Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Port scans legal, judge says
Kevin Poulsen, SecurityFocus 2000-12-18

Federal court finds that scanning a network doesn't cause damage, or threaten public health and safety.

Comments Mode:
Lame 2000-12-19
Anonymous (1 replies)
Lame (a reply by VC3) 2000-12-20
david.dunn (at) vc3 (dot) com [email concealed] (2 replies)
Extra Lame 2000-12-20
anonymous (1 replies)
Extra Lame (Another reply from VC3) 2000-12-21
david.dunn (at) vc3 (dot) com [email concealed]
Lame (a reply by VC3) 2000-12-21
Dazed and Confused (1 replies)
Lame (a reply by VC3) 2000-12-21
david.dunn (at) vc3 (dot) com [email concealed]
Get a grip 2000-12-19
Chip
Good for him. 2000-12-19
Your headline is misleading 2000-12-19
EJ (4 replies)
Your headline is misleading 2007-03-09
Sady.Org
Re: Your headline is misleading 2007-03-09
Sady.Org
re: Your headline is misleading 2000-12-19
ThwartedEfforts (2 replies)
re: Your headline is misleading 2000-12-19
Sleeper (1 replies)
re: Your headline is misleading 2000-12-20
Anonymouse (1 replies)
Your headline is misleading 2000-12-19
merk_man (1 replies)
Your headline is misleading 2000-12-19
Ray L (4 replies)
Good guy getting blamed... 2000-12-19
anon-coward
Your headline is misleading 2000-12-20
Giezr
judges decision 2000-12-19
jeff_schmitz (at) enron (dot) net [email concealed]
So if some one knocks on my door... 2000-12-19
garak (at) fastvcd (dot) com [email concealed] (1 replies)
Just don't do it. 2000-12-19
Anonymous Coward (1 replies)
Just don't do it. 2000-12-19
iNDiGO
Port Scan 2000-12-19
Bear
Interesting 2000-12-20
mickey
American Justice System 2000-12-20
b00tl3g
VC3 is Full of Crap! 2000-12-20
JamesF, web developer
Things not mentioned in the article 2000-12-20
A Fly on the Wall
Ringing a Doorbell or Checking for an Open Window? 2000-12-20
apersonwhosees thisalot
VC3 2000-12-20
Matthew F. Caldwell, CISSP <mattc (at) guarded (dot) net [email concealed]>
Wrong 2000-12-20
William Black (1 replies)
Wrong 2000-12-20
aardwolfe (at) yahoo (dot) com [email concealed]
Was Mr. Moulton doing a professional job, though?

I work for a security consulting firm. As part of that, we do "Ethical Hacking" or Penetration Attacks. We always verify with the client which IP addresses belong to him and ensure we have (in writing) permission to run port scans and other scans on those addresses, and we run our scans only on those addresses.

Yes, sometimes clients don't understand this - we had one client who refused to give us his IP addresses, on the grounds that "Real hackers wouldn't phone up and ask for this information". (We did a series on "whois" lookups on their sites, identified some IP addresses that we thought belonged to the client, and then asked him to confirm that these IPs did, in fact, belong to him and that we were authorized to attack them.)

A professional security expert should not be running port scans or ping sweeps or nmap or Satan or any other attack tool against IP addresses without permission from the owner, let alone without knowing who the owner is.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/126/4102#4102
Scanning illegal? 2000-12-20
vcloud
Doing his job. 2000-12-20
Bob C
Mistakes 2000-12-21
djmad (1 replies)
Mistakes .... 2000-12-22
cert (at) fvsh (dot) de [email concealed]
Intent is really the issue 2000-12-21
Scott Craig <scraig@MIfortune500(fake).com>
Clarifications 2000-12-21
JAG (Just Another Geek)







 

Privacy Statement
Copyright 2007, SecurityFocus