Archives

April 2004 (7)
March 2004 (12)
February 2004 (12)
January 2004 (22)
December 2003 (19)
November 2003 (16)
October 2003 (26)
September 2003 (18)
August 2003 (38)
July 2003 (80)
June 2003 (13)
May 2003 (24)
April 2003 (76)
March 2003 (75)
February 2003 (51)
January 2003 (73)

Category

Family (5)
FYI (18)
Games (2)
Geek (88)
Geographic (3)
Hacks (13)
Home (15)
Humor (54)
Ideas (20)
Ideaspace (15)
Local (15)
Metadata (10)
Microsoft (2)
MovableType (5)
Nitwits (66)
PKI (2)
Politics (22)
Quotes (3)
RDF (15)
RSS (4)
Security (3)
Semantic Web (13)
Site Info (13)
Social Networks (1)
Spam (9)
Sysadmin (1)
Tips (2)
Tivo (2)
TMFTOTHD (1)
To Do (1)
Unlisted (1)
Web (3)
Windows (1)

Local

« MetroBlogs »
DC metroblogs
beltway bloggers

Links


Assorted bits

Blogroll Me!
GeoURL
Listed on BlogShares




April 04, 2003

exploit reporter?

I'm not one to pay much attention to referral or web access logs. But recently I've had to delve into some and was unpleasantly surprised to find a fair amount of requests for various security exploits. Like looking for formmail.pl, default.ida and a host of others. The hacks don't work, of course, but the people running these searches should be exposed.

Why not deploy some sort of service that collects the IP addresses and uses them during future page deliveries?

Basically, when someone runs exploit searches like this keep track of it. Then when they try reading other, legitimate pages, stuff a warning box of some kind that says "someone from your IP address has been running a exploit search" and give them links to a report page. Basically 'out' them and their ISP. Shame them, if such a thing is possible, into ceasing this behavior. Couple it with geographic lookups so others in their area can start 'applying pressure' to them. Pitchforks and torches, wielded by angry mobs, are often mighty fine ways to apply said pressure.

And even when some poor soul is using a dial-up number that some spammer used before, give them the same error message with a link that says something to the effect of 'hey, if this isn't you then it's someone else your ISP is dumb enough to let onto the Internet'.

Just a thought, oh lazy web...

Nitwits
Perma  | Comments (0) | TrackBack (0) | 12:41 PM  | xml
Comments
Post a comment






* if you do not leave a valid e-mail or URL your comment may be deleted *







Navigation

Recent Entries

America and Europe: Vive la différence?
Server changes afoot
Diet behavior mod
Googling for sensitive info
Outlook 2003 and IMAP, a marriage made in Hell
Bike to Work Day, May 7th
Speakeasy rocks
Zippo USB?
When geographic data is nowhere 'near' correct
Local campaign contributions

User comments
Trackbacks

Contact

send me an e-mail E-mail
chat with me using MS messenger MSN Messenger
chat with me via AIM America Online
chat with me on ICQ ICQ
chat with me on Yahoo! Yahoo
Add my vCard to your electronic addressbook vCard
Friend of a Friend FoaF

Syndication

XML  RDF  CDF

Comments

XFML

Extra Stuff

foaf
vCard
pgp info
Linked In
Powered by
Movable Type 2.64