Security Incidents mailing list archives

Re: What to do if they ignore you


From: Paul Schmehl <pauls () utdallas edu>
Date: Thu, 14 Apr 2005 11:50:58 -0500

--On Wednesday, April 13, 2005 11:50:16 PM -0400 "Byron L. Sonne" <blsonne () rogers com> wrote:

I believe David gravely injured him and was taken far more seriously
after that.

Perhaps publish the offending address information... if you're getting
that kind of behaviour originating from their net, I'd wager they have
other problems and might be more easily exploitable than some other
address. There are people out there who would appreciate and make use of
that kind of info. Maybe pick the appropriate high visibility mailing
list or irc channel.

While perhaps personally satisfying, I believe this is very poor advice. Goliath just might decide that your publishing his exposure to risk put him at greater risk, and he might decide that *you* should be personally sued to compensate him for the results of that exposure.

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------


Current thread: