<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: IT Security Warfare</title>
	<atom:link href="http://mcwresearch.com/archives/496/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com/archives/496</link>
	<description>Things I think I've thought about</description>
	<pubDate>Thu, 20 Nov 2008 09:31:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Michael</title>
		<link>http://mcwresearch.com/archives/496#comment-4748</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 27 Jun 2007 14:23:41 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/archives/496#comment-4748</guid>
		<description>As much as I'd like to trade metasploit volleys with someone attacking my network, it just isn't ethical as you mentioned and besides, the attacking IP is likely someone's mom's computer that has been compromised and is used as a proxy.  

However, we aren't without options.  Counter attacking in IT security involves gathering evidence that will hold up in a court of law and involving the authorities to pursue the attackers for you.  

Counter attacking would also include moving upstream and notifying the ISP of the attacking IP to let them know they have a compromised or malicious host on their network and hopefully they'll take action.  Allies can often take action you can't.  

Other actions you can take are to get involved with groups that take down bot herders and their C&#038;C channels.  The &lt;a href="http://isc.sans.org/" rel="nofollow"&gt;ISC&lt;/a&gt; is one such organization that everyone knows about.  

Hope your travels were safe!</description>
		<content:encoded><![CDATA[<p>As much as I&#8217;d like to trade metasploit volleys with someone attacking my network, it just isn&#8217;t ethical as you mentioned and besides, the attacking IP is likely someone&#8217;s mom&#8217;s computer that has been compromised and is used as a proxy.  </p>
<p>However, we aren&#8217;t without options.  Counter attacking in IT security involves gathering evidence that will hold up in a court of law and involving the authorities to pursue the attackers for you.  </p>
<p>Counter attacking would also include moving upstream and notifying the ISP of the attacking IP to let them know they have a compromised or malicious host on their network and hopefully they&#8217;ll take action.  Allies can often take action you can&#8217;t.  </p>
<p>Other actions you can take are to get involved with groups that take down bot herders and their C&#038;C channels.  The <a href="http://isc.sans.org/" rel="nofollow">ISC</a> is one such organization that everyone knows about.  </p>
<p>Hope your travels were safe!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickies on a Travel Day &#124; RiskAnalys.is</title>
		<link>http://mcwresearch.com/archives/496#comment-4747</link>
		<dc:creator>Quickies on a Travel Day &#124; RiskAnalys.is</dc:creator>
		<pubDate>Wed, 27 Jun 2007 13:20:50 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/archives/496#comment-4747</guid>
		<description>[...] is &#8220;on&#8221; in his last two posts on IT Security Warfare.   Problem is that we&#8217;re not really allowed all the benefits of counter-attack.  That [...]</description>
		<content:encoded><![CDATA[<p>[...] is &#8220;on&#8221; in his last two posts on IT Security Warfare.   Problem is that we&#8217;re not really allowed all the benefits of counter-attack.  That [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
