nanog mailing list archives

Re: Re[4]: "portscans" (was Re: Arbor Networks DoS defense product)


From: Ralph Doncaster <ralph () istop com>
Date: Sun, 19 May 2002 11:22:08 -0400 (EDT)


If they don't give a satisfactory bank somewhere else (or offer your
services ;)).  Certainly that is a better approach than scanning to
see what you can find out.  The organization receiving the scan has
no way of knowing what your intentions are -- and should interpret
them as hostile.

I think that's pretty stupid.  If I had my network admin investigate every
portscan, my staff costs would go up 10x and I'd quickly go bankrupt.
Instead we keep our servers very secure, and spend the time and effort
only when there is evidence of a break in.



Current thread: