be careful with anything that "attacks back", the legality of that is still being phrased.
yes, i know that it doesn't "really" "attack back" but when you phrase it that way you're going to raise some hackles.
yes, i know that it doesn't "really" "attack back" but when you phrase it that way you're going to raise some hackles.
I think this project, much like all "offensive security" projects, is fundamentally misguided. At best, this project loudly alerts the hacker every time an attack is detected, providing an easy way to black-box test the service's attack detection criteria. At worst, it provides an easy way for jerks to goatse, Last Measure, etc. third parties using the webmaster's site. While I understand the kind of spiteful thrill that would come from redirecting a (maybe not) attacker to a shocking image, quietly stopping and logging the attack is always the best option.