Re: [Full-Disclosure] Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution

From: morning_wood (se_cur_ity_at_hotmail.com)
Date: 02/19/04

  • Next message: Byron Copeland: "RE: [Full-Disclosure] Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution"
    To: <insecure@ameritech.net>, "Tim" <tim-security@sentinelchicken.org>
    Date: Wed, 18 Feb 2004 19:59:04 -0800
    
    

    > Many of these systems come from the vendor with default shares enabled
    > allowing anonymous access, no patches, default passwords, no anti-virus,
    > etc. Many health-care organizations then proceed to plug them into the
    > general network and pretend that nothing's wrong.

    ahem... this is not a "windows" issue.

    Sounds like you need a vendor that does its job,
    not just VAR you to death and leave you to
    your own destruction..

    Donnie Werner
    dwerner@exploitlabs.com
    http://exploitlabs.com
    360-312-8011

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Byron Copeland: "RE: [Full-Disclosure] Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution"

    Relevant Pages

    • CLIENT PERMISSION
      ... We have just acquired an application from a vendor which uses SQL server. ... times change the passwords and other things. ... Is there a way that they cannot manipulate information / passwords. ...
      (microsoft.public.sqlserver.security)
    • Off-the-wall Auditor Requests (was RE: Hardware Alerts)
      ... I would have sent his bleeding body back to the vendor in a ... Asking for passwords is ludicrous and he should have ... You could also have said that RACF doesn't store passwords. ... a key to one-way encrypt the userID, ...
      (bit.listserv.ibm-main)
    • Stupid requests (was:RE: Hardware Alerts)
      ... One of my favorite requests was for a vendor doing a conversion. ... wanted all the passwords for user accounts in RACF. ... For IBM-MAIN subscribe / signoff / archive access instructions, ...
      (bit.listserv.ibm-main)
    • Re: Kaspersky service
      ... > Regarding Kaspersky antivirus: ... Do you realize how many thousands of people contact any anti-virus ... vendor every day? ... Redmond offices. ...
      (alt.computer.security)
    • Re: Best free AV s-ware?
      ... so many buying nags to make you angry, ... class to the paid version, ... If your data is worth nothing, use a free anti-virus. ... vendor are more effective than free versions from the same vendor, ...
      (alt.comp.anti-virus)