Full Disclosure mailing list archives
Re: Reacting to a server compromise
From: Peter Busser <peter () trusteddebian org>
Date: Sat, 2 Aug 2003 09:27:48 +0200
Hi!
My question is: Do I report this, and run the risk of the Feds charging me because these attacks originated from my subnet? Do I inform the owners of the machines that were hacked that their systems have been compromised? Judging from the usernames, some of these machines belonged to doctors offices, and may contain sensitive information. Or should I just have a nice cup of STFU, and pretend nothing happened?
I can understand that you want to try to stay out of trouble. But I think the ``right thing'' to do is of course to contact the other people as soon as possible. It makes sense too if you want to stay out of trouble. Because you clearly show that you care about what happened and want to limit the damage done to others. Keeping quiet is what an attacker would do. So you would act like an attacker, which makes it only harder to stay out of trouble if a few of those hacked machine owners find out your machine was the cause of the problem. Groetjes, Peter Busser -- The Adamantix Project Taking trustworthy software out of the labs, and into the real world http://www.adamantix.org/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Reacting to a server compromise Mark (Aug 01)
- Re: Reacting to a server compromise Peter Busser (Aug 02)
- RE: Reacting to a server compromise Wayne Chang (Aug 02)
- Re: Reacting to a server compromise SecuresDotComs (Aug 02)
- RE: Reacting to a server compromise Edward W. Ray (Aug 02)
- Re: Reacting to a server compromise Aron Nimzovitch (Aug 03)
- RE: [inbox] Re: Reacting to a server compromise Curt Purdy (Aug 04)
- RE: [inbox] Re: Reacting to a server compromise Ron DuFresne (Aug 04)
- RE: Reacting to a server compromise Edward W. Ray (Aug 02)
- <Possible follow-ups>
- Re: Reacting to a server compromise Jennifer Bradley (Aug 02)
- RE: [inbox] Re: Reacting to a server compromise Curt Purdy (Aug 03)
- RE: [inbox] Re: Reacting to a server compromise Michal Zalewski (Aug 03)
- RE: [inbox] Re: Reacting to a server compromise Curt Purdy (Aug 03)