Vulnerability Development mailing list archives

Re: Civil Disobedience


From: dan.ellis () sophos com
Date: Tue, 16 Oct 2001 11:18:52 +0100


On 10/15/2001 05:56:56 PM ethan wrote:

I can't begin to count the number of times that visitors to our site,
whom just got that spiffy new firewall on their windows box, have
emailed me, cc'd to the FBI, our upstream, and anyone else they can
think of claiming our servers were "breaking into" their machine.

It's a shame these 'spiffy new firewalls' don't come packaged with at
least a small amount of clue under the shrinkwrap. Having somebody
retrieve files via FTP from your server, and then send you, your
upstream etc the logs showing you trying to *ahem* 'hack' them on
the auth port and, astoundingly, the ftp-data port really goes to show
how over-paranoid and hysterical people can get.

Any newbie
with a firewall that suspects something is going to become a terrorist
spotter.

I'd have to agree that the reporting of every small incident leads to
a complete loss of perspective for some people.


--
Dan Ellis, Software Engineer                              Sophos Anti-Virus
email: dan.ellis () sophos com                           http://www.sophos.com
US Support: +1 888 SOPHOS 9                     UK Support: +44 1235 559933


Current thread: