We had a State security audit

Paul B. Hill pbh at MIT.EDU
Tue Mar 5 21:01:04 EST 2013


As I understand the relevant laws, blocking them at the firewall is 
fine. Launching a DoS against a machine not owned by you is a problem.

Paul

BTW, hand warmers for don't leave a wet spot on the floor. You wouldn't 
want someone to slip and fall.

On 3/5/2013 8:45 PM, Bryan E. Wooten wrote:
>
>
> On 3/5/13 6:33 PM, "Paul B. Hill" <pbh at MIT.EDU> wrote:
>
>>> One of my co-workers also caught the bogus CAS page, fired up jmeter and
>>> hit the bogus login page with 20,000 login attempts. That brought the
>>> bogus login web server down. Got to love DDOS. The auditors said that
>>> was unethical. Hehe.
>>
>> If the machine was owned by the state, and was being used for an audit,
>> then launching a DoS attack on the machine was probably a violation of
>> state and federal law.
>>
>> Count calling the reaction unethical instead of a visit from a
>> prosecutor a gift. :)
>
>>
>
> This is interesting. We've had students on our network perform DDOS on our
> servers in the past. As soon as we detect it, we shut them down, usually
> at the firewall. We can't tell a state owned machine from a private
> machine on our network (think wireless or VPN). Did my buddy really break
> some law? Being proactive to protect patient and FERPA data?
>
>
> What a strange world. I can't jailbreak my phone and I can't protect state
> data? How do we differentiate a legit audit from a rogue state employee?
>
> -Bryan
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>


More information about the users mailing list