Re: what would you do....
Quote:
Originally posted here by wgillam
If you're protecting (or trying to protect) a network that really doesn't have any sensitive information on it and you kept receiving hack/dos attacks, would you turn the matter over to the feds or would you intervene and get rid of the hacker yourself ? (i.e. use an IDS to monitor the intruder and then counter-hack.)
I would definitely gather as much information as possible and contact the proper authorities. You could wind up in more trouble if you try to counter attack the attacker, only making things worse. Although it sucks, the best way to go in cases like these is to inform the proper authorities and see what they can do - you'll have to hope for the best.
I know that it would make me feel good to go after some of these attackers, but I also know that I could wind up in deep water myself.
And KorpDeath beat me to it, Snort is pretty good.