Re: Interesting Apache logs

From: Barry Margolin (barmar@genuity.net)
Date: 03/26/02


From: Barry Margolin <barmar@genuity.net>
Date: Tue, 26 Mar 2002 00:25:33 GMT

In article <Pine.LNX.4.40.0203260049090.23243-100000@lxplus033.cern.ch>,
Alan J. Flavell <flavell@mail.cern.ch> wrote:
>I'm sorry: we (back at the campus - at cern I'm just another user and
>it's none of my business what their security scanner gets up to) try
>not to wait for victims to complain: known abuses are tested for, and
>nipped in the bud. I'm not saying that cases don't slip through, of
>course they do, but I'd like to see a more pro-active approach from
>other providers.

You've viewing it from a completely different perspective. Operating a
private campus network is different from operating an ISP, both in scale
(you don't have hundreds of thousands of customers, do you?) and in
customer expectations.

My cable modem ISP does (or at least used to -- they've gone through so
many mergers and acquisitions I don't know what their current policies are)
scan customer machines for certain problems; mostly things like
misconfigured WinGate, which allowed crackers to relay through the machine.
Many customers who did have firewalls would be alarmed at what seemed to be
port scans coming from the ISP's internal machines, until someone explained
to them that it was a preventative scan. Still, some customers felt that
it was no more proper for the ISP to be probing them than it would be for a
cracker; it's not the ISP's job to check up on them, they believed.

-- 
Barry Margolin, barmar@genuity.net
Genuity, Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.



Relevant Pages

  • Re: What protects Unices from Virus like attacks ??
    ... > what protects all Unix machines from such similar problems. ... Microsoft, ignored many of those ... Many MS customers don't know what to do ...
    (comp.unix.questions)
  • Re: What protects Unices from Virus like attacks ??
    ... > what protects all Unix machines from such similar problems. ... Microsoft, ignored many of those ... Many MS customers don't know what to do ...
    (comp.unix.programmer)
  • Re: [fw-wiz] The home user problem returns
    ... > The fact that ISPs are now seeing enough pressure (from customers, RBLs, ... > an antivirus app and personal firewall. ... that of a tech within an ISP. ... Afterall, what are folks ...
    (Firewall-Wizards)
  • Re: PLUG: PMAS
    ... I've just started using that zen.spamhaus.org as well, ... looking at my suggestion for a social solution rather than technical ... My ISP has recently tightened things up, as a couple of months ago the ... If you knew that all of your existing customers ...
    (comp.os.vms)
  • Re: GVR Meeting
    ... You certainly know what is best for GVR. ... > customers who raise valid issues. ... > increasing the total number of such machines, but by having some of the ... > play at any time, so they are usually available for a player who wishes. ...
    (alt.vacation.las-vegas)