Reputation Lookup for IPs
xzap writes "ZDNet is running an article about TrustedSource.org which is a new portal that provides reputation information for IP addresses. It can be used to configure your spam filters or when deciding whether to add an unknown host to your blacklist. Dmitri Alperovitch, a research engineer at CipherTrust said "Often companies don't realize that they have zombie machines on their network that have been sending e-mail. It may be more helpful for organizations to identify which systems on their networks are sending e-mail." Users can drill down to find more information on each domain. The portal is an initiative of CipherTrust who have previously been covered on Slashdot."
a reputation system for sites who don't try to slam you with a ginormous Flash advertisement the minute you load their site? Good Lord, and thank goodness for FlashBlock...
The World Wide Web is dying. Soon, we shall have only the Internet.
It showed my IP blocks as having raised concern, despite the fact that they're not on any black lists and I can't why it has drawn that conclusion. Also, using the domain checker, it has no knowledge of non-TLDs meaning it will treat xxx.org.uk and yyy.org.uk as the same domain - org.uk.
Tim Brown
You can bet that the spammers will look for ways to improve their standing. Being able to use a compromised computer to rank a page with positive points/karma/rating etc seems like a significant problem. If it's a negative-only system then those same compromised computers can blacklist IPs that aren't compromised, effectively reducing the 'average' past their own, leading to their own standing out as relatively whiter.
Hopefully CipherTrust will have a look at (for example) things Google has done with pagerank, and be able to address a problem that is significantly tied in with the problem it is trying to help with.
Browsing with +2 to insightful posts and a higher threshold makes the average post seen seem a lot more ingenious
of course this page would be more useful especially for everybody else... but at first glance at the summary I started to scratch my head and wonder why exactly somebody would make this.
Add to that admins who lease IP addresses for servers. You really don't need the IP address on your new dedicated server to have been recently held by a spam group.
__
Funny video clips for adults
``Why on earth should lots of machines be able to send email from inside a corporation? Surely some smarthosts and block port 25 at the border routers is the way to go.''
Hmm, I don't like that idea. It basically forces you to send your mail through an SMTP server on the same network. Most machines I use use the sendmail command, which, AFAIK, connects directly to the MX for the receiving domains. I like this behavior, because (1) it doesn't put unnecessary load on any outgoing SMTP server, (2) doesn't have a single point of failure, and (3) doesn't allow the administrator of the outgoing server to inspect/filter/modify/reject the mail I send.
How do other people feel about this?
BTW: I am aware that using an outgoing SMTP server is standard practice on Windows, that traffic that leaves the network can still be inspected/filtered/modified/rejected at the gateway, and that a gateway is also a single point of failure. The point is that having an outgoing SMTP server _adds_ a piece of infrastructure where these problems occur. Also, it's usually easier to do any kind of content processing on an SMTP server than on a router. So, considering all this, how do people feel about having or not having to use an outgoing SMTP server?
Please correct me if I got my facts wrong.
China has surpassed the US in the zombie race. According to this page: http://www.trustedsource.org/zombiemeter.php China has taken the lead. Still the US zombies are more effective since almost all spam originates from the US. You just wait until the Chineese gets the Dragon CPU up and running.
HTTP/1.1 400
For example, on the "IP" page, it said that 255.255.255.255 is sending spam, and that 224.1.2.3 "raised concern".
:-)
Of course, those are not valid unicast IP addresses.
On the other hand, 192.168.10.12 is "inoffensive". Phew!