Security Incidents mailing list archives

Re: Postmaster notify: User unknown


From: "Jay D. Dyson" <jdyson () TREACHERY NET>
Date: Tue, 19 Dec 2000 10:35:12 -0800

-----BEGIN PGP SIGNED MESSAGE-----

On Tue, 19 Dec 2000, Mark Collins wrote:

Is spam sent using other peoples mail servers legal? It is, afterall,
unauthorized access...

        It's one of those grey areas, technically akin to having a
world-writable anonymous FTP site.  Basically, the admin of the open relay
has given tacit permission for anyone to perform third-party relay through
them, just as the admin of the anonymous FTP site has given tacit
permission for any number of "warez pups" to dump and pump their various
and sundry collections on the server.

        Mind you, the abuse of the service isn't what the admin had in
mind, but the typical user did not have to elevate their privileges in
order to take advantage of the service in question.  Thus, it's really not
"unauthorized access" in the pure sense of the term since the admin did
authorize such access by leaving the service open for anyone's use.

        I understand that there are those whose philosophical
sensibilities are offended by this stance, but we're long past the days
when everyone played nice in the sandbox.

- -Jay

   (                                                            ______
   ))   .-- "There's always time for a good cup of coffee" --.   >===<--.
 C|~~| (>------- Jay D. Dyson -- jdyson () treachery net -------<) |   = |-'
  `--'  `------ ...You can have my absence of faith... ------'  `-----'

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: E-mail me for my PGP Public Key.

iQCVAwUBOj+qZdCClfiU/BIVAQGk/AP+Pibyv4tIb4hkKTJblPaopZtUQICT42xo
fuvC2VXik3uyxZlJOTXUBTZLzKsgi6+JvIcFiYP24MSbPlaNu3lJYv3wnqrOD7w8
UFF26n6tw1R3axiuHfIRPx/Cd4Jo6wprl3+b2/i0jmlEPUbWtAZmFbF8K+/XsWzX
Z9ZCdvJPWKE=
=t/yu
-----END PGP SIGNATURE-----


Current thread: