Re: [marf] draft-jdfalk-marf-as

"J.D. Falk" <jdfalk-lists@cybernothing.org> Thu, 23 June 2011 19:51 UTC

Return-Path: <jdfalk-lists@cybernothing.org>
X-Original-To: marf@ietfa.amsl.com
Delivered-To: marf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7D78811E807A for <marf@ietfa.amsl.com>; Thu, 23 Jun 2011 12:51:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.499
X-Spam-Level:
X-Spam-Status: No, score=-6.499 tagged_above=-999 required=5 tests=[AWL=0.100, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r+VQskHIEkKt for <marf@ietfa.amsl.com>; Thu, 23 Jun 2011 12:51:40 -0700 (PDT)
Received: from ocelope.disgruntled.net (ocelope.disgruntled.net [97.107.131.76]) by ietfa.amsl.com (Postfix) with ESMTP id 7749011E8072 for <marf@ietf.org>; Thu, 23 Jun 2011 12:51:40 -0700 (PDT)
Received: from [192.168.1.191] (adsl-69-228-65-174.dsl.pltn13.pacbell.net [69.228.65.174]) (authenticated bits=0) by ocelope.disgruntled.net (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id p5NJp7n7023456 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT) for <marf@ietf.org>; Thu, 23 Jun 2011 12:51:39 -0700
X-DKIM: Sendmail DKIM Filter v2.6.0 ocelope.disgruntled.net p5NJp7n7023456
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cybernothing.org; s=triac; t=1308858699; bh=yEtW5kTUn+HkLrKdIWTxpJKl5PcljgvuQlwUugSsc IM=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date: Content-Transfer-Encoding:Message-Id:References:To; b=RQSM59/pKAKH iNvyRTomO7VEdejGFzHJAEVkX5m7gPewjOTGuRNq78VBUGhZYLFNf8s43s0WgbvwT9Q og1kFTwMxf4+evNPFiuzuVEByuYNjpc1l8ChgfD1rufqMAiWtJf82Kgd0g0iojj/sHg QrsbasRUmy4oD+cn2wCHFuZs8=
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Apple Message framework v1084)
From: "J.D. Falk" <jdfalk-lists@cybernothing.org>
In-Reply-To: <20110623192929.13813.qmail@joyce.lan>
Date: Thu, 23 Jun 2011 12:51:07 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <DF7FE29E-A65E-4406-AFE0-EBDBA5280EE9@cybernothing.org>
References: <20110623192929.13813.qmail@joyce.lan>
To: Message Abuse Report Format working group <marf@ietf.org>
X-Mailer: Apple Mail (2.1084)
Subject: Re: [marf] draft-jdfalk-marf-as
X-BeenThere: marf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Message Abuse Report Format working group discussion list <marf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/marf>, <mailto:marf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/marf>
List-Post: <mailto:marf@ietf.org>
List-Help: <mailto:marf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/marf>, <mailto:marf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jun 2011 19:51:41 -0000

On Jun 23, 2011, at 12:29 PM, John Levine wrote:

>> I don't believe that there's sufficient implementation experience for
>> an AS on non-solicited feedback, but I could be wrong.
> 
> I've been sending all of my abuse reports in ARF format for several
> years.  I get the target addresses by a combination of looking up rDNS
> in abuse.net and a largish local table of IP address ranges->domains.
> It works reasonably well, at least as well as sending messages just
> pasted in as text.  I used to get a lot of responses that said "we're
> too scared and/or incompetent to open your attachment so send it
> pasted in", but I haven't gotten any of those in a while.
> 
> My experience, which may or may not be typical of what other people
> would find, is that sending reports in ARF format works fine, but
> figuring out where to send them is a big challenge.  In particular,
> getting the addresses from WHOIS works poorly both because of the iffy
> quality of WHOIS data, and because WHOIS servers don't have the
> capacity to handle high volume scraping.

Since you're pretty much the only one, a "My Uncommon Practices" document could be useful.

--
J.D. Falk
the leading purveyor of industry counter-rhetoric solutions