin and hello, TL;DR: Should there be an optional contact for sending security information to (i.e. about vulnerable services), which can be different from the abuse contact? Background: We get a reasonable amount of security information sent to our abuse mailbox about things like "There's a vulnerable Confluence server on your network" and "This IP has contacted a botnet C&C server". Technically, this is not an abuse related issue, but still relevant to know and forward to the respective customer. Most of these e-mails originate from our local CERT (in my case CERT-BUND in Germany) but there are some other senders which are informing about these vulnerable services. I guess, most other providers know about these from their local CERTs or other organizations. Our abuse mailbox is not overflowing with these, of course, but it makes semi-automated handling a bit painful. For example, we would like to forward these information to our customers, but we wont need to take further action on this, because we refuse to break into the offices of our customers at night and patch their software. Also, sometimes these reports contain outdated data and the vulnerability has been removed in the time between collecting these information and sending the e-mail. On the other hand, for real abuse like sending spam or participating in DDoS, we also want to forward this information as quick as possible (automated), but also we want to know about and escalate so we can pull the plug if needed. So I wondered, if there (c|sh)ould be an optional contact/role for sending security related information to? This could be a different mailbox which does another automated handling of forwarding this notifications. What is your opinion on this? Greetings Max
- Previous message (by thread): [anti-abuse-wg] addtess verification (was: personal data in the RIPE Database)
- Next message (by thread): [anti-abuse-wg] Adding a "Security Information" contact?
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]