Re: Moving forward ...

David Nicol <[email protected]> Thu, 26 Feb 2004 16:24:58 -0600
Newsgroups gmane.ietf.asrg.filtering
Organization tipjar LLC
Message-ID <[email protected]>
Craig Hughes wrote:

>   hijacking "bad" network connections to either shut them down, or do 
> something else with them.


Reminscent of the suggested "attack handler" directives for web servers: 
when your web
server gets probed with a known IIS worm, instead of just redirecting 
them to an error page,
one replies with a command, designed to exploit the weakness known to be 
exploited by the
worm that is known to issue the probe in question, which will shut down 
the server that
is issuing the probe.

The down side is, whereas the worm was living as a parasite that was 
letting the host-machine
continue its operations, the proactive response of shooting infected 
patients on sight is
not, as I recall, legal in California.

I don't remember who sued whom to get who to stop, but someone got in 
trouble for
shutting down vulnerable and machines , and this was roundly regarded on 
slashdot as
a perfect example of judicial miscarriage.

-- 
[email protected].
Include phrase "cat and buttered toast" to get through my filter