Security Incidents mailing list archives

Re: Annoy Those Sub7 Scanners.


From: Frank Knobbe <FKnobbe () KNOBBEITS COM>
Date: Tue, 29 Aug 2000 20:11:15 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

-----Original Message-----
From: Dan Hollis [mailto:goemon () ANIME NET]
Sent: Sunday, August 27, 2000 8:47 PM

The cops disagree with you. Properly handled, logs are more than
just hearsay, and also contribute to convergence of evidence -- a
basic concept of law.

We have successfully prosecuted using logs. Although they were not
our only evidence, they did play a key part proving malicious
intent.

Yeah, but these logs are used for correlation. Do you prosecute
people that are just scanning you? I don't think any law enforcement
agency would give a hoot if you have been scanned but not broken into
(trespass, destruction of IP, etc). Logs play a crucial role in
forensics in case of a real incident. But is a portscan an incident?

Regards,
Frank

PS: I agree with the statement made about not luring people into your
machines by running something on a port you normally wouldn't have
open.

-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.1
Comment: PGP or S/MIME (X.509) encrypted email preferred.

iQA/AwUBOaxfM0RKym0LjhFcEQJt4wCgrhzdEHBq2KmgpzxPoESKZKzIh5wAnAiz
eufhhZ0kzoM3/w0889/LjCmz
=QxaP
-----END PGP SIGNATURE-----


Current thread: