Software vendor clueless

From: Jeff Peterson (jpeterson_at_btiis.net)
Date: 08/16/03

  • Next message: Juri Haberland: "Re: possible 0-day exploit for latest Real-/Helixserver 9.0.2.794"
    Date: 16 Aug 2003 19:31:35 -0000
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    All,

    I have a customer whose company does legal work for lots of businesses.
    The data housed on their network is what I would call 'financially
    sensitive'. Recently, I found their Exchange server had been turned into
    an open relay. It was not that way a month ago.Once I stopped the
    bleeding, I told them I wanted to change the Administrator password,
    (NT4.0, Exch5.5. I know, I know). They told me they were not allowed to
    change the password. "Sez WHO", I asked. "Our software vendor", they
    replied. Turns out the vendor in question has a niche market in this
    kind of legal field. Also turns out they use the same 4-letter, (no
    caps, no special chars), administrator password on ALL their customers
    networks. To make matters worse, they have PCAnyWhere ports open on all
    these networks, because their software is so buggy, the developers need
    to remote in and fix things all the time. The spokesman for the group
    claims that the AT&T managed firewall prevents anyone else from using the
    PCNoWhere ports by IP address.

    I'm not a great negotiator, and I'm going to face the SW spokesman next
    week. He is a good spin doctor. I'm looking for help in making him
    secure his stuff. All help is appreciated.

    Jeff Peterson
    BTIIS

    ---------------------------------------------------------------------------
    Captus Networks - Integrated Intrusion Prevention and Traffic Shaping
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Ensure Reliable Performance of Mission Critical Applications
     - Precisely Define and Implement Network Security and Performance Policies
    **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    Visit us at:
    http://www.securityfocus.com/sponsor/CaptusNetworks_incidents_030814
    ----------------------------------------------------------------------------


  • Next message: Juri Haberland: "Re: possible 0-day exploit for latest Real-/Helixserver 9.0.2.794"

    Relevant Pages

    • Re: [Newbie] Info about ISP Gateways
      ... Regarding the private networks, this is just means that they are just a ... The ISP gateway (not on the customer ... should be unaffected by how the ISP has chosen to structure the network. ...
      (Pen-Test)
    • Re: [opensuse] Moving to IPv6
      ... NAT on my local networks. ... You have a new customer, who finds they can only get a NAT address ... They also want VPN access to their network. ...
      (SuSE)
    • Re: spamassassin doesnt seem to be using bayes
      ... He is using procmail, ... (When my customer sends me mail I have procmail play a notification ... The trusted networks setup is critical. ... are NOT networks you trust not to forward spam. ...
      (Fedora)
    • Re: Orange or Three?
      ... as well as other ancillaries such as good customer ... service, coverage, etc. ... Bear in mind that very soon the Orange and T-Mobile networks are going ... Which will mean two customer bases using one network ...
      (uk.telecom.mobile)
    • Re: This seems like a good buy on a network switch
      ... grew to the point of needing more ports. ... It claims to be a business-class switch yet I don't see any ... really seem to provide isolation of ports into different segments. ... networks or extending your managed networks." ...
      (alt.comp.hardware.pc-homebuilt)