ARF (Abuse Reporting Format)
Posted: 15 Mar 2010, 22:46
Greetings!
I've been using csf ever since i discovered it. It's awesome. Even recommended it today to an abuse dept. teamleader (of a company with 4k+ servers) after resolving an abuse matter.
During the chat i had with this person, ARF came up. It looks like an upcoming standard for reporting abuse, which i would defenatelly would like to see within csf.
There is also a perl module for it, see the next link ( wordtothewise.com/resources/mimearf.html ). More information on the subject, obviously on Wikipedia ( en.wikipedia.org/wiki/Abuse_Reporting_Format ).
I am aware that it is mostly used for email reporting. yet i know that fail2ban also implemented it somehow. I think it could be used for reporting bruteforce attacks to originating network owners. (example reports for login failures in ARF blocklist.de/downloads/report_ssh.eml / blocklist.de/downloads/report_postfix.eml ).
Anyway, keep up the good work!
ffs @ 5 posts url posting limit
I've been using csf ever since i discovered it. It's awesome. Even recommended it today to an abuse dept. teamleader (of a company with 4k+ servers) after resolving an abuse matter.
During the chat i had with this person, ARF came up. It looks like an upcoming standard for reporting abuse, which i would defenatelly would like to see within csf.
There is also a perl module for it, see the next link ( wordtothewise.com/resources/mimearf.html ). More information on the subject, obviously on Wikipedia ( en.wikipedia.org/wiki/Abuse_Reporting_Format ).
I am aware that it is mostly used for email reporting. yet i know that fail2ban also implemented it somehow. I think it could be used for reporting bruteforce attacks to originating network owners. (example reports for login failures in ARF blocklist.de/downloads/report_ssh.eml / blocklist.de/downloads/report_postfix.eml ).
Anyway, keep up the good work!
ffs @ 5 posts url posting limit