Re: what to do with a script kiddie

carnack <[email protected]> Sat, 4 Jun 2005 19:19:11 +0200
Newsgroups gmane.comp.security.honeypots
Message-ID <[email protected]>
On 04.06.2005, at 19:08 Uhr, David Jiménez Domínguez wrote:

> You shouldn't expose him, you are studying him (when you are studying 
> an animal for scientific proposes you don't expose the animal itself, 
> you expose your work)... If you're going to use this information for 
> your thesis just use it. You could share it with the community like 
> the honeynet project does.

Dear David,
I will share if I find something interesting, but the incident was 
nearly the same as told in the "Linux Compromise" chapter of "Know your 
Enemy" by the Honeynet Project. So I see no further sense to share that 
info. I recovered all the incident files, like the rootkit, a local 
root exploit and an IRC bouncer, but they are nothing special and easy 
to come by.
yours
Christian