[PLUG] The lion in Salem
Jeff Schwaber
freyley at gmx.net
Fri Aug 29 12:34:02 UTC 2003
On Fri, 2003-08-29 at 12:02, AthlonRob wrote:
> On Fri, 2003-08-29 at 10:43, Cliff Wells wrote:
>
> > And it bothers me that running nmap is considered a crime. It's called
> > "looking". Often people use "looking" as preparation for comitting a
> > crime. More often they don't. Perhaps next time someone walks past my
> > house and gives it a twice-over, I should call the police. They might
> > be casing the place.
>
> As much as I hate to contribute to the continuation of this thread...
>
> nmap isn't just looking so much.
>
> To make the comparison of somebody on the street 'nmap'ing your house...
> they don't walk past it, taking two looks at it.
Okay, I've heard all the analogies before, and I've been disgusted each
and every time by everyone's fundamental lack of understanding that an
analogy is only useful so much as it fits.
A server is not a house. A machine on the network IS NOT YOUR PERSONAL
HOME.
It might be a slightly better analogy if you compared a server to a
business, as a server offers services. I could make another analogy
suggesting that nmapping is a way of asking a server what services it
offers, as well as checking out the building, by walking into the store
and looking around.
But that, too, would be a FLAWED analogy. Hugely flawed.
Rather than trying to use flawed analogies to spin the actuality, can we
study for a moment the actuality?
nmap studies a server, which is a machine intended to be publicly
accessible in some manner (or highly misconfigured), and it gets a whole
bunch of data about it. Yes, that data could be used to look up security
vulnerabilities, but nmap the tool does not itself print those out, nor
does it have capabilities to search for security vulnerabilities. That
is left to the user.
Nmap is a tool, and the information it gathers is publicly available,
simply because you put the machine on the net with the intent of
providing services (if you didn't intend to provide services, that's
what firewalls are there for--allowing a machine to be on the net
without providing services).
running nmap on a publicly available server should not be criminal.
Whether or not it is will be decided by technophobic judges, but as long
as techies fail to understand the definition of analogy, they really
desperately worsen the situation.
Jeff
More information about the PLUG
mailing list