Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Port scans legal, judge says
Kevin Poulsen, SecurityFocus 2000-12-18

Federal court finds that scanning a network doesn't cause damage, or threaten public health and safety.

Comments Mode:
Lame 2000-12-19
Anonymous (1 replies)
Lame (a reply by VC3) 2000-12-20
david.dunn (at) vc3 (dot) com [email concealed] (2 replies)
Extra Lame 2000-12-20
anonymous (1 replies)
Extra Lame (Another reply from VC3) 2000-12-21
david.dunn (at) vc3 (dot) com [email concealed]
Lame (a reply by VC3) 2000-12-21
Dazed and Confused (1 replies)
Lame (a reply by VC3) 2000-12-21
david.dunn (at) vc3 (dot) com [email concealed]
Get a grip 2000-12-19
Chip
Good for him. 2000-12-19
Your headline is misleading 2000-12-19
EJ (4 replies)
re: Your headline is misleading 2000-12-19
ThwartedEfforts (2 replies)
re: Your headline is misleading 2000-12-19
Sleeper (1 replies)
re: Your headline is misleading 2000-12-20
Anonymouse (1 replies)
Your headline is misleading 2000-12-19
merk_man (1 replies)
Your headline is misleading 2000-12-19
Ray L (4 replies)
Good guy getting blamed... 2000-12-19
anon-coward
Your headline is misleading 2000-12-20
Giezr
Your headline is misleading 2007-03-09
Sady.Org
Re: Your headline is misleading 2007-03-09
Sady.Org
judges decision 2000-12-19
jeff_schmitz (at) enron (dot) net [email concealed]
So if some one knocks on my door... 2000-12-19
garak (at) fastvcd (dot) com [email concealed] (1 replies)
Just don't do it. 2000-12-19
Anonymous Coward (1 replies)
Just don't do it. 2000-12-19
iNDiGO
Port Scan 2000-12-19
Bear
Interesting 2000-12-20
mickey
American Justice System 2000-12-20
b00tl3g
VC3 is Full of Crap! 2000-12-20
JamesF, web developer
Things not mentioned in the article 2000-12-20
A Fly on the Wall
Ringing a Doorbell or Checking for an Open Window? 2000-12-20
apersonwhosees thisalot
VC3 2000-12-20
Matthew F. Caldwell, CISSP <mattc (at) guarded (dot) net [email concealed]>
Wrong 2000-12-20
William Black (1 replies)
Wrong 2000-12-20
aardwolfe (at) yahoo (dot) com [email concealed]
Scanning illegal? 2000-12-20
vcloud
Doing his job. 2000-12-20
Bob C
Mistakes 2000-12-21
djmad (1 replies)
Mistakes .... 2000-12-22
cert (at) fvsh (dot) de [email concealed]
Intent is really the issue 2000-12-21
Scott Craig <scraig@MIfortune500(fake).com>
I don't have legal expertise. I do have security expertise. I've also dealt with legal departments.

Even when working with agreements with vendors, a lawyer sometimes wishes to know the author of the agreements intent for some of the particular statements. That doesn't mean the statement gets changed.

I've seen various research groups (independent and govt sponsored) that gather statistics. I imagine some research groups may wish to gather statistics to determine how much a service offering has grown.. such as determining the growth of FTP servers... just an example not something I've seen specifically. They could then determine that company XYZ seems to have 90% of the market and that the remaining 10% is shared between 3 other companies. That could prompt those 3 minority service holders to figure out why XYZ has an advantage and how they will go forward with their products.

Sometimes a corporate scan of a network may reveal networks it had no knowledge of. They may procede to see if the network has any hosts or if it's just a router to a network no longer used. Low and behold they could then find out they scanned the Acme Scooter company without knowing it. Would it be held illegal? I doubt it, because the intent was not to scan the Acme Scooter company network. As the employee turnover rate within IT continues the way it is, and the project initiatives climb, I'm sure there will be many things left undocumented and forgotten. The last company I worked for had a computer from 1985 that was still running that noone knew what it did, how to log in etc. Sometimes a network scan may be the only way to find out, or the first way before finding physical presence. With everything internetworking, business-to-business relationships, etc... by banning network scanning altogether for networks not belonging to you, it will end up being the equivalent of carrying a concealed weapon. Only the outlaws would do it.

Scott

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/126/4121#4121
Clarifications 2000-12-21
JAG (Just Another Geek)







 

Privacy Statement
Copyright 2008, SecurityFocus