Search RPD Archives
Limit search to: Subject & Body Subject Author
Sort by:

[rpd] [off-topic] Humble feature request for quarantined/cleaned up IP addresses

Loganaden Velvindron loganaden at gmail.com
Sun Sep 27 14:17:54 UTC 2026


On Sun, 27 Sept 2026 at 15:53, Sylvain BAYA <baya.sylvain at cmnog.cm> wrote:
>
> Le 26 septembre 2026 09:23:43 GMT+01:00, Ben Roberts - AfriNIC via RPD <rpd at afrinic.net> a écrit :
> >Logan,
> >
>
> Dear Ben,
> Thanks for your email ; brother!
>
> >
> >It might be wrong to assume that all quarantined and returned space is contaminated. I’m sure that cyber threat blacklist companies have their own methods of determining address space with threats.
> >
>
> ...i think, it's more related to INRs squatting;
> but i would leave it to Logan to better
> explain it's context.

Dear Sylvain,

SM took the initiative to tackle the problem and included his own
views which add value
to the current discussions.

If SM can get something working  in a single day, do we really need a policy ?


I'm fowarding this email from afnog:
---------- Forwarded message ---------
From: <sm+afrinic at elandsys.com>
Date: Sun, 27 Sept 2026 at 17:13
Subject: Re: [afnog] Africacert opinion on cybersecurity threat Intelligence
To: Loganaden Velvindron <loganaden at gmail.com>, <afnog at afnog.org>


Hi Logan,
At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
>Yes. This can be used as data feed to update IP blocklists which are
>maintained by Cybersecurity
>Threat Intel companies.

I commented about the topic yesterday while I was discussing about
email:
https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk
The usual companies in the vicinity don't sell those services because
they don't see much value in it.  Those which sell threat
intelligence services usually re-brand an existing product from a
foreign company.

There is some code at https://www.elandsys.com/r/09740  You will have
to make some changes to the code to get it to do what you want.  You
can also try this (set the variable to the one in code first):

sh -c 'curl -sL "$url" | awk -F"|" '\''/afrinic\|.*\|ipv4/
{split($4,a,"."); ip=(a[1]*16777216)+(a[2]*65536)+(a[3]*256)+a[4];
print ip, ip+$5-1}'\'' | sort -n | awk '\''NR==1{prev_end=$2; next}
{gap_start=prev_end+1; gap_end=$1-1; if(gap_start<=gap_end &&
(gap_end-gap_start+1)>=256) { s=gap_end-gap_start+1; printf
"%d.%d.%d.%d - %d.%d.%d.%d (%d IPs)\n", int(gap_start/16777216)%256,
int(gap_start/65536)%256, int(gap_start/256)%256, gap_start%256,
int(gap_end/16777216)%256, int(gap_end/65536)%256,
int(gap_end/256)%256, gap_end%256, s}; prev_end=$2}'\'''

>I'm not sure I fully understand this statement. Can you please elaborate ?

One side works on the clock while the other side waits for the
adversary to go off the clock to run its operation.  If you are
interested in, for example, fraud or advanced persistent threats,
you'll need to be schedule your operation around the perceived
threats.  You would also have to look for other information if you
are doing an analysis.

Regards,
S. Moonesamy



More information about the RPD mailing list