NODE 53ca9178A serious question of ethics
nobody@pmantis.berkeley.eduWed, 2 Feb 94 23:31:05 PST
Ok, I'm in a bit of a quandry. While surfing the net last week, I
happened across an address addached to a machine that belongs the the
federal reserve. No big deal. I telnetted there on a lark, and entered
'guest' for the account. It dropped me into a shell. It didn't ask for
a password. Intrigued, I did a little looking around. Nothing special,
a CDRom and about 80 accounts. But(!!), /etc/passwd was there and
available and not using shadows. No, I didn't snatch a copy.
Quandry(ies)
1) Should I alert someone there about the obvious (and, IMHO serious)
seciruty hole?
or
2) Should I ignore it?
3) Should I take advantage of it (well, maybe not)
----------
I don't like to see systems so open, no matter who they belong too, and
the fact that the governments (whether you like them or not) has one this
open REALLY bothers me.
But, I also wonder what kind of trouble I could get into. Technically, I
violated something just by being there as I didn't have permission, and
the fact I accessed the passwd file makes it even worse. If I report it,
I could be in deep shit.
I could mail to them via a remailer (like penet.fi, so that they could
answer for more information if needed). That is a little securer and
Julf is out of jurisdiction of the FBI hunting me down.
Yes, I'm a little paranoid, but Uncle Sam likes to make examples out of
white-collar hackers, and for me it was pure and dumb luck (like a jury
would believe a 22 year-old computer geek isn't trying to gain illegal
access).
Any suggestions? Please? I consider this to be serious (most may not).
NODE 852fc9f8A serious question of ethics
m5@vail.tivoli.com (Mike McNally)Thu, 3 Feb 94 05:36:11 PST
This seems like a textbook example of an ideal use of a remailer.
What makes you hesitant to use that method? As you say, it's unlikely
that the government would go to the extensive trouble of trying to
bust you if you go through penet. The worst that could happen would
be that they'd ignore the blowing whistle, but that'd be their
problem.
Note that there may be some way that they could figure out where you
telnetted in from once you alert them to the security hole.
--
| GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com> |
| TAKE TWA TO CAIRO. ||| Tivoli Systems, Austin, TX: |
| (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |
NODE 59a608d6Re: A serious question of ethics
drzaphod@brewmeister.xstablu.com (DrZaphod)Thu, 3 Feb 94 12:09:44 PST
> 3) Should I take advantage of it (well, maybe not)
How about offering your services to them as a security
consultant.. grin.
--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
- DrZaphod #Don't Come Any Closer Or I'll Encrypt! -
- [AC/DC] / [DnA][HP] #Xcitement thru Technology and Creativity -
- [drzaphod@brewmeister.xstablu.com] [MindPolice Censored This Bit] -
- 50 19 1C F3 5F 34 53 B7 B9 BB 7A 40 37 67 09 5B -
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-