Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Asking To Get Owned?
EH-Net
May 24, 2013, 06:35:09 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Asking To Get Owned?  (Read 5080 times)
0 Members and 1 Guest are viewing this topic.
xXxKrisxXx
Hero Member
*****
Online Online

Posts: 512



View Profile
« on: August 21, 2009, 11:38:06 PM »

Alright, I have a friend who works at Best Buy. He works in the computer section and over there they've partnered with a couple ISP's to help get customers set up with internet at their homes. I was making the ISP switch just last week when I noticed that the computer they were using to sign customers up for internet service had no Anti-Virus / Firewall. It honestly just looked like a default out of box installation of Vista.

Once I noticed this I instantly went, "wow", and mentioned it to my buddy (the guy who works there). He goes, "Yeah, I Know Bro, Can You Believe They Use WEP For Our Routers Encryption Too?". Was in a sort of 'wow' moment there for a second and I thought, "This is the home of the Geek Squad", you'd certainly think they have a networking guy on board somewhere that's concerned with this?

Maybe I'm just rambling on about nothing here, but I definitely see how attackers pull off these mass credit card stings from examples like how TJ Max got hacked awhile back :
http://news.cnet.com/T.J.-Maxx-hack-exposes-consumer-data/2100-1029_3-6151017.html and even more recent ones. I instantly thought to myself, that there could be a guy in a van in the parking lot right now with an ALFA card sniffing traffic and they wouldn't know. I guess I was just surprised to see companies relying on WEP as a security scheme when it can be broke in a matter of minutes. I wouldn't be surprised to hear about this Best Buy getting owned within a few months if they keep this up. It's unpredictable to really say how long they've been using WEP for their encryption and what other computers don't have proper protection.

Just my rant though, any thoughts on the subject?
Logged

eCPPT, GCIH, OSCP, OSWP
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: August 22, 2009, 12:39:15 AM »

It's a shame, but people never seem to surprise me when it comes to security.   I have too seen tons of WEP implementations, even in government.   Although, I find that physical security is almost always a lacking.   That brand new shiny firewall isn't going to save you if someone walks out with your server.
Logged

~~~~~~~~~~~~~~
Ketchup
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #2 on: August 22, 2009, 01:15:02 AM »

There was recently a similar thread at EH-Net, were a weak security was found on some shop iirc. It's no rarity that also companies and other institutions have no proper setup of their security and therefore are vuln. although they should know better.
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #3 on: August 22, 2009, 02:14:13 AM »

Like Ketchup, it takes alot to surprise me when it comes to InfoSec.
Even the most basic practices are overlooked. We have to remember though that not every one or organisation shares the passion.
Logged

Laz3r
Guest
« Reply #4 on: August 22, 2009, 02:36:42 AM »

"This is the home of the Geek Squad"
Which is exactly why you shouldn't be surprised.  =P
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #5 on: August 22, 2009, 11:46:55 AM »

"This is the home of the Geek Squad"
Which is exactly why you shouldn't be surprised.  =P

I was thinking the same thing. I mean, how often do we hear that Geek Squad is stealing data off machines brought in for repair.
Logged

OSWP, Sec+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.