John Kristoff's Avatar

John Kristoff

@jtk.infosec.exchange.ap.brid.gy

UIC PhD candidate | https://Dataplane.org | Netscout. Internet infrastructure (#BGP, #DNS) and #infosec. Bit mechanic. Also: #Blues / tfr / #fedi22 ๐ŸŒ‰ bridged from โ‚ https://infosec.exchange/@jtk, follow @ap.brid.gy to interact

49
Followers
15
Following
589
Posts
11.11.2024
Joined
Posts Following

Latest posts by John Kristoff @jtk.infosec.exchange.ap.brid.gy

Original post on infosec.exchange

I'm sure there are some caveats about interpreting the pretty picture and data this way, but a neat visualization just the same.

"A map of all ~2,100 Swiss municipalities showing which provider handles their official email - grouped by jurisdiction - based on public DNS records." [โ€ฆ]

13.03.2026 18:28 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

@paulehoffman @msftsecurity @bagder I searched nugget for "ssh" - Yikes! Maybe 99.99% of the results are harmless, but what the heck is all that stuff ... and look at the download counts.

12.03.2026 22:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

#Hosting provider AlexHost (#AS200019) is raising the price of their low end U1 VPS (1 CPU, 1.5GB RAM, 10GB NVMe) from 4โ‚ฌ/month to 6โ‚ฌ/month. Two reasons for the increase are:

"The price of RAM has increased."

"[...] abuse of extremely cheap plans has also increased significantly."

12.03.2026 14:14 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Small #hosting provider Servitro (#AS213495) sent out this alert:

"Due to an urgent network issue, we need to replace the subnet 192.209.62.0/24 with a new subnet. This maintenance only affects servers currently using IP addresses from 192.209.62.0/24."

They were leasing this prefix from [โ€ฆ]

12.03.2026 14:08 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
DNS-OARC The DNS Operations, Analysis and Research Center. DNS-OARC has 38 repositories available. Follow their code on GitHub.

DNS-OARC has officially moved from #GitHub to #Codeberg.

This seems mildly noteworthy to me. They have a number of widely used DNS-related utilities and projects that had been on GitHub for many years.

https://github.com/dns-oarc

10.03.2026 12:37 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Contabo (#AS51167):

"[...] we are internally facing sharply rising market prices for state-of-the-art, server-grade components - in particular, high-performance RAM and other critical hardware - as a result of the rising AI demand."

VM prices are going up about 20% in April 2026.

09.03.2026 18:23 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

IP4 prefixes for.ir TLD name servers are being announced. TCP/UDP over IP4 queries are getting responses from most of those name servers.

There are inconsistencies between what is in the root and now in ir. The root zone has IP6 addresses for each .ir name server, but the .ir zone currently [โ€ฆ]

09.03.2026 18:17 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

RE: https://mastodon.social/@pid_eins/116198551587107672

Net and cloud people, this imay be worth a look? Some hard-coded net resources, temp server listeners, and DNS juju going on here it looks like.

09.03.2026 10:29 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

The differences are stark.

Cyber strategy Biden 2023: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf

Cyber strategy Trump 2026: https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf

06.03.2026 22:53 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

Aeza Group was put on the U.S. Treasury's OFAC list last year "for its role in supporting cybercriminal activity targeting victims in the United States and around the world."

The "international" AS is registered to an address in the U.K., while the "group" AS is registered in St. Petersburg [โ€ฆ]

06.03.2026 21:38 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Be sure to read the comments if you read the ICANN article on circleid

06.03.2026 21:28 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Weekend Reads

* Building a BGP map
https://kmcd.dev/posts/live-internet-map/
* Measuring DNS over IPv6
https://www.potaroo.net/ispcol/2026-02/v6dns.html
* ICANN root system governance
https://circleid.com/posts/icanns-ultimate-demise
* India DNS censorship examined [โ€ฆ]

06.03.2026 20:38 ๐Ÿ‘ 2 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/

https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/

Bar plots like these may raise more questions than answers.

Without any y-axis label what are we to make of this? We don't really have a sense of scale.

Are two months on the x-axis long enough to show correlation or just coincidence?

They show graphs [โ€ฆ]

[Original post on infosec.exchange]

06.03.2026 18:49 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Zenlayer (#AS4229 and others):

"[...] new pricing policy for public IPv4 addresses will take effect on March 31, 2026, reflecting rising IPv4 costs [...]"

"All compute products will no longer include complimentary public IPv4 addresses by default."

"Customers are strongly encouraged to [โ€ฆ]

05.03.2026 15:10 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

@xabean I've been caught by this a few times on remote systems. Thankfully I've always had the ability to remote console in.

You can set an alias name if that helps.

05.03.2026 14:07 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

@jerry In the DNS world there is the concept of newly active/observed/registered domains. This has been used for all sorts of things, from trend analysis, to alerting, to quarantine, to outright blocking.

I wonder if the concept could be applied here, and maybe even just to accounts from [โ€ฆ]

03.03.2026 22:49 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

RE: https://flipboard.com/@washpost/local-7equn4ocz/-/a-uHOwa-dOSgWMb01D41Px3Q%3Aa%3A419161690-%2F0

First the IP4 space, now the actual physical space.

03.03.2026 02:15 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Rock Me - Live by Hound Dog Taylor Listen now on your favorite streaming service. Powered by Songlink/Odesli, an on-demand, customizable smart link service to help you share songs, albums, podcasts and more.

Monday jam: Hound Dog Taylor | Rock Me | https://song.link/s/57QydZwmh2XCNmBoZtlfCi #blues

02.03.2026 16:04 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Dataplane.org (@dataplane@noc.social) The Internet Last Week * US/Israel Attacks on Iran Internet effects https://infosec.exchange/@ProjectAinita/116147653707149458 https://noc.social/@cloudflareradar/116151293471289304 https://mastodon.social/@IODA/116148656276570120 https://infosec.exchange/@dougmadory/116148738148192917 * NDSS Symposium 2026 https://www.ndss-symposium.org/ndss2026/ * Various US DoD route withdrawals https://stat.ripe.net/widget/routing-history#resource=360&starttime;=2026-02-22 https://stat.ripe.net/widget/routing-history#resource=647&starttime;=2026-02-22 https://bgp.he.net/AS6034#_prefixes https://stat.ripe.net/widget/routing-history#resource=34369&starttime;=2026-02-22 * Python infrastructure outage https://status.python.org/incidents/r47c43jw19zq #Iran #NDSS2026 #USDoD #Python

A few DoD's BGP withdrawals I looked at are covered by larger prefixes. I am not intimately familiar with these networks, but I think it would be a good guess to say these BGP updates reflect something related to the Israel-US strikes on Iran.

https://noc.social/@dataplane/116155288703209670

02.03.2026 01:08 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Weekend Reads

* Peering market evolution
https://blog.lacnic.net/en/peering-market-at-a-glance/
* BGP path security with ASPA
https://blog.cloudflare.com/aspa-secure-internet/
* HTTP/2 from scratch part 2
https://kmcd.dev/posts/http2-from-scratch-part-2/
* First subsea optic cable removal [โ€ฆ]

27.02.2026 20:41 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

RE: https://infosec.exchange/@jtk/114378253611506206

I have to assume he or whoever is responsible for the site has abandoned it, but someone is paying to keep the name and site running. Even more gambling links have since been injected throughout various pages.

[ alan-dershowitz .com ]

I [โ€ฆ]

26.02.2026 18:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

RE: https://mastodon.social/@botgov/116137836000900744

aicenter, earlycareers - two new exec office names

26.02.2026 17:03 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

OVH (#16276) releases prices updates on additional services (e.g., dedicated and virtual servers) to take effect 2026-04-01.

Monthly dedicated server price increases are mostly in the 3%-15% range. VM price increases are much higher, around 40%-60% in most cases! Lock in long-term prices now if [โ€ฆ]

26.02.2026 14:13 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Germany hosting provider Netcup (#AS197540) cancelled a planned sale about a day before it was to take place citing industry hardware pricing challenges:

https://forum.netcup.de/information/netcup-community/netcup-updates/21752-rampocalypse-an-honest-update-on-the-hardware-situation/

24.02.2026 14:14 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Don't Just Sing About The Blues by Cedric Burnside, Lightnin' Malcom Listen now on your favorite streaming service. Powered by Songlink/Odesli, an on-demand, customizable smart link service to help you share songs, albums, podcasts and more.

Monday jam: Cedric Burnside & Lightin' Malcolm | Don't Just Sing About the Blues | https://song.link/s/6ap0Ak7viTDadS3HXvg25o #blues

23.02.2026 19:15 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

Hetzner (#AS24940) is raising prices across the board by more than 30% in many cases on April 1, 2026 (no joke).

https://docs.hetzner.com/general/infrastructure-and-availability/price-adjustment/

They explained:

"The underlying causes of the increased costs are, among others, the exploding [โ€ฆ]

23.02.2026 17:44 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

It's only a /24 from from an edu to Nebius, but if you don't know Nebius, they are like a CoreWeave, which if you don't know, they are the two of the leading (start up) AI-driven, GPU-fueled infrastructure providers outside of the big, better-known hyperscalers (e.g., AWS, Azure, GCP) [โ€ฆ]

22.02.2026 13:38 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

@ricmac archive.org also has an opt-out, but either archive.today seemed to largely ignore those requests or site owners were unaware of archive.today's existence. This could be useful particularly after Google discontinued the cached page feature.

21.02.2026 20:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

RE: https://mastodon.social/@botgov/116109524473900322

sotu - state of the union, currently 404
techcorps - new peace corps program
why - unknown (to me) exec office name

21.02.2026 17:52 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0