Re: Malicious Use of GRC.COM

From: Administrator (Administrator@jfdi.com)
Date: 11/27/01


Subject: Re: Malicious Use of GRC.COM
Date: Mon, 26 Nov 2001 21:42:14 -0800
Message-ID: <BCC8282A57137A43BE52AB905B7DBAE2018329@sbs.jfdi.com>
From: "Administrator" <Administrator@jfdi.com>
To: <FOCUS-MS@securityfocus.com>

The problem you stated isn't as complex as all that....one needs only to
spoof an IP address (such as in, oh i dont know, win2k lan settings) and
upon starting IP agent the phony address shows up as a possible host to
scan with ShieldsUp. While it is supremely ironic that a guy who's so
sure that his way is the best way when it comes to security is having
his own site used for malicious port scans, this isnt any worse a threat
then any of the 2 million other port scanning softwares out there. If a
ShieldsUp scan reveals any vital information you weren't aware of, you
probably shouldn't be running a network ;)
 
Cheers,
 
Joe Borusiewicz
IT Manager
Rapport Leadership International, llc.
avail@lasvegas.net <mailto:avail@lasvegas.net>