Re: Sites blocking ISP Addresses

2022-12-01 Thread Grant Taylor via NANOG
On 12/1/22 10:21 AM, Owen DeLong via NANOG wrote: The WAF is under control of the site, but many sites blindly implement the recommendations of the WAF provider. I have heard tell of a CDN / WAF that is generally held in good regard having a free tier that many people use that is much less fle

Re: Fwd: Alternative Re: ipv4/25s and above Re: 202212010732.AYC Re: 202211220729.AYC

2022-12-01 Thread Tom Beecher
Mr. Chen- I don't have any interest in continuing this discussion on this topic. Best of luck to you. On Thu, Dec 1, 2022 at 7:44 AM Abraham Y. Chen wrote: > Dear Tom: > > Have not heard from you since the below MSG. Could you please let me > know if you have seen it, so that we can carry on by

Re: Sites blocking ISP Addresses

2022-12-01 Thread Mike Hammett
Pointing fingers is free. - Mike Hammett Intelligent Computing Solutions http://www.ics-il.com Midwest-IX http://www.midwest-ix.com - Original Message - From: "Owen DeLong via NANOG" To: r...@rkhtech.org Cc: "James Dexter" , nanog@nanog.org Sent: Thursday, December 1,

Re: Sites blocking ISP Addresses

2022-12-01 Thread Owen DeLong via NANOG
To make matters worse, many sites use CDNs with Web Application Firewalls. The WAF is under control of the site, but many sites blindly implement the recommendations of the WAF provider. So this allows the site to blame the CDN because they blindly implement their recommendations, while the CDN

Remote code execution bug in FreeBSD's ping (CVE-2022-23093)

2022-12-01 Thread Mike Lewinski via NANOG
Ooof. https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc Some hope here: "The ping process runs in a capability mode sandbox on all affected versions of FreeBSD and is thus very constrainted in how it can interact with the rest of the system at the point where the bug can occ

Re: Fwd: Alternative Re: ipv4/25s and above Re: 202212010732.AYC Re: 202211220729.AYC

2022-12-01 Thread Abraham Y. Chen
Dear Tom: Have not heard from you since the below MSG. Could you please let me know if you have seen it, so that we can carry on by avoiding the repeated open-loop situation with this thread? Regards, Abe (2022-12-01 07:44 EST) On 2022-11-22 23:23, Abraham Y. Chen wrote: Dear Tom: Pl

Mozilla and others move to distrust the "Trustcor" CA

2022-12-01 Thread Eric Kuhnke
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ Start from the top post for a full history.