funsec mailing list archives
Re: Question for the group
From: Paul Schmehl <pauls () utdallas edu>
Date: Sun, 12 Feb 2006 16:35:43 -0600
--On February 12, 2006 4:04:26 PM -0500 TheGesus <thegesus () gmail com> wrote:
Of course I'm aware of this. Proxies have been scanned and abused for years. But this is different. The application "ezproxy", which is used by quite a few edus, is being specifically targeted, and unless there's some way to break out of the "normal" operation, the only thing you get, once you're logged in, is access to books, periodicals and databases that have research information in them.What I'm looking for is insight on *why* there would be massive, scripted attempts to get access to library proxies all over the world.Proxies are proxies. They get scanned. They get listed. I doubt if libraries are being singled out in any special way, unless they're "easy".
That's not exactly your "normal" proxy situation.
I have done a... ahem... less than casual study of open proxies over the last few of years. There was a dot-edu a couple of years ago with some sort of campus-wide Cisco content delivery system that was WIDE open. A port in every dorm, as it were. Point being, there's a little bit of a historical reputation dot-edus have to deal with.
Yeah, sure, and we've had them ourselves - usually when someone sets one up with our knowledge and then gets discovered.
I can't stress this enough - this is different. I guess I should be dicussing this on an edu list where folks are more familiar with ezproxy.
Paul Schmehl (pauls () utdallas edu) Adjunct Information Security Officer University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/ _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- favorite quotes from the malware sharing discussion Gadi Evron (Jan 01)
