RE: [lists] RE: [Full-Disclosure] Awake a modem with AT commands

2005-02-26 Thread Curt Purdy
a response. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White House cybersecurity czar Richard Clarke

RE: [lists] [Full-Disclosure] Novell/Ximian Evolution multiple text attachmentsDoS

2005-02-26 Thread Curt Purdy
time to create this remote DoS than it would cause the victim in lost time. IMHO Outlook Express would be a much less time consuming vector. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than

RE: [lists] [Full-Disclosure] Novell/Ximian Evolution multiple textattachmentsDoS

2005-02-26 Thread Curt Purdy
Roman Drahtmueller wrote: snip Evolution - just as everything else in the Open Source world, is subject to permanent development, improvement and evolution. snip Maybe that's why they call it Evolution ;) Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions

RE: [lists] Re[2]: [Full-Disclosure] GREENAPPLE Release

2005-02-13 Thread Curt Purdy
. Multiply my waisted 10 seconds by 10, and you will see what a service you are doing for the world. Sorry for the rant. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security, you

RE: [lists] [Full-Disclosure] Credit Card data disclosure in CitrusDB

2005-02-13 Thread Curt Purdy
Maximillian Dornseif wrote: A group of students at our lab called RedTeam found an information disclosure vulnerability in CitrusDB which can result in disclosure of credit card information. snip Nice job. Congrats to your students. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information

RE: [lists] Re: [Full-Disclosure] Credit Card data disclosure in CitrusDB

2005-02-13 Thread Curt Purdy
Loptr Chaote wrote: snip Who ever the authors, they should never have been put in front of a developer environment.. snip No, they should have been put in front of a fireing squad... Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions

RE: [lists] Re: [Full-Disclosure] Administrivia: List Compromised due to MailmanVulnerability

2005-02-13 Thread Curt Purdy
. If so, it must then be rejected. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White House cybersecurity

RE: [lists] [Full-Disclosure] Terminal Server vulnerabilities

2005-01-25 Thread Curt Purdy
vulnerablities that can be exploited, but the fact that administrator can be bruteforced (6 attempts followed by reconnect) and that it is screaming its existence on port 3889. If you use it, definitely change the port in the registry. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP

RE: [lists] [Full-Disclosure] Phrack is dead, long live Phrack!

2005-01-24 Thread Curt Purdy
snip Been a long time since I read Mentor's words. Good luck to you starwars, I hope you start something. I'd join the effort, but am currently working on my masters in IS and get little sleep as it is. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions

RE: [in] Re: [Full-Disclosure] previledge password in cisco routers

2004-11-24 Thread Curt Purdy
. The only BS I don't like on this list is when those kiddies are stupid enough to open their mouth instead of lurking and learning like I did on the BBS's and newsgroups of my younger days. Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions

RE: [ok] [Full-Disclosure] Certifications

2004-11-22 Thread Curt Purdy
to keep me busy for months. Well worth the money. My .02 Curt Purdy CISSP, GSEC, CNE, MCSE+I, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former

Re: [Full-Disclosure] controversial shadowcrew site hacked by secret service?

2004-11-17 Thread Curt Purdy
. It's the wild west in 1800 and there is no law. If you want to survive, you better have a hired gun and we go for $300/hour these days. At least those of us who have met the black hat on main street at 50 paces at high noon and walked away to tell about it. Curt Purdy CISSP, GSEC, MCSE+I, CNE

RE: [in] Re: [Full-Disclosure] IE is just as safe as FireFox

2004-11-14 Thread Curt Purdy
re-election). Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White House cybersecurity zar Richard Clarke

Re: [Full-Disclosure] IE is just as safe as FireFox

2004-11-14 Thread Curt Purdy
ANYTHING try's to install, is just one more example of FireFox's focus on security. And as for those sites that use ActiveX, I pass them by since they don't have the good since to stick with web standards. FireFox ROX! Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP

RE: [in] Re: [Full-Disclosure] IE is just as safe as FireFox

2004-11-14 Thread Curt Purdy
the first thing I would do when I got home was scan their network. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former

RE: [in] [Full-Disclosure] Securing My Mobile users

2004-11-14 Thread Curt Purdy
everything from stopping split-tunneling to quarantine users to a VLAN and performs remediation on them until they are policy compliant. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions - If you spend more on coffee than on IT security

RE: [ok] [Full-Disclosure] RE: [Full-Disclosure]MS should re-write code with security in mind

2004-08-18 Thread Curt Purdy
, when I have to run windows (rarely), I start a VMWare session under SuSE, do what I need, and close it out as quickly as possibe, after checking for patches of course ;) Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [ok] [Full-Disclosure] Possible Virus/Trojan

2004-07-25 Thread Curt Purdy
a very lame trick against me. =) I'm guessing the latter.Although story scraping would be possible, intellegent naming of the .exe would not be. Most likely a friend... or enemy. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDAInformation Security EngineerDP Solutions

