Welcome, Guest. Please Login
 
  HomeHelpSearchLogin FAQ Radified Ghost.Classic Ghost.New Bootable CD Blog  
 
Page Index Toggle Pages: 1
Send Topic Print
Top 20 Internet Security Attack Targets (Read 5304 times)
Pleonasm
Übermensch
*****
Offline



Posts: 1619


Back to top
Top 20 Internet Security Attack Targets
Nov 27th, 2006 at 3:55pm
 
It’s that time of year when lists are in vogue . . . .

See Top 20 Internet Security Attack Targets for a listing of the key vulnerabilities uncovered in 2006.
 

ple • o • nasm n. “The use of more words than are required to express an idea”
 
IP Logged
 

Rad
Radministrator
*****
Offline


Sufferin' succotash

Posts: 4090
Newport Beach, California


Back to top
Re: Top 20 Internet Security Attack Targets
Reply #1 - Nov 27th, 2006 at 4:23pm
 
quotes:

If you are using Internet Explorer on your system, the best way to remain secure is to upgrade to Windows XP Service Pack 2. The improved operating system security and Windows Firewall will help mitigate risk.

For those unable to use Windows XP with Service Pack 2, it is strongly recommended that another browser be used.

It is also recommended to upgrade to version 7 of Internet Explorer, which provides improved security over previous versions. The latest version of Internet Explorer, IE7, is being distributed by Microsoft as a Critical Update (KB926874)

----------------------------------------------

I just upgraded to IE v7 this weekend. I like it. Only one IE crash so far.
 
WWW  
IP Logged
 
MrMagoo
Übermensch
*****
Offline


Resident Linux Guru

Posts: 1026
Phoenix, AZ (USA)


Back to top
Re: Top 20 Internet Security Attack Targets
Reply #2 - Nov 27th, 2006 at 9:15pm
 
Nothing really new there.  The threats are the same as they've been ever since Windows XP was realeased.  Still, it's a good list for people who don't know the basics about computer security.  Good find Pleo.
 
WWW  
IP Logged
 
ben_mott
Nuclear Grade
****
Offline



Posts: 278


Back to top
Re: Top 20 Internet Security Attack Targets
Reply #3 - Nov 29th, 2006 at 3:17pm
 
dreamPack:

This tool give full access to Windows 2000/XP. DreamPackPL do not change/overwrite old passwords, thereforeEFS encrypted files will be still readable.

http://www.911cd.net/forums//index.php?showtopic=6228

the best thing to do is  have your server in a locked room
as with DREAM PACK PL and KNOPPIX it is very easy to read files from Xp or even Server 2003 Quickly and easily.
and  certainly do not carry all data base in EFS files on laptop and take it home on the TUBE (or TAXI) as it was the case with few JAMES BONDS and bankers )  007 008 etc who caused great panic in the local papers
and the official answer was oh that is ok  they are encrypted.

Regards Ben
Smiley
 
 
IP Logged
 
Pleonasm
Übermensch
*****
Offline



Posts: 1619


Back to top
Re: Top 20 Internet Security Attack Targets
Reply #4 - Nov 29th, 2006 at 4:45pm
 
Ben_mott, the description of the tool is rather succinct.  Are you saying that it allows a user to bypass both the Windows XP login password and to bypass EFS (encrypted file system) passwords?  Have you confirmed that the tool actually performs as advertised?

I am incredulous, especially about the EFS claim.
 

ple • o • nasm n. “The use of more words than are required to express an idea”
 
IP Logged
 
ben_mott
Nuclear Grade
****
Offline



Posts: 278


Back to top
Re: Top 20 Internet Security Attack Targets
Reply #5 - Nov 30th, 2006 at 2:27pm
 
http://www.911cd.net/forums//index.php?s=a95c52ee0ee4575fc9ad9d02410f75b7&showto...
http://www.911cd.net/forums//index.php?s=a95c52ee0ee4575fc9ad9d02410f75b7&showto...
the author of the software Damian says :
I have made few tests with EFS files. In winXP EFS files are indeed unreadable, but in win2000 i can read encrypted files.

Current version of DreamPackPL modify only 16-byte (128 bit MD5 or MD4 hash) comparisons that are responsible for local authentication. I have found information that there is another one 24-byte comparison responsible for network authentication. Next version of DreamPackPL will be patch also this comparison.

I have no reason to doubt the author Damian he says it works with 2000
I have not tested it on 2003 server ie with EFS files .
His web site when is connected seem to be all about encryption software , i think he turnes his web server off when he is out or goes to sleep, it seems to be intermitant; one day is on next day is off.
http://www.911cd.net/forums//index.php?showtopic=6228&st=71


regards Ben
Smiley
 
 
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print