We had a State security audit
Paul B. Hill
pbh at MIT.EDU
Tue Mar 5 20:33:38 EST 2013
> One of my co-workers also caught the bogus CAS page, fired up jmeter and
> hit the bogus login page with 20,000 login attempts. That brought the
> bogus login web server down. Got to love DDOS. The auditors said that
> was unethical. Hehe.
If the machine was owned by the state, and was being used for an audit,
then launching a DoS attack on the machine was probably a violation of
state and federal law.
Count calling the reaction unethical instead of a visit from a
prosecutor a gift. :)
Paul
More information about the users
mailing list