ietf-asrg
[Top] [All Lists]

Re: [Asrg] 7. BCP - Abuse reporting email [Was: Abuse Reporting standard]

2004-01-08 10:49:05
Jon Kyme wrote:
Andrzej Filip:

Markus Stumpf wrote:

On Wed, Jan 07, 2004 at 12:02:51PM +0000, Jon Kyme wrote:


I think "abuse" is pretty much the de facto standard, supported by

rfc2142,

adopting anything else would take some justifying.


Yes, but abuse @ whatdomain?
The most reliable information is the IP address from which the spam was injected into my system.
[...]


One possible solution would be to require RP (responsible person) DNS records in reverse DNS zones of */24 and */16 nets.

Two contact addresses make sense:
* abuse
* netmaster

This is an interesting idea - but somewhat orthogonal to a standard for the
*matter* of an abuse report. Which is, I guess, why you forked the thread.

I would not call it orthogonal, "where should the report go" is a separate but closely related issue worth starting a sub-thread.

This is the kind of data traditionally held in the whois - standardisation
in this area has been (is) difficult - I hear. Some of the registries and
registrars have "difficulties".

IMHO problems with single simple worldwide whois set of standards and keeping all the whois data "up to date" justify creation of simpler "email contact" standard. Whois data are managed by "a third party", reverse DNS is managed almost always by ISP or direct IP zone user.

Abuse reporting standard makes sense if it would allow automatic submission/processing including fully automatic finding of right destination of the report.

As I understand it, RP gives us someone to contact in response to a host
malfunction - I'm not sure that your proposed usage stretches this a bit?

May be a little bit.
The idea is to put email contact info into reverse DNS zones [*.in-addr.arpa] - IMHO RP record is the best choice for such task.

I'd like to sidestep all this by assuming that the reporter has obtained
(by an unspecified mechanism) a suitable address as the target for the
report. If a reliable and foolproof mechanism can be put in place for the
address discovery - so much the better.
But it's a separate issue.

So treat this sub-thread as a separate thread :)

--
Andrzej [pl>en: Andrew] Adam Filip http://anfi.freeshell.org/
anfi(_at_)priv(_dot_)onet(_dot_)pl anfi(_at_)xl(_dot_)wp(_dot_)pl [former: 
anfi(_at_)Box43(_dot_)pl]


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg