<div dir="auto"><div><br><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Sun, 27 Sept 2026, 17:13 , <<a href="mailto:sm%2Bafrinic@elandsys.com">sm+afrinic@elandsys.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Logan,<br>
At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:<br>
>Yes. This can be used as data feed to update IP blocklists which are<br>
>maintained by Cybersecurity<br>
>Threat Intel companies.<br>
<br>
I commented about the topic yesterday while I was discussing about <br>
email: <br>
<a href="https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk" rel="noreferrer noreferrer" target="_blank">https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk</a> <br>
The usual companies in the vicinity don't sell those services because <br>
they don't see much value in it.  Those which sell threat <br>
intelligence services usually re-brand an existing product from a <br>
foreign company.<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">In a tightly regulated environment or "corporate" environment, putting a linux or bsd box to parse a database file from an RIR is very difficult. </div><div dir="auto"><br></div><div dir="auto">Auditors will come and ask: is the linux box certified, do we have a support contract, has the script you wrote been tested and vetted internally. Compliance can make some things "difficult."</div><div dir="auto"><br></div><div dir="auto">If the rir provides this as a csv or json file,</div><div dir="auto">There are less issues and the addition of the csv feed becomes a CAB item which has a strong business justification. The rir is considered the authoritative source which is trusted. </div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div class="gmail_quote gmail_quote_container"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
There is some code at <a href="https://www.elandsys.com/r/09740" rel="noreferrer noreferrer" target="_blank">https://www.elandsys.com/r/09740</a>  You will have <br>
to make some changes to the code to get it to do what you want.  You <br>
can also try this (set the variable to the one in code first):<br>
<br>
sh -c 'curl -sL "$url" | awk -F"|" '\''/afrinic\|.*\|ipv4/ <br>
{split($4,a,"."); ip=(a[1]*16777216)+(a[2]*65536)+(a[3]*256)+a[4]; <br>
print ip, ip+$5-1}'\'' | sort -n | awk '\''NR==1{prev_end=$2; next} <br>
{gap_start=prev_end+1; gap_end=$1-1; if(gap_start<=gap_end && <br>
(gap_end-gap_start+1)>=256) { s=gap_end-gap_start+1; printf <br>
"%d.%d.%d.%d - %d.%d.%d.%d (%d IPs)\n", int(gap_start/16777216)%256, <br>
int(gap_start/65536)%256, int(gap_start/256)%256, gap_start%256, <br>
int(gap_end/16777216)%256, int(gap_end/65536)%256, <br>
int(gap_end/256)%256, gap_end%256, s}; prev_end=$2}'\'''<br>
<br>
>I'm not sure I fully understand this statement. Can you please elaborate ?<br>
<br>
One side works on the clock while the other side waits for the <br>
adversary to go off the clock to run its operation.  If you are <br>
interested in, for example, fraud or advanced persistent threats, <br>
you'll need to be schedule your operation around the perceived <br>
threats.  You would also have to look for other information if you <br>
are doing an analysis.<br>
<br>
Regards,<br>
S. Moonesamy <br>
<br>
</blockquote></div></div></div>