Security Incidents mailing list archives

Re: Annoy Those Sub7 Scanners.


From: Pierre Vandevenne <pierre () datarescue com>
Date: Mon, 28 Aug 2000 11:03:39 +0200

On Sun, 27 Aug 2000 18:47:10 -0700, Dan Hollis wrote:

On Sun, 27 Aug 2000, H Carvey wrote:
How about this...don't run anything at all, and the
script kiddies drop by once and for the most part just
go away?

How about this... we lose the dripping sarcasm before we make an ass of
ourselves on a public mailing list?

Ahem...

To whom are you "proving beyond all doubt their
malicious intentions"?  The cops?  Your logs do not
constitute evidence.

The cops disagree with you. Properly handled, logs are more than just
hearsay, and also contribute to convergence of evidence -- a basic concept
of law.

Being a part of converging evidence if properly handled and proof
beyond all doubt are two different things, aren't they ?

We have successfully prosecuted using logs. Although they were not our
only evidence, they did play a key part proving malicious intent.

OK, but the thread was (is?) about Sub7 isn't it ? One doesn't get much
more than a few log entries in those cases.

If they ignore you, then you have found a grey or black hat network and
report it to your colleagues so they can firewall out that network.

This is not always possible unfortunately - if you are selling things
on the net, you don't want to reduce your potential customer base. If
you are running an e-banking service, you just can't deny your customer
access because some script kiddie was scanning for subseven from that
DHCP pool, etc... etc...

So what's the point of all these logs?

Cancelling script kiddies accounts, of course.

Wether you want to do this depends on a balance of different factors I
guess : wether you feel vulnerable to script kiddies attacks, wether
you have time to loose on them etc...


---
http://www.datarescue.com/ida.htm - IDA Pro 4.04 released !
alpha and more...


Current thread: