sks-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Sks-devel] Big amount of updated keys yesterday?


From: Daniel Kahn Gillmor
Subject: Re: [Sks-devel] Big amount of updated keys yesterday?
Date: Tue, 12 Apr 2011 14:15:32 -0400
User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.15) Gecko/20110402 Icedove/3.1.9

On 04/12/2011 01:58 PM, John Clizbe wrote:
> My first big hit came from pgp.surfnet.nl ~0930 CDT (US/Central - UTC-5:00)

Here's zimmermann.mayfirst.org's log of recent large (>99) hashdumps via
recon (timestamps are America/New_York):

> 0 zimmermann:~# cd /var/log/sks
> 0 zimmermann:/var/log/sks# (zcat recon.log.[543].gz; cat recon.log.1 
> recon.log) | egrep '[0-9]{3} hashes'
> 2011-04-11 13:34:50 499 hashes recovered from <ADDR_INET 
> [195.111.98.30]:11371>
> 2011-04-11 13:45:43 6854 hashes recovered from <ADDR_INET 
> [85.126.233.231]:11371>
> 2011-04-11 15:02:30 776 hashes recovered from <ADDR_INET 
> [208.84.222.190]:11371>
> 2011-04-11 15:10:12 256 hashes recovered from <ADDR_INET 
> [85.126.233.231]:11371>
> 2011-04-11 15:12:33 255 hashes recovered from <ADDR_INET 
> [195.111.98.30]:11371>
> 2011-04-11 15:41:02 957 hashes recovered from <ADDR_INET 
> [204.13.164.120]:11371>
> 2011-04-12 05:58:31 433 hashes recovered from <ADDR_INET 
> [94.142.241.93]:11371>
> 2011-04-12 06:07:54 107 hashes recovered from <ADDR_INET 
> [131.155.141.70]:11371>
> 0 zimmermann:/var/log/sks# 

So my first sighting of the increase was via kiss.niif.hu,, and the
major lump appears to have come from pgp.treefish.org.

Alexander Schmidt, Kiss Gabor, can you trace backward to see where you
got the burst data from?

Is this kind of forensics something we should think about
automating/graphing somehow?  It seems like it would be nice to have an
easy way to be alerted to unusual activity.

        --dkg

Attachment: signature.asc
Description: OpenPGP digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]