RE: Legal? Road Runner proactive scanning.

From: Mark Medici (mark_at_dbma.com)
Date: 03/13/04

  • Next message: Burton M. Strauss III: "RE: FW: Legal? Road Runner proactive scanning.[Scanned]"
    Date: Fri, 12 Mar 2004 18:31:38 -0500
    To: "Bryan S. Sampsel" <bsampsel@libertyactivist.org>, <security-basics@securityfocus.com>
    
    

    > From: Bryan S. Sampsel [mailto:bsampsel@libertyactivist.org]
    > Sent: Friday, March 12, 2004 11:23 AM
    >
    > If you're the customer. However, if you're not the customer, they
    have no
    > legal right to scan your resources.

    That's a different matter, but still it's not illegal, at least not
    under any law that I have seen. But IANAL or a cop, YMMV and all that
    stuff. While I might not like someone scanning my ports, there is
    nothing particularly bad about it, unless it is done in such a way as to
    constitute a denial-of-service attack or harassment.

    Now, how the person scanning uses that information may be illegal
    (attempting an exploit) or negligent (unauthorized disclosure to third
    parties).

    Port scanning is such a common and innocuous occurrence that there's no
    reason for it to even be a part of your normal IDS alerts or reports.
    Just block it and log it and ignore it unless/until there's an
    escalation, then go back to the raw logs for evidence. Of course, if
    the port scans make it through to your DMZ or internal network, then I'd
    want to see alerts from the IDS's in those zones.

    As for testing all connecting SMTP servers for the presence of open
    relay/proxy, I think this is a matter of self preservation and a feature
    I'd personally like to see my MTA provide. It's hard to argue against
    something that makes good common sense.

    If it makes you feel better or more secure to firewall-off every IP that
    scans your ports or checks for open relays, then go ahead and do it.
    But expect to keep busy, and potentially loose communications from bona
    fide customers in the process.

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Burton M. Strauss III: "RE: FW: Legal? Road Runner proactive scanning.[Scanned]"

    Relevant Pages

    • Re: [exim] TCP Header Rewrite
      ... The trivial way is to set up N exim daemons, ... from ports 1024-1039; customer 2's mail can originate from posts 1040-1055; ... The fundamental problem is how your shaper can associate a particular ...
      (freebsd-questions)
    • RE: A question for the list...
      ... There seems to be consensus that competence is part of the ... * ISP would block all ports for incoming traffic by default, ... Suitable procedures could be defined to protect a compentent customer ...
      (Incidents)
    • Re: o2 to Orange number port, Orange tell me problems since last week?
      ... a network problem where these three numbers have failed to connect to ... As business telecoms, what kind of compensation are you, or your customer, ... As I only have Level 2 access on the account I am unable to speak to ... Over half of the 32 ports were botched in some way or other; ...
      (uk.telecom.mobile)
    • Re: Mozilla on Alpha question
      ... >> I understand that to some people the difference may not matter. ... unless you're a significant customer ... > I'm certainly not arguing that free software is the answer to everything. ... > makes sense to pay for it, by all means spend your money on it. ...
      (comp.os.vms)
    • Re: Freightlocate goes live
      ... issues to do with local taxation it shouldn't matter to the customer ... practice, of course, it does matter a little (I wonder how many UK ... Marston Gate, Bedfordshire, which is adjacent to Ridgmont station on ... Gourock, Inverclyde and Glenrothes, Fife, which is all of 25 miles ...
      (uk.railway)