|
-
June 24th, 2003, 04:55 AM
#28
hmm..Let me get this straight.
Your company has hired an outside service to create and host a website for it. You were concerned or just curious about the webhosting company's security, so you ran a SYN stealth port scan on it (presumably as su or root). The results came back with many open and filtered ports, leading you to believe it was insecure, as you could not see a use for many of the ports. Additionally, you would like to prove that this site is insecure so you can take over the web server administration duties for better pay (and to use *NIX instead of NT). Therefore, you began to do some footprinting and exploration. Furthermore, you invited us to help you prove it's insecure so as to help you take over the duties.
That is my understanding of the situation thus far, and in a more favorable light than I imagine a few others see it.
However, your handling of the situation leaves much to be desired. First of all, you are attempting to crack into a system OUTSIDE of your control, and without the permission of the owners. While you do have an interest in the security of your site, this is STILL illegal. Furthermore, you bring this up on a site adamantly anti-cracker and ask for help (whether it was the main focus or not is beside the point). Second, most, if not all, of those ports have legitimate uses in the context of the company. ftp, ssh, telnet, smtp, http, pop3, auth (TCP authentication), imap2, news, https, login, shell, klogin, kshell, and eklogin are all services that are enabled on some server or another on the internet and have legitimate purposes in use or administration, and for a large web hosting are to be expected. Don't believe me? google for them, one by one, down the list to find out the purpose and use of all these ports. Also, all those other ports are filtered. Filtered does not mean open. It doesn't mean closed either, but importantly they are not open.
Now for the last item of my hit list: your very abusive post in response to HTRegz. While there is some reason - he was shooting you down again and again, it is not nearly enough for an outburst like that. First, you should have more control than that. Second, you better get used to criticism or you will never survive on the net (at least, if you want to participate and not just watch), nor in the real world - react like that to your boss's criticism, and you will be on the street before your workday ends. That post was childish, immature, and entirely inappropriate. If you don't like what he says, ignore him. If he challenges you, come back with an intelligent reply. Not only did that post portray a lack of control, it also insinuates that you have no clue what you are talking about, that you are incapable of properly defending yourself, and so you are resorting to personal attacks. Further, even what you did say was uninformed, presumptuous, and prejudicial. Before you attempt to do anything resembling this again, I suggest that you do a bit of research into the person you are trying to insult, and be well aware that what you say may cause ill will toward you from more than just your target and his/her friends.
Grow up, gain some self control, read up on law in regards to the internet, and learn. You will be better for it, and if you don't, it's your loss.
Preliminary operational tests were inconclusive (the dang thing blew up)
\"Ask not what the kernel can do for you, ask what you can do for the kernel!\"
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|