|
EH-Net
|
|
May 21, 2013, 06:04:12 AM
|
Show Posts
|
|
Pages: 1 2 3 [4] 5 6
|
|
46
|
Ethical Hacking Discussions and Related Certifications / OS / Re: Remote Code Execution
|
on: August 31, 2012, 08:52:00 AM
|
|
From what I've been reading, many exploits are the result of getting the user to click your infected site and take advantage of a browser flaw, Java exploit, Flash Player, PDF reader....as shadowzero said, no run runs vanilla Windows with no third party apps installed. Just might take some Social Engineering.
|
|
|
|
|
54
|
Ethical Hacking Discussions and Related Certifications / Other / Re: Company Wide InfoSec....
|
on: August 22, 2012, 09:03:20 PM
|
|
I too deal primarily with SMB's, well mostly SB. The major issue I've seen recently is how poorly they deal with employee termination. I got a call from one THREE WEEKS after they let someone go for check stealing. She still had remote access and a working company email. I found out during a routine checkup. They said "Oh, don't bother with her computer, she doesn't work here anymore..."
She had been given significant access to many areas. My head spins at the harm that could have been wrought. I had a chat with the boss and hopefully enlightened him. At the very, very least, call me first before firing anyone so I can cut access and lock their account.
I know many larger companies with real HR departments handle this more professionally. Have any of you needed to step in and fix employee termination processes as part of an evaluation?
|
|
|
|
|
58
|
Ethical Hacking Discussions and Related Certifications / Malware / Re: msfpayload
|
on: August 15, 2012, 05:37:24 PM
|
|
So long as your router on the BT5 end is set to port forward whatever port you had your exploit use and BT5 is listening on, should be OK. Haven't tested that myself yet, just been doing stuff on my local LAN. Let us know if your AV picks anything up when you open your mail on the remote test boxes.
|
|
|
|
|
59
|
Resources / Career Central / Re: Questions From a Retiree
|
on: August 15, 2012, 04:56:54 PM
|
|
If you can pull off a certain amount of gravitas, your age could be a bonus. I would think that most potential clients would really just care that you seem to know what you are doing, and you present yourself well. And that you can document your findings in a way that management can grasp, and enough technical knowledge to demonstrate expertise to their internal IT staff.
|
|
|
|
|
Loading...
|