Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

Cyber Security Awareness Tip #1: Penetrating the This Does Not Apply To Me Attitude, (Mon, Oct 1st)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 10-01-2007
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 46,133
Steve is a jewel in the roughSteve is a jewel in the roughSteve is a jewel in the rough
Thanks: 7
Thanked 24 Times in 11 Posts
Cyber Security Awareness Tip #1: Penetrating the This Does Not Apply To Me Attitude, (Mon, Oct 1st)
As you are hopefully aware, October is the Cyber Security Awareness month. We will focus on one security awareness subject per day. Marc published the agenda at http://isc.sans.org/diary.html?storyid=3429 so lets start with the first tip.

What are your tips for system administrators and others trying to get the word out to user? How did you get past the This Does Not Apply To Me attitude? Submit your ideas and stories here.

You might have heard this from your managers and CEOs multiple times that they are not the target and that certain vulnerabilities dont apply to them. An example of security not taking personally hit the news couple of days ago when Francis Ford Coppolas laptop got stolen (http://www.nydailynews.com/gossip/20...op_stolen.html). The laptops value in the whole story is negligible the main issue here is that it contained the script for his upcoming movie and that there was no backup (at least it appears like so since Coppola pleaded for the return of the laptop).

Alan M. sent us another real story:

I was called to help remove a phishing site from an ISP's apache server. It was not an easy offsite fix as the hacker was no script-kiddie and very actively fought from many countries' ips to retain his server.

One digi-macho guy let the hacker have a major advantage over me...

I setup a new linux machine offline to replace the bad server then put it online on an unused address of the ISP. I ssh'ed into it. While I was working, I noticed something odd in an lsattr directory listing. I ran who and found another me on the machine as root. Time from my login until hacked 10 minutes. The hacker was playing man in the middle.

I fired up Nesus and ran a scan on the ISP staff machines and found one was infected. I went to that computer and its user and found the ANTIVIRUS program removed from the machine. I asked why? The reply, I don't keep anything important on this machine. It doesn't need to be Fort Knox. I can reformat it if it gets infected.

I had to explain to him that his machine wasn't Fort Knox but the hacker had stolen his machine and used it as a bulldozer to break into the ISP.

Well I didn't know that could happen. I thought the viruses just sent spam.

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cyber Security Awareness Month - Daily Topics, (Fri, Sep 28th) Steve Security News 0 09-28-2007 02:31
Cyber Security Awareness Month - We Need Your Ideas, (Sun, Sep 16th) Steve Security News 0 09-16-2007 21:00
Nonprofit Focuses on Security Awareness Paul Security News 0 08-21-2007 18:11
Security World: Watch the winning videos of college student security awareness conte Steve Security News 0 08-02-2007 01:27
Information security awareness videos, (Mon, May 14th) Steve Security News 0 05-14-2007 14:51


All times are GMT +1. The time now is 05:31.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119