spf-discuss
[Top] [All Lists]

Re: first spf-enabled spam

2004-04-13 11:28:31
On 13 Apr 2004 at 13:00, wayne wrote:

However, take a look at the amount of information you get from the
whois database for the IP address that sent your email to me:

    (wayne(_at_)footbone) $ whois 208.58.1.195
    RCN Corporation RCN-BLK-5 (NET-208-58-0-0-1) 
                                      208.58.0.0 - 208.59.255.255
    TELENET LLC EROLS-CUST-5117 (NET-208-58-1-192-1) 
                                      208.58.1.192 - 208.58.1.207
    
    # ARIN WHOIS database, last updated 2004-04-12 19:15
    # Enter ? for additional hints on searching ARIN's WHOIS database.
    
That's not very much info, and it isn't very obvious to me how to
contact the owner of 208.58.1.195.  

This here is just a summary, because this IP matched two entries in the
whois database. It shows that the IP is in a block assigned to RCN
Corporation, which in turn delegated this specific block to TELENET LLC.
So if you lookup NET-208-58-1-192-1 (with whois -h whois.arin.net
NET-208-58-1-192-1), you find the contact for TELENET LLC, and if this 
doesn't help, you can go the hierarchy up and complain to RCN, whose
info you can find querying for NET-208-58-0-0-1.

If you read "whois -h whois.arin.net \?", you see that you have a lot
more options that you think. Try the following: "whois +208.58.1.195".
The "+" will expand both net-blocks automatically, instead of just 
showing the summary.

So your argument about this doesn't count.

-- 
Ernesto Baschny <ernst(_at_)baschny(_dot_)de>
 http://www.baschny.de - PGP: http://www.baschny.de/pgp.txt
 Sao Paulo/Brasil - Stuttgart/Germany
 Ernst(_at_)IRCnet - ICQ# 2955403


<Prev in Thread] Current Thread [Next in Thread>