Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Re: Highlighting Security Issues

Re: Re: Highlighting Security Issues

From: Marcus J. Ranum <mjr_at_ranum.com>
Date: Fri, 06 Aug 2004 13:41:19 -0400

firewalladmin_at_bellsouth.net wrote:
>And would you fake screenshots of stock quotes or would fake screenshots of porn if you were trying to get a guy in trouble?

Incompetence is not an offense in the government. If you're trying to get
someone in trouble, you need to make it look like they're committing a
bona-fide offense, not just something that's going to bring them a mild
wrist-slapping. In today's climate, making them appear to be involved in
child porn, or terrorism would be better.

Hmmm.... This makes me wonder about the shifts to the balance of
power that might happen if someone introduced a tool intended to
introduce spurious "evidence" for such a purpose. Stuff the victim's
cache with kiddie-porn, load their history, create an encrypted virtual
disk of snuff movies (with a crackable password) and perhaps a few
recipes for radiologic bombs... Then the tool could automatically
dime them out to HR and the FBI.. Such a tool could make a great offensive
weapon _or_ defensive weapon, once its existence was known.
"Someone must have gotten my hard disk with Cthulhu4.0! I swear!"
now becomes a an effort in plausible deniability.

mjr.

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Aug 07 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos