Re: Cryptography and Site Security: Please critique my security idea

From: Robert Paris (rpjava@hotmail.com)
Date: 03/26/03


From: rpjava@hotmail.com (Robert Paris)
Date: 26 Mar 2003 10:18:01 -0800


> Hmm. An interesting idea. However, if the server is compromised and
> the user gains administrative access they should be able to gain access
> to almost any area of the memory - rip out your keys and ftp them
> somewhere.

Is this true? Is there a way around this? Or a way to guard against
this? Would this be the case that they could gain access to any part
of memory without any need of restarting anything? On Linux? On
Windows? (Not sure yet which it will be hosted on)

> Check how strong your passwords
> are regularly.

What might this entail? I'm not sure I fully follow.



Relevant Pages

  • Accessing BIOS memory range
    ... Gaining access to the I/O ports isn't a big problem, ... know how to gain access to memory that isn't part of my user address space. ... Is it even possible to gain access to that memory area. ...
    (freebsd-hackers)
  • Virtual addresses, router techniques
    ... If you run an exploit against a virtual machine are the memory addresses, which are typically hardcoded in the exploit, the same or is there some difference? ... Also, aside from playing with the dhcp and routing specific ports/protocls, what other techniques can be used to gain access to the internal network/machines when you have access to the router? ...
    (Pen-Test)
  • Re: Global Catalog
    ... Remember you need a DC available to be provided a Kerberos ticket to gain access to remote services, so although a user will be able to logon locally but w/o a dc cached credentials will provide no relief to gain access to files/objects/services. ... As I know there is Global Catalog - less logon process. ... I'd urge you to look for Server 2003. ...
    (microsoft.public.win2000.active_directory)
  • Re: Can not get into server 2003
    ... Seems to be on all accounts, have now just locked the account instead of ... or member or workgroup server? ... Normally i can gain access daily, then about once a week all access ... Reboot and it all returns! ...
    (microsoft.public.windows.server.general)
  • Re: Security updates - 04/13/2004
    ... There is a supported hotfix available as described in the KB article you ... > Shortly afterwards I was unable to access the server via pcAnywhere ... Over the next two weeks I could not gain access to ... > Setup has determined that Drive C: is corrupted and cannot be repaired. ...
    (microsoft.public.win2000.security)