Security Basics mailing list archives

Re: Is portscanning legal? was Re: application for an employment


From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Wed, 5 Apr 2006 21:38:59 +0200

On 2006-04-04 c.s.wright () unn ac uk wrote:
Here, the port scanning has caused a server reboot and damage... but
would the exact same danger not also be there if I use a mass
downloader to download from the web site and cause the server reboot?

If the site has a set of terms and conditiuons that forbid mass
downloaders and site mirrors than you are violating the policy and if
you cause the damage you are liable.

Even if the site hadn't terms forbidding it one might be liable for
causing damage that way.

Port scanning with autorisation is legal,

Yes.

without is illegal.

No.

Just as driving with a licence is lefgal and without is iullegal.

Driving without license is illegal, because there are laws against it
(in Germany that's ยง 21 StVG). There are, however, no laws against
port-scanning.

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Tailor your education to your own professional goals with degree 
customizations including Emergency Management, Business Continuity Planning, 
Computer Emergency Response Teams, and Digital Investigations. 

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: