[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Piracy



In article <5e40t8$gvj@newslink.runet.edu>, dmcclain@runet.edu (Dennis
McClain-Furmanski) wrote:
> Joe, posting the list seems like a good idea, but it isn't. The 
> information recorded by ftp servers is offered by the caller. It takes 
> very little to spoof it. All you have to do is ftp with the command flags 
> set to force by-hand login rather than the automatic acct:anonymous and 
> pass:your@e-mail.addr. 
[...]
> A text file of anything sent over the net is not proof. Anyone can 
> write/edit anything. Trust me, I've been going at this for some time now.  

To Joe & others,

You could further spoof it by using a hacked version of identd on the
client's machine. What is to say that a client did not spoof the IP address
in the first place? Sure, it's really easy to point the finger using what
you may see as hard facts. However, the Internet and FTP protocol are by NO
MEANS SECURE. To think otherwise would be very foolish.. This is the real
world, not some ideal cyberspace described of by fiction writers.

Please read the RFC on the FTP protocol. Make yourself aware of the facts,
before you put full trust in something that is easily suseptible to
security violations and spoofing.

It would be a sad day when someone may download a file off an FTP site and
they might prosecuted because of it. Does the downloader know for a fact
that the contents of the file are commercial software? You cannot prove the
intent of a downloader to willingly download what may represent commercial
software from an FTP site.

What is to say that the user has not written a script that downloads all
the new files out of a particular directory on an ftp server. One day, a
secure document may be posted to the directory whether it be malicious or
accidental. Would you want the FBI knocking on your door ready to prosecute
you, if this happened?

Again, please research the problems with the anonymous FTP protocol.

I am glad to see that some people were willing to recognize that the files
they downloaded were commercial software and reported it to you. Others may
not have recognized that it was commercial software in the first place. You
cannot prove that all of these people knew the files they downloaded were
in fact commercial.

As a responsible FTP admin, many steps could have been taken to prevent
such an event from ever happening. You may point the finger at someone who
uploaded the file as cturley@wco.com, but remember four other fingers are
pointing back at yourself.

FTP transfers files without charge or fee from the server. The files are
freely accessable to the entire world. If you (Joe) were truely concerned
that commercial software could be uploaded/downloaded to/from the site,
much greater restrictions could be placed on the system. You can add fancy
disclaimers to your ftp site taking no responsibility for what is uploaded.
However, you are just leaving the opportunity wide open for anyone to do
upload anything, whether it is commercial or public domain software.

> I sympathize. Posting the list IS a good idea. Most of the info would 
> probably be true and correct. But as I said, you can't prove it with just 
> the list.

Posting the list to this newsgroup would damage the names of people who may
have downloaded the file(s) unknowingly. What would this prove? Again, more
hate toward unproven pirates. Moreover, you cannot prove intent or that the
email addresses in the log represent the people who downloaded the file(s).
Well, you could if there were total cooperation from both system admins. 

I suggest you all continue to collect more of the facts, before making too
quick of a conclusion. It sounds like you (Joe) and Brutal Deluxe Software
may be doing just that.

I have only two questions though.. How many people had been given this
commercial software (before the files were uploaded to your ftp site)? Can
you truely confirm with a written document that Charles had been given
access to and received the files (previous to this incident)?

(Sorry if you got this twice. The last two questions were somewhat unclear.)

Hope you can straighten this out,
--Mike
#  Michael Bytnar  m-bytnar@uiuc.edu  |  UIUC-Dept of Computer Engineering  #
# http://www.uiuc.edu/ph/www/m-bytnar | Opinions wanted-insert $0.02 above. #