Posting sensitive info, was => Re: Taking control of ones machine

From: H C (keydet89@yahoo.com)
Date: 12/21/01


Date: Fri, 21 Dec 2001 06:09:24 -0800 (PST)
From: H C <keydet89@yahoo.com>
To: focus-ms@securityfocus.com

As we reach the end of 2001, I find it hard to believe
that posts like this are still making their way to
public forums. For all of the strides we think we've
made with regards to security, there still seems to be
an effort to undermine that effort.

What we see with this post is an admin (quick check to
NSI's whois lookup confirms this) who is publicly
stating that at least one of his servers has a
web-based remote admin utility installed.

Quick checks of other public forums via a search
engine reveal quite a bit more information about the
infrastructure, applications used, and the apparent
knowledge level of the admins.

Now, don't misunderstand me...I'm all for the sharing
of information, and getting assistance from
knowledgeable sources. However, what I do find to be
extremely concerning is the apparent need for some
administrators to post sensitive information about
their infrastructure. Why not create a Yahoo account
specifically for such posts?

--- Steven Bonici <sbonici@groupea.com> wrote:
>
>
> You have to forgive me with the following questions,
> as I am not sure if
> this is the right group.
>
> We have been asked by one of our software vendors to
> allow them to use WebEx
> to take control of one of our servers. They
> explained to me that all I need
> to do is to install a "plug-in" and they can take
> control of the server
> through a web browser. We staged a test with a test
> server, and they came
> right in and took control. Isn't way too easy?
>
> I haven't contacted them yet, I thought I would ask
> here first. Is there
> any documentation or white papers into how this
> actually works and what can
> be done to protect the machine? Does anyone have
> any insight into WebEx? I
> am really curious as to how easy this is. I know
> once you go to the WebEx
> web site you need to agree and "allow" someone to
> actually connect, but it
> just seems way too easy.
>
> I know that websites can grab information from your
> browser, but again I
> would love to know "how" and all this seems to be
> connected in some way. I
> downloaded a copy of "pcaudit.exe" (by Internet
> Security Alliance), and that
> just goes to prove how vulnerable one is.
>
> Any information would be greatly appreciated.
> Thanks - Steven

__________________________________________________
Do You Yahoo!?
Check out Yahoo! Shopping and Yahoo! Auctions for all of
your unique holiday gifts! Buy at http://shopping.yahoo.com
or bid at http://auctions.yahoo.com



Relevant Pages

  • Re: Anyone use Newsguy?
    ... >>>Well Newsguy doesn't seem to be so great as far as propegating. ... >> servers in a timely manner. ... >to hit Supernews, Giganews, etc. ... >> and receive those incoming posts, no more than they can control ...
    (alt.2600)
  • Re: IDS vs Application Proxy Firewal & OT list bouncing
    ... On Mon, Oct 27, 2008 at 2:29 PM, Arian J. Evans ... I would understand if moderation were the problem. ... Having been on the ugly end of public posts like that as ... nastiness in public forums. ...
    (Focus-IDS)
  • Re: Error - Windows Cannot Connect
    ... Microsoft Online Partner Support ... When responding to posts, please "Reply to Group" via your newsreader so ... | resolution for this I rebooted 2 of the effected servers last night. ... |> after you stop the BackupExec service. ...
    (microsoft.public.win2000.general)
  • Re: Town Shaken after U S Attorneys Arrest in Child-Sex Sting
    ... First let me say - yes I see your posts. ... While i think you make a good point, that perhaps there are pedophiles ... of these chatrooms/ groups might be the sort needy for attention - any ... AB Yahoo group was removed is that they don't want to publicize the ...
    (alt.true-crime)
  • Re: Censorship in the net group OT?)
    ... Acouple of posts including mine were removed ... your posts before they're propogated out to the rest of the Usenet ... as long as they don't disrupt or damage other servers in the network. ... cancel by removing the original post. ...
    (rec.arts.anime.misc)