Advertisement
Promo

Toolkit

Story: 11,000 IP addresses found on accused hacker's PC

  • Previous comment

Posted by: Anonymous (Friday 10 October 2003, 10:14 AM)

  • Reply

11k IP-s... So what??? What kind of file(s)???...

My firewall log, for dial-up Internet access, on a single system, contains a rolling 12-month dataset (to cross-check for possible stealthed probes/attacks). This file has 16845+ log entries, with probably 9k of those being unique IP-s. I have a somewhat lesser number of entries in my IDS log for the same system. Easily, I've got 9k-10k IP addresses residing on this one system, many of these IP-s correlated with DNS names, NETBIOS names, ISP contact info, etc.

I'll wager that the vast majority of these IP-s were occupied, at the time of their log entries, by infected/compromised systems at the other end of the Internet... (But don't ask me how many of those IP-s may also have been unpatched for UNICODE exploits... I have no idea...)

Do these Iists make me a "criminal?" Particularly when these lists are an archival record of attempted tresspasses/penitrations against said system? All of these recorded events unsolicited and unwelcomed???...

WHERE ARE THE *ISP'S NETWORK LOGS* THAT SHOW THAT THE DEFENDANT'S COMPUTER/IP WERE BEING USED TO COMMIT/CONDUCT HOSTILE ACTS AGAINST OTHER SYSTEMS/IP-S??? *That* would be far more damning and convincing than 11k IP addresses sitting in a file...

What kind of investigative and forensic work was conducted??? By ZDUK's account, it all seems to have been very slip-shod, if not fundamentally ignorant...

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters