On Fri, 15 Feb 2002 08:35:29 PST, Christian Huitema <[EMAIL PROTECTED]>  
said:

> and extrapolate. I do not advise that you try the hacker's path, i.e.
> pick address at random and use hackers' tools to remotely sense the type
> of the equipment; it is bad practice, and your results would be tainted
> by statistical errors due to firewall practices.

An even bigger danger, statistics-wise, is assuming that because it's
answering on ports 25, 80, 109, and 119, that it's a server, when it's
more likely just another desktop machine running WAAAY too many services
by default....

How many people do you think found out they had IIS installed when CodeRed
or Nimda pointed it out to them?  And how many do you think are *still*
unaware they have IIS on their desktop system? ;)


-- 
                                Valdis Kletnieks
                                Computer Systems Senior Engineer
                                Virginia Tech

Attachment: msg07474/pgp00000.pgp
Description: PGP signature

Reply via email to