OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: IDS: mouse trap + fight back!
From: John D. Burkett (jburkettcleveland.dynacs.com)
Date: Tue May 16 2000 - 12:41:28 CDT


Archive: http://msgs.securepoint.com/ids
FAQ: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
HELP: Having problems... email questions to ids-owneruow.edu.au
NOTE: Remove this section from reply msgs otherwise the msg will bounce.
SPAM: DO NOT send unsolicted mail to this list.
UNSUBSCRIBE: email "unsubscribe ids" to majordomouow.edu.au
-----------------------------------------------------------------------------
Fight back how?
If you mean actively such like .... "they" port scaned me, so I'm gonna
port scan them back....or...they defaced my web site, so I'm gonna deface
theirs.....Then I have ethical difficulty with that. Your mileage may vary.

By knowingly becoming offensive, one would be affecting all innocent "hops"
in between, adding traffic that otherwise wouldn't be necessary.
And...
Could this escalate?
Isn't this what some "gangs" do to prove superiority?
Could your business or clients become effected by this game?
Not to mention, perhaps said initial attack was accidental - this happens.

Having an offensive Policy response may have some "eye-for-an-eye"
justifications, but then you could be called upon to explain your self.

What would you say to explain your actions?
You could only hope that the person to whom you must explain your offensive
actions to, also happens to share your ethics.
Why put yourself in that position?

Does your ISP have an AUP that would be violated by offensive actions on
your part?
I suspect they may, which makes you the bad guy.

Where do you stop, where do you draw the line? If someone cuts your T-1
line with a hedge clipper out side your building, can you go to their
building and cut theirs in the same manor?

Perhaps these things are ethical questions that can very.
These are my 2cents. I would have an ethical problem using "zombie zapper"
type technology against hosts which are not under my authoritative
administration.

Often, if problems are ignored, generally they goes away without any extra
effort.
It seems simpler to block the site and move onto your next assignment.

There are other ways to fight, such as down the food chain (notify the up
stream provider).

-John

At 10:54 PM 5/15/00 , ajim de' great wrote:
>Dear all,
>
>I just wondering, is there any way we can fight back
>any intruders? Or is there any device can be used to
>fight back??? Is it ethical or not??? Need some help.
>Thanks!
>
>Just me,
>
>Nazim Jambli