Security Incidents mailing list archives
Re: Annoy Those Sub7 Scanners.
From: H Carvey <keydet89 () YAHOO COM>
Date: Mon, 28 Aug 2000 02:38:37 -0700
--- Dan Hollis <goemon () ANIME NET> wrote:
On Sun, 27 Aug 2000, H Carvey wrote:How about this...don't run anything at all, andthescript kiddies drop by once and for the most partjustgo away?How about this... we lose the dripping sarcasm before we make an ass of ourselves on a public mailing list?
I would agree...except I'm not being sarcastic at all. Your ealier post (which prompted my above response) stated that the use of port listeners keeps the script kiddies busy banging against the box, so that you can track their activities and prove their malicious intent. I say...why bother? If I'm on an NT box, then I wouldn't normally have port 111 open. Given that, there would be no valid reason for me to run a port listener or a deception toolkit on that port. The same goes for fake trojans...there is a Yahoo club called "Victim Exchange" in which lists of infected systems are exchanged...the lists include IP addresses and the respective trojan. It would seem to me that were an IP address to appear on such a list, the owner would experience increased traffic.
To whom are you "proving beyond all doubt their malicious intentions"? The cops? Your logs donotconstitute evidence.The cops disagree with you. Properly handled, logs are more than just hearsay, and also contribute to convergence of evidence -- a basic concept of law.
The key is "properly handled". Running a deception toolkit or some fake trojan and keeping it's logs does not constitute properly handled. Why not? B/c you would be collecting those logs and there is no proper chain of evidence...such logs can easily be created or altered in Notepad, vi, etc.
We have successfully prosecuted using logs. Although they were not our only evidence, they did play a key part proving malicious intent. Others have successfully prosecuted using logs.
While I have no doubt that logs have been successfully used to prosecute an individual, I doubt strongly (unless someone is able to provide compelling proof) that the logs collected by NukeNabber, FakeBO, or a deception toolkit could be used as such evidence.
Their ISP? They can just as likely ignore you ascancel their account. From what ive experienced, its more the latter. 90% of the time the ISP cancels the account with "this is a known baddie that ive already warned once, ive been waiting for proof they are still up to no good".
That is your experience. My experience, and undoubtedly others, differs...both from reporting malicious activity to performing vulnerability assessments as a consultant. __________________________________________________ Do You Yahoo!? Yahoo! Mail - Free email you can access from anywhere! http://mail.yahoo.com/
Current thread:
- Re: Annoy Those Sub7 Scanners., (continued)
- Re: Annoy Those Sub7 Scanners. Guillaume Filion (Aug 27)
- Re: Annoy Those Sub7 Scanners. H Carvey (Aug 27)
- Re: Annoy Those Sub7 Scanners. Doug Kahler (Aug 27)
- Re: Annoy Those Sub7 Scanners. Valdis Kletnieks (Aug 27)
- Re: Annoy Those Sub7 Scanners. Dan Hollis (Aug 27)
- Re: Annoy Those Sub7 Scanners. Greg A. Woods (Aug 28)
- Re: Annoy Those Sub7 Scanners. Snehal Dasari (Aug 28)
- Re: Annoy Those Sub7 Scanners. H Carvey (Aug 27)
- Re: Annoy Those Sub7 Scanners. H Carvey (Aug 27)
- Re: Annoy Those Sub7 Scanners. Dan Hollis (Aug 27)
- Re: Annoy Those Sub7 Scanners. H Carvey (Aug 28)
- Re: Annoy Those Sub7 Scanners. Forrester, Mike (Aug 28)
- Re: Annoy Those Sub7 Scanners. Pierre Vandevenne (Aug 28)
- Re: Annoy Those Sub7 Scanners. Frank Knobbe (Aug 30)
- Re: Annoy Those Sub7 Scanners. Talisker (Aug 31)
- Re: Annoy Those Sub7 Scanners. Computer Vegetable (Aug 31)
- Re: Annoy Those Sub7 Scanners. Talisker (Aug 31)
- Re: Annoy Those Sub7 Scanners. Robert G. Ferrell (Aug 30)
- Re: Annoy Those Sub7 Scanners. Bryan Andersen (Aug 31)
- Re: Annoy Those Sub7 Scanners. Bill Royds (Aug 31)
- Re: Annoy Those Sub7 Scanners. Forrester, Mike (Aug 31)
