Security Incidents mailing list archives

Re: Rooted Boxes


From: gabriel rosenkoetter <gr () ECLIPSED NET>
Date: Tue, 16 Jan 2001 16:23:08 -0500

On Tue, Jan 16, 2001 at 03:53:18PM +0100, Christian W. Zuckschwerdt wrote:
Is it okay to send a report to abuse@each-isp or perhaps a more suitable
address?

If you're comfortable being unsure whether or not it's a legitimate
sysadmin responding to the email, go right ahead. (There have been
several reported cases of emails sent to the owners of rooted boxes,
to which the helpful, remote sysadmin got concerned replies about
fixing the problem... from the script kiddies. The real sysadmin
never saw the mail.)

A phone number is still more reliable, till some form of identity
verification (PGP?) is more widespread.

       ~ g r @ eclipsed.net


Current thread: