[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] False-positive abuse reports from XMission's exit relay made against other relays
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Hello.
An ISP in Utah, XMission, runs their own Tor exit under the fingerprint
E3DB2E354B883B59E8DC56B3E7A353DDFD457812. Their exit has been running
for 14 whole years! But in the last few years, they appear to have
added an AbuseIPDB auto-submitter script that reports any UFW blocks to
AbuseIPDB, even if those come from fellow relays.
I'm sure a lot of you have seen xmission appear as a reporter against
your (middle and exit) relays on AbuseIPDB with a reports such as:
> Blocked by UFW (TCP on 36972) Source port: 9001 TTL: 47 Packet length:
> 2276 TOS: 0x08 This report (for 89.125.139.145) was generated by:
> https://github.com/sefinek/UFW-AbuseIPDB-Reporter
I've tried contacting their support and they may be slowly realizing
what the issue is, but I (and others) have already had relays suspended
by our hosting providers because of XMission's false reports, and they
do not appear to be doing anything about it anytime soon.
What can be done about this? At this rate, I'll have to shut a number of
my own relays down because of their false reports. The only other thing
I can think of is to block their IP, but I know that that's not good
practice. Is it a necessary evil in this case?
Could someone from Tor Project possibly reach out to them and explain
that their relay is auto-submitting false positive abuse reports against
other relay operators, if I'm unable to get through to them?
Regards,
forest
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCao5ARwAKCRAw+TRLM+X4
xsRVAP9nr/n4linFzJDSDnayuR4z8ZI83E7UsT6Mx1W4v+1fLQEA8vfxAOQm1R+2
liyMtXCw/cEyvUFto+1m0TBZMUaPywI=
=gyrl
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx