Like all tools, it's the usage and motivation of the user that defines it. I can use a hammer to build a house or to crack open someone's skull. Knoppix-STD is no different. Almost all of the tools could be used maliciously or with good intent. Even your standard web-browser can be a malicious tool in the wrong hands (think Unicode traversal attacks).

What are people using STD for? I'm seeing far more "legitimate" uses than malicious. Government agencies are using it. I have word that several branches of the US military are using it. Private businesses are using it.

And more than using it they're LEARNING from it. Overly taxed security admins finally have an preconfigured environment to play with tools that they may have never touched before. I got an e-mail from one admin that is finally using Intrusion Detection on his network after learning how through STD. Home users are learning how firewalls work. One admin was able to completely restore a dead Windows NT PDC with STD before any of his users showed up for work. STD may have saved that admins job.

Do I get feedback from the script kidz? Sure. Most are double clicking on the Knoppix directory in Windows and are angry that "the stuffs broke".

STD is just a tool, but I get the distinct feeling that it is securing much more data than it is breaching.

[email protected]
http://www.knoppix-std.org