Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 12 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
November 22, 2008, 02:56:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 5 6 [7] 8 9 ... 31
91  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: AkamaiGhost - Akamai Global Host - Geographically co-located Caching Server on: August 18, 2008, 03:23:27 AM
Manu,

not sure about AkamaiGhost, I know Akamai are a web-host cluster for major sites in the UK (possibly international, I don't know). http://www.akamai.com/

From my limited encounters with Akamai I believe that AkamaiGhost is a proprietory HTTP(S) server, so getting access to the application may be difficult.
92  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: help me to protect my WEBSITE ? on: August 17, 2008, 03:53:52 PM
isosoft,

that is one seriously open-ended question.

Standard advice of google applies (It always does....)

OnLAMP is a good resource, of specific interest will be articles in the security section.

As for a checklist, there is only one universal rule:
Quote
Patch your vulns before the other guy exploits them....

Wink Good luck out there.
93  Ethical Hacking Discussions and Related Certifications / Other / Re: Networking question on: August 16, 2008, 06:14:55 AM
what are they gonna give us next as the 'NEW SUPER TECHNOLOGY' that doesnt work Smiley

I think it's called Vista...
* RoleReversal runs and hides.....Wink
94  Columns / Editor-In-Chief / Re: Man Looks Into the Abyss... on: August 15, 2008, 08:43:01 AM
Don,

good luck, plenty of people behind you. Just remember to enjoy it Wink
95  EH-Net / News Items and General Discussion About EH-Net / Re: Registration Experience, and Security on: August 15, 2008, 06:39:33 AM
...I am on my last day at my regular job...

Nervous?
96  Ethical Hacking Discussions and Related Certifications / Forensics / Re: HELIX on USB?? on: August 14, 2008, 04:43:02 AM
Glad to hear you got BT3 working nicely, puts the Aspire One back on my possibles lists (of course need to find the finance first....)

Let me know how you get on with USB-ising Helix, I've used to CD several times so a USB version could come in handy.

(And I'll get IM installed soon promise....One hell of week....)
97  Ethical Hacking Discussions and Related Certifications / Forensics / Re: HELIX on USB?? on: August 14, 2008, 03:57:35 AM
Dale,

I've not tried specifically with the Helix distro, but all USB setups I've played with I've found PenDriveLinux to have some good guides and advice.

With similar distros I've created a bootstrapped USB drive and copied the directories over from the Live install. Hasn't failed me so far.

btw, how you finding the Aspire One now? (Laptop died horribly and haven't gotten MSN reinstalled yet....)

RR
98  Resources / News from the Outside World / Re: Looks like people are starting to take notice... on: August 14, 2008, 03:52:59 AM
I saw a scary stat one time. the number one unclaimed item from an airport's lost and found is a laptop. What are people thinking these days?

I'm thinking some people have too much money. I struggle to afford my kit in the first place, nevermind replace kit I forget to pick up when my brain stops working
99  Resources / Mass Media / Re: HACKERS ARE PEOPLE TOO on: August 14, 2008, 03:50:41 AM
For any other UK guys and gals thinking of getting it, its £9.35 GBP including shipping so hardly breaking the bank.

Cheers Dale, had just loaded the site in a new tab to see what postage would set me back. Guess you just saved me a few clicks for RSI Wink

Roll on pay-day....
100  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web Application Vulnerability Scanner on: August 13, 2008, 06:22:47 AM
I've used Nikto in the past with varying levels of success. However I haven't done much in this field so don't have much to compare it to.

As mentioned in sectools list referenced by KrisTeason it is often behind the curve when it comes to bleedingedge threats, but the chances are if your developers have left old, well known vulnerabilities about the place it could be a safe bet that your vulnerable to the newer stuff regardless of what your audit tool tells you.
101  Resources / News from the Outside World / Re: Looks like people are starting to take notice... on: August 13, 2008, 06:15:01 AM
I also have never had a laptop stolen, personal or business.
However I put this down to working in IT, working in Security, and not being a total numpty Cheesy

Well, I was about to reply to Don's question saying something similar but I don't think I can put it better than that Cheesy

As many have said, the dismissal may have issues depending on the actual policy in place. But I know most places I've worked have had a general policy that states (paraphasing):
Quote
Don't be a muppet with our stuff or we wont be happy
So they may have him on a broad do stupid things, get sacked basis.
102  Ethical Hacking Discussions and Related Certifications / Other / Re: Blackhat 2008 on: August 13, 2008, 06:09:10 AM
OleDB,

thanks for the write-up. Wish I could have been then, I'll need to try harder for next year.

Sounds like you had a blast.
103  Ethical Hacking Discussions and Related Certifications / Other / Re: Networking question on: August 12, 2008, 12:09:45 PM
Yeah, but these auto sensing ports *cannot* work with crossover cables.

iSmith, what make/model are these NICs?

(want to make sure I avoid them...)

Then what the hell are the "auto-sensing?"
Not the same thing I'd expect from an 'auto-sensing' port from they looks of it Wink
104  Resources / News from the Outside World / Re: Looks like people are starting to take notice... on: August 12, 2008, 12:07:18 PM
About bloody time. What the hell was a manager doing with patient data? He no doubt broke the rules if not the law in storing it on a laptop in the first place.

I'm a fan of mobile computing like most people here, but why does everybody seem to need a laptop? What justifies this manager having a laptop for the day to day work? Perhaps there was a good reason but it's just as likely the they simply wanted one.

Confidential data + mobile device = FAIL

Jimbob

I think the first problem is why he was able to have so much data transfered to his machine? Surely there have been enough high-profile precedents (especially in the UK) that should have made people at least think twice about leakage vector.

Quote
The PC ... contained copies of the personal details and treatment plans of several thousand patients.

Even if the manager in question had a legitmate reason for requiring the data (possible), and on a mobile device (less likely but still possible). What reason did he have for taking the data to a different country, over 400 miles away whilst on holiday?

It is ashame that this guy is going to take the fall for what is commonly a non-issue, just using the UK as an example several high-ranking government and security services personnel have been in similar situations with nothing other a slapped wrist.

Regardless, it is nice to see an organisation taking tough action to lacking security controls, whether or not the hospital had sufficient procedures/policies in place to make the dismal fair is another matter.

Either way it will hopefully increase general awareness of the problem which can only be a good thing of those of us having to protect against and clean up after end-users get their hands on shiny toys.

Think Jimbob put it best
About bloody time.

RR
105  Resources / News from the Outside World / Looks like people are starting to take notice... on: August 12, 2008, 10:37:26 AM
Just read this on El Reg that I thought I'd share.

Quote
Colchester University Hospital has sacked one of its managers over the theft of his work laptop, which contained unencrypted patient records.

The PC - which was stolen from the unnamed manager's car in June - contained copies of the personal details and treatment plans of several thousand patients. Thieves took the machine after breaking into the car, which was parked in Edinburgh at the time, where the unnamed manager was holidaying.

The computer was password-protected but the data was not encrypted.

Colchester Hospital University NHS Foundation Trust said that the manager involved was dismissed following a disciplinary panel last Friday. "The unanimous decision of the disciplinary panel sends out a clear statement about how seriously the Trust takes security and patient confidentiality. I again apologise for the distress the theft of this laptop may have caused," said Peter Murphy, chief executive of Colchester Hospital University NHS Foundation Trust.

Perhaps threat of unemployment might make employees take more care with client data. Don't fancy filling in his next job application form: Reason for leaving previuos position?....
Pages: 1 ... 5 6 [7] 8 9 ... 31
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.