RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scan ners

From: Ng, Kenneth (US) (kenng_at_kpmg.com)
Date: 04/28/04

  • Next message: Codex: "Re: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scanners"
    To: "'Starford, Christopher D.'" <CHRISTOPHER.D.STARFORD@saic.com>, "'Harlan Carvey'" <keydet89@yahoo.com>
    Date: Wed, 28 Apr 2004 16:18:17 -0500
    
    

    It depends on who you get. At a previous job I was once asked to provide a
    printout of the file permissions of every file on every system. After
    delivering I think it was four cartons of paper for one system, I think he
    changed his mind because he didn't ask for the other systems.

    But the best ever was from a goverment auditor doing a securities
    investigation. Said auditor wanted all transactions between us and XXX
    between such and such dates. Ok, we said, what format tape do you want it
    on? They insisted on a printout. So, I think it was 14 cartons of 8.5x11
    paper. A few months later we asked them how they were doing. They said
    that they were having difficulty (AND I KID YOU NOT) OCR'ING IT BACK INTO
    ELECTRONIC FORMAT. Now think about this. Every transaction is a series of
    about 80-120 numbers of accounts, stocks, amounts, etc. Given an OCR
    accuracy of 90% (this was the early 90's), every line that they OCR'ed in
    had an error on it. Not very useful for searching for illegal trading.

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com]On Behalf Of Starford,
    Christopher D.
    Sent: Wednesday, April 28, 2004 3:55 PM
    To: 'Harlan Carvey'
    Cc: 'full-disclosure@netsys.com'
    Subject: RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security
    Scan ners

    Harlan,
     
    I believe many true IT Security Auditors out there would agree that your
    wrong on this one.

    > -How will I ever pass my IT Security Audits?
    >
    > Don't worry about it...most audits don't seem to have
    > an IT background, and even when they do, they don't
    > take the time to understand your business processes or
    > your network infrastructure.

    __________________________________________________
    Christopher D. Starford
    SAIC Enterprise Security Sulutions

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    *****************************************************************************
    The information in this email is confidential and may be legally privileged.
    It is intended solely for the addressee. Access to this email by anyone else
    is unauthorized.

    If you are not the intended recipient, any disclosure, copying, distribution
    or any action taken or omitted to be taken in reliance on it, is prohibited
    and may be unlawful. When addressed to our clients any opinions or advice
    contained in this email are subject to the terms and conditions expressed in
    the governing KPMG client engagement letter.
    *****************************************************************************

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Codex: "Re: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scanners"

    Relevant Pages

    • Re: [Full-disclosure] Ganging up on n3td3v
      ... doesnt stand for Fat Douches it stands for Full Disclosure. ... I see that you are an A-list blogger for the web2.o security industry ... > Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • RE: [Full-disclosure] infosecbofh
      ... There is no reason to flame N3td3v for his work. ... Greyhats Security ... >> Charter: ... No virus found in this incoming message. ...
      (Full-Disclosure)
    • Re: [Full-disclosure] [Dailydave] Hacking software is lame -- try medical research...
      ... What did I do I just said I was gonna eat CORNdogs. ... >> What have you done for the security community ... > Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • RE: [inbox] RE: [Full-Disclosure] MS03-039 has been released - critical
      ... posted and he's going to write his IDS rules by them. ... http://eEye.com/Retina - Network Security Scanner ... http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] Antigen Path Disclosure
      ... security, you're all just playing with "the morning wood" (err.. ... the pool, I don’t care if he went off a bridge, I DON'T FUCKING CARE, ... something i never actually bothered poking at them or something i never ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)