RE: [ok] Re: [Full-Disclosure] Cry For help

2004-07-25 Thread Curt Purdy
Abilash Praveen wrote: whats this about? - Original Message - From: g0bb13s [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Sunday, July 25, 2004 12:58 PM Subject: [Full-Disclosure] Cry For help Good sirs and madames, It's a 491 scam parody. Curt Purdy CISSP, GSEC, MCSE+I

RE: [ok] [Full-Disclosure] RE: Unchecked buffer in mstask.dll

2004-07-16 Thread Curt Purdy
] (EAX=0). So at first glance this doesn't seem to be trivially exploitable, but I'm not a win32 expert, and intuition suggests that there must be a way. One possible exploit is to simply place the file on your desktop. explorer.exe goes to 100% cpu. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA

Re: [Full-Disclosure] RE: Unchecked buffer in mstask.dll

2004-07-15 Thread Curt Purdy
programmers don't trust user-supplied data?? (H -- does it also fail on W2K3??) No, in W2K3 you get Cannot query the properties for this program. There may not be enough memory available. blah blah as opposed to 100% cpu in 2K. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [Full-Disclosure] How big is the danger of IE?

2004-07-11 Thread Curt Purdy
can click. Also a few of the extensions are real productivity improvers, although FireSomething does steal a few seconds every day ;) Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than

[Full-Disclosure] Dull-Disclosure

2004-06-14 Thread Curt Purdy
to install adware on users' systems, security researchers warn. Other exploits - include computer viruses - based on the same techniques of tricking users into visiting a maliciously constructed website housing malign script could follow. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [Full-Disclosure] no more public exploits

2004-04-27 Thread Curt Purdy
and pocs extremely valuable in my pen-testing/auditing work. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

RE: [Full-Disclosure] Decompression

2004-04-27 Thread Curt Purdy
only cause the network device to fragment the packet which would fail since there would be no bits beyond the true length to fragment. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than

RE: [Full-Disclosure] Super Worm

2004-04-19 Thread Curt Purdy
(notifying me of a virus getting through the gateway filter or being able to access something they know they shouldn't). I have found that my time spent has paid me back in a user base (at least part of it) that has become an asset not a liability, as we often think of them. Curt Purdy CISSP, GSEC, MCSE

RE: [inbox] Re: [Full-Disclosure] Hi! Antiviruses Comparison - A Little Research Results

2004-04-16 Thread Curt Purdy
process can touch it, making it extremely fast and efficient with no noticble impact in performance, even on slow boxes. My $.02 Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than

RE: [inbox] [Full-Disclosure] Hi! Antiviruses Comparison - A Little Research Results

2004-04-16 Thread Curt Purdy
Feher from Hungary. Actually Tamas, that is one of the best short critiques I have seen on the AV market and I agree with almost every point. Factual and without bias. Maybe you should write that book. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] RE: [Full-Disclosure] Cisco LEAP exploit tool...

2004-04-16 Thread Curt Purdy
of the little built-in omnis) you could not get near 7 miles. My estimation is that considering the walls in the building, you would be doing good to pick up anything 100 yards from the building edge, even with a yagi. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP

RE: [inbox] Re: [Full-Disclosure] Cisco LEAP exploit tool...

2004-04-15 Thread Curt Purdy
legal power limits. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity adviser Richard

RE: [inbox] RE: [Full-Disclosure] Cisco LEAP exploit tool...

2004-04-15 Thread Curt Purdy
some1 eles states as it may not be true. I have Don't know where you get off including me in your list, but I have personally setup Cisco units up to 20 miles with parabolics and Adaptive Broadband up to 35 miles. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] Re: [Full-Disclosure] Cisco LEAP exploit tool...

2004-04-14 Thread Curt Purdy
. If the packets/hashes can be accessed it can be compromised. Unbreakable has been touted from the 48-bit Netscape encryption that took USC's distributed network a week to crack, to Oracle 9i that took one day to compromise, I believe. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP

RE: [inbox] [Fwd: Re: [Full-Disclosure] MCSE training question]

2004-04-07 Thread Curt Purdy
are in a different class of certs that apply to technologies, not products, i.e. information security, auditing, and even in the case of CEH (which I would not touch with a 10-foot pole), hacking. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

Re: [Full-Disclosure] Training Certifications

2004-04-07 Thread Curt Purdy
rebuilding the system and not getting paid for it because the client knows the bluescreen was caused by us, is not fun. We have never once had this happen on a *NIX or Netware box. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] [Full-Disclosure] ROSI

2004-04-07 Thread Curt Purdy
n30 wrote: Any good links/pointers to ROSI (Return on security investment)? Here's what I've got: ROSI A classic argument is that there is similarly no clear return on life insurance, but that doesn't stop most of us from buying it; still, attempting to formulate operational-security ROI may

RE: The Return of Carolyn Meinel (was Re: [Full-Disclosure] ron1n phone home...)

