We had a State security audit

Paul B. Hill pbh at MIT.EDU
Tue Mar 5 20:33:38 EST 2013


> One of my co-workers also caught the bogus CAS page, fired up jmeter and
> hit the bogus login page with 20,000 login attempts. That brought the
> bogus login web server down. Got to love DDOS. The auditors said that
> was unethical. Hehe.

If the machine was owned by the state, and was being used for an audit, 
then launching a DoS attack on the machine was probably a violation of 
state and federal law.

Count calling the reaction unethical instead of a visit from a 
prosecutor a gift. :)

Paul


More information about the users mailing list