North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Disabling QAZ (was Re: Port 139 scans)

  • From: John Fraizer
  • Date: Fri Sep 29 16:37:29 2000

On Fri, 29 Sep 2000, Dan Hollis wrote:

> 
> On Fri, 29 Sep 2000, Mike Lewinski wrote:
> > "exit" will close the connection but not the QAZ server, while "quit" does
> > appear to shut it down. You can also "run x". Once QAZ has been shutdown,
> > it's also possible to connect to the share and manually delete the infected
> > notepad.exe, although I haven't yet figured out if there's a way to unshare
> > someone's drives remotely via command line (if I did this, I wouldn't be
> > able to get back in to clean the infection).
> 
> It would be cool if someone would make a tool that would auto-disinfect
> users...
> 
> -Dan
> 
> 


Yep.  The problem with that is that current laws on the books (in the US
at least) make this an illegal solution.  If memory serves me correctly,
the one I'm thinking about is worded something like:

"...any person who without authorization, accesses, modifies, deletes or
destroys..."

The penalties are pretty stiff too.  The best of intentions don't negate
the fact that it's illegal.

---
John Fraizer
EnterZone, Inc