Greetings!
I've been using csf ever since i discovered it. It's awesome. Even recommended it today to an abuse dept. teamleader (of a company with 4k+ servers) after resolving an abuse matter.
During the chat i had with this person, ARF came up. It looks like an upcoming standard for reporting abuse, which i would defenatelly would like to see within csf.
There is also a perl module for it, see the next link ( wordtothewise.com/resources/mimearf.html ). More information on the subject, obviously on Wikipedia ( en.wikipedia.org/wiki/Abuse_Reporting_Format ).
I am aware that it is mostly used for email reporting. yet i know that fail2ban also implemented it somehow. I think it could be used for reporting bruteforce attacks to originating network owners. (example reports for login failures in ARF blocklist.de/downloads/report_ssh.eml / blocklist.de/downloads/report_postfix.eml ).
Anyway, keep up the good work!
ffs @ 5 posts url posting limit
ARF (Abuse Reporting Format)
-
- Moderator
- Posts: 1524
- Joined: 01 Oct 2008, 09:24
Hello,
the Abuse-Department can set a Priority for the Typ and Category and "Reported-From".
When you recive a Message with:
Reported-From: x1@domain.tld
Category: abuse
Report-Type: login-attack
you can give the report a high priority and parse them automatically. If the Report-Type not "login-attack" or the "Reported-From" is a other Address, so you can forward the Report to manually evaluate from your Abuse-Team.
The recipient can decide how it handles prioritize the reports or what action should be executed.
Martin
the Abuse-Department can set a Priority for the Typ and Category and "Reported-From".
When you recive a Message with:
Reported-From: x1@domain.tld
Category: abuse
Report-Type: login-attack
you can give the report a high priority and parse them automatically. If the Report-Type not "login-attack" or the "Reported-From" is a other Address, so you can forward the Report to manually evaluate from your Abuse-Team.
The recipient can decide how it handles prioritize the reports or what action should be executed.
Martin