Author: H.User5946 (29 Nov 10 6:53am)
I just spotted the following reply in my logs (I've attempting to validate how well my mod_perl http:BL plugin is working).
88.234.182.81 "127.26.5.1"
http://www.projecthoneypot.org/ip_88.234.182.81
"This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)"
And further detail shows: Last Received From within 1 year, 4 months, 2 weeks
# host xxxxxxxxxxxxxx.81.182.234.88.dnsbl.httpbl.org
xxxxxxxxxxxxx.81.182.234.88.dnsbl.httpbl.org A 127.26.5.1
So why is the reply "127.26.5.1" ? That says Threat level 5 and last seen 26 days ago.
Thanks,
Paul Gregg
Same goes for: http://www.projecthoneypot.org/ip_89.0.7.209
[Aside: Why do I post as H.User5946 ? That didn't used to be the case]
Post Edited (29 Nov 10 7:33am)
|