Security Incidents mailing list archives

Re: Annoy Those Sub7 Scanners.


From: H Carvey <keydet89 () YAHOO COM>
Date: Mon, 28 Aug 2000 02:38:37 -0700

--- Dan Hollis <goemon () ANIME NET> wrote:
On Sun, 27 Aug 2000, H Carvey wrote:
How about this...don't run anything at all, and
the
script kiddies drop by once and for the most part
just
go away?

How about this... we lose the dripping sarcasm
before we make an ass of
ourselves on a public mailing list?

I would agree...except I'm not being sarcastic at all.
 Your ealier post (which prompted my above response)
stated that the use of port listeners keeps the script
kiddies busy banging against the box, so that you can
track their activities and prove their malicious
intent.

I say...why bother?  If I'm on an NT box, then I
wouldn't normally have port 111 open.  Given that,
there would be no valid reason for me to run a port
listener or a deception toolkit on that port.  The
same goes for fake trojans...there is a Yahoo club
called "Victim Exchange" in which lists of infected
systems are exchanged...the lists include IP addresses
and the respective trojan.  It would seem to me that
were an IP address to appear on such a list, the owner
would experience increased traffic.

To whom are you "proving beyond all doubt their
malicious intentions"?  The cops?  Your logs do
not
constitute evidence.

The cops disagree with you. Properly handled, logs
are more than just
hearsay, and also contribute to convergence of
evidence -- a basic concept
of law.

The key is "properly handled".  Running a deception
toolkit or some fake trojan and keeping it's logs does
not constitute properly handled.  Why not?  B/c you
would be collecting those logs and there is no proper
chain of evidence...such logs can easily be created or
altered in Notepad, vi, etc.

We have successfully prosecuted using logs. Although
they were not our
only evidence, they did play a key part proving
malicious intent.

Others have successfully prosecuted using logs.

While I have no doubt that logs have been successfully
used to prosecute an individual, I doubt strongly
(unless someone is able to provide compelling proof)
that the logs collected by NukeNabber, FakeBO, or a
deception toolkit could be used as such evidence.

Their ISP?  They can just as likely ignore you as
cancel their account.

From what ive experienced, its more the latter. 90%
of the time the ISP
cancels the account with "this is a known baddie
that ive already warned
once, ive been waiting for proof they are still up
to no good".

That is your experience.  My experience, and
undoubtedly others, differs...both from reporting
malicious activity to performing vulnerability
assessments as a consultant.



__________________________________________________
Do You Yahoo!?
Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/


Current thread: