Security Incidents mailing list archives

Re: What use is the NIPC?


From: "Jay D. Dyson" <jdyson () treachery net>
Date: Mon, 6 Aug 2001 01:48:05 -0700 (PDT)

-----BEGIN PGP SIGNED MESSAGE-----

On Sun, 5 Aug 2001 aleph1 () securityfocus com wrote:

I've yet to hear from the NIPC. Not a problem. I am probably not the
only person to report the worm. They are probably busy with their own
analysis. But it is surprising that they have yet to put out an alert. 

        This comes as no surprise at all, especially considering that one
NIPC agent was single-handedly responsible for spewing a sizeable chunk of
data when his system was hit by Sircam.

        Normally I would say that NIPC is a has-been...but that's
impossible since it never amounted to anything in the first place.

        As an aside, I too am seeing a large upswing in CR probes; many of
which are repeated by the same IPs.  Additionally, CRv2 is now
outnumbering CRv1 probes by 2:1.

        "While the angels, all pallid and wan,
           Uprising, unveiling, affirm
         That the play is the tragedy, 'Man,'
           And its hero the Conqueror Worm."

                -- Edgar Allan Poe, "The Conqueror Worm" (1843)

- -Jay

  (    (                                                         _______
  ))   ))   .-"There's always time for a good cup of coffee."-.   >====<--.
C|~~|C|~~| (>------ Jay D. Dyson - jdyson () treachery net ------<) |    = |-'
 `--' `--'  `- Black as hell, sweet as love, swift as death. -'  `------'

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: See http://www.treachery.net/~jdyson/ for current keys.

iQCVAwUBO25LublDRyqRQ2a9AQFqAQQAjPo1+zTIof3A66eOhTWaQjo901R8jkVp
1/ZGJvlTu9eyd2ilLFx0bSLIuXQNZXjuoFYD/LrLrcqBUSRIeXYmpPvy9pTAQNZd
poXTmy1A78a1KXvEPP74KOIKHvRryq/LqZHHns/vNUWGSbAcbxPGO5M2Cx3t5Xuy
7NNXmGDlDHY=
=JQ7V
-----END PGP SIGNATURE-----


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: