Security Incidents mailing list archives

Re: Quova.net


From: lurker () ITIS COM (M J)
Date: Tue, 20 Jun 2000 12:44:06 -0000


I brought this up to the list back in May.  Apparently this 
activity has been going on for some time.  I've had a 
number of people (all over the world) respond privately to 
me regarding this so don't feel like the Long Ranger.  In 
fact - the technical contact from Quova informed me that 
they intend to scan all class A, B, and C networks!!  
Eeesh!  I demanded that our networks be excluded from their 
scans and after a number of phone calls and emails to Quova 
and to Exodus, I have not seen them poking around since.  
(I guess this could be because they actually removed our 
networks or they gathered as much info from us as they 
needed and then moved on)  I have all of the relevant 
contact information both from Exodus.net and Quova so if 
you want to get in touch with these people - email me 
privately and I'll give you all of the information I have 
(names, numbers, email, etc.).  

FYI - Exodus.net FULLY CONDONES this type of activity from 
their customers!!  

After a fruitless 20 minute conversation with 
their "security" contact, he couldn't understand my point 
and he told me that there is no useful information that can 
be gathered from a scan (ping, traceroute, etc.) and that 
I'm being too paranoid.  He then told me to just deal with 
it because they were not going to change their policy.  
Grrrr... (*scowls*)  Anyway - check out some of the 
incidents archives - a couple other people have posted 
regarding this.  Lemme know if I can provide any more info.

WOOT!

-m


Current thread: