North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Advice requested

  • From: Roland Dobbins
  • Date: Tue May 29 17:16:13 2007
  • Authentication-results: sj-dkim-6; [email protected]; dkim=pass ( sig from cisco.com/sjdkim6002 verified; );
  • Dkim-signature: v=0.5; a=rsa-sha256; q=dns/txt; l=1671; t=1180460722; x=1181324722; c=relaxed/simple; s=sjdkim6002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; [email protected]; z=From:=20Roland=20Dobbins=20<[email protected]> |Subject:=20Re=3A=20Advice=20requested |Sender:=20; bh=YGRqmVqtIms2hszTuZQ//ocuiNXtHhpk20KKxKkPVJk=; b=BUeEQO/3hJ/KjO98E0xrzB+fHSRDWQD1fEfIaxPtpGNlyO9rvFcDJMI/UXjNli/xiOaPRtS3 OMddk4iacK/WabsttE1nKVNijiQrsT+90UwljQYNUhCEoMgo6Mnq308V;



On May 29, 2007, at 8:21 AM, Matthew Black wrote:

What would you do if a major US computer security firm
attempted to hack your site's servers and networks?

I think the first thing to do would be to attempt to determine whether they were trying to actually 'hack' anything, or whether they were doing some kind of hostscanning as part of a survey, or what (or even if it's traffic which isn't spoofed - i.e., is it TCP) - i.e., classify the traffic - and then if the activity is annoying/harmful/ undesirable, implement appropriate filtering mechanisms to block said traffic.


[Of course, various OS, application, and network infrastructure BCPs should be implemented so as to combat interactive cracking-type activity in the first place.]

The next thing to do would be to contact them directly and ask if they're aware of this situation - if so, ask what they're doing and ask them to stop if it's annoying/harmful, secondly if they're not aware, let them know so that they can see if they've an unauthorized individual/group generating the traffic in question, or perhaps have systems on their network which have been compromised and are being used for illicit activity.

IANAL, but I'd suggest trying to have a conversation before getting lawyers involved. Hopefully, it's just a misunderstanding of some sort, and can be resolved amicably.

------------------------------------------------------------------------
Roland Dobbins <[email protected]> // 408.527.6376 voice

You may not be interested in strategy, but strategy is interested in you.

-- Leon Trotsky