2004-04-05 Thread Curt Purdy
of this. Obviously Ms. Meinel has pissed off a few people in the past. Actually I have been around long and have the grey hair to prove it. Just never participated in the chat room underground, too busy learning to build tcp packets from scratch ;) Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA

[Full-Disclosure] MCSE training question

2004-04-05 Thread Curt Purdy
the rec or unrec as the case may be. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity

RE: [Full-Disclosure] A sucker is born every day

2004-04-05 Thread Curt Purdy
Carolyn Meinel wrote: Stories in the New York Times and Vanity Fair quoted the FBI saying Martin was wrong, but what does the FBI know? Jay Dyson tells you to believe, so believe you must, because it is cool. I don't intend to get in the middle of the crossfire here, but I just wanted

RE: [inbox] Re: [Full-Disclosure] Training Certifications

2004-04-04 Thread Curt Purdy
from a security standpoint.) Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity

RE: [inbox] Re: [Full-Disclosure] Training Certifications

2004-04-04 Thread Curt Purdy
the oldest of the security certs and now requiring a bachelors degree as a pre-requisite. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you

RE: [inbox] Re: [Full-Disclosure] Training Certifications

2004-04-03 Thread Curt Purdy
. I have only had one person so far, answer all correctly. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

RE: [inbox] [Full-Disclosure] stenagrophy software recommendations

2004-03-25 Thread Curt Purdy
close links to crypto, they are different. Where crypto hides data behind encryption, stego hides it in plain site. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you

RE: [inbox] [Full-Disclosure] Possible Comprimised IIS 5 on Win2k help

2004-03-24 Thread Curt Purdy
for analyzing non-text files as well as many other tools from SysInternals. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve

RE: [inbox] [Full-Disclosure] What Antivirus Should I Get

2004-03-22 Thread Curt Purdy
of their engines (they have 3) operates at the very lowest level of I/O, immediately scanning a file as it comes off the disk, before it enters memory or interacts with OS. This makes it very fast and very efficient. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] [Full-Disclosure] malware added in transit

2004-03-18 Thread Curt Purdy
them at a huge amount of work, you ARE way off-base. There is no malware I know of that would even know what the packets were, muchless re-assemble them into the original document, insert itself, and pass it on. Maybe by 2104... Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [inbox] [Full-Disclosure] Operating Systems Security, Microsoft Security, baby steps

2004-03-18 Thread Curt Purdy
day. I patch my Netware servers a couple of times a year. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

RE: [inbox] [Full-Disclosure] Is this a paypal scam?

2004-03-18 Thread Curt Purdy
) Don't ever put your cc info into any site you did not directly go to and trust. 3) nslookup 218.62.43.30 - Non-existent domain nslookup paypal.com - 64.4.241.16 Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you

RE: [Full-Disclosure] Re: Microsoft Security, baby steps ?[Scanned] [Scanned] [Scanned]

2004-03-18 Thread Curt Purdy
it on a seperate box if you wanted to. Another sign of the total cluelessness of MS on security. -- Curt Purdy CISSP MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's

Re: [Full-Disclosure] Emailing SSN info

2004-03-18 Thread Curt Purdy
on this course, at least encrypt it with PGP or S/MIME. -- Curt Purdy CISSP MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- Former White House

RE: [inbox] Re: [Full-Disclosure] Re: Microsoft Security, baby steps ?

2004-03-17 Thread Curt Purdy
last MS product. BTW, I love the way SuSe updates online during install, before the first boot off the hard drive. Those guys know security. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-09 Thread Curt Purdy
outbreak. The peaceful sleep alone is proof of it's usefullness. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

RE: [Full-Disclosure] Where to start

2004-03-09 Thread Curt Purdy
of the same protiens your brain is made of, and goog for your heart too. And also the reason human ancestors that were coastal dwellers beat out Neanderthals that were hunters). Sorry for rambling. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-06 Thread Curt Purdy
docco wrote: What Curt Purdy is saying looks to me like a great_pain_in_the_ass_solution. In case the supersecret extension would get leaked or compromised, which I beleive would be absolutely not hard to achieve (by means of social engineering, sniffing or just brute force - combinations

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
renames it. A little trouble yes, but it virtually eliminates email propagated viruses from the corporation. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
without the need for scanning. Quite a simple, yet elegant solution, if I do say so myself. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
, past/present/future without any further interaction by IT dramatically improve the virus/worm situation across the board. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security

RE: [inbox] [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
as easy to tell senders to rename the file as to zip it. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
took a day of school or boot camp. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Curt Purdy
, but highly unlikely as long as everyone who implements this strategy don't use the same extension. If you pick a relatively random sequence, a.k.a as in .dps for my company, you would not be the target of a virus, whose purpose is to infect as many systems as possible. Curt Purdy CISSP, GSEC, MCSE+I, CNE

RE: [inbox] [Full-Disclosure] Knocking Microsoft

2004-02-27 Thread Curt Purdy
on my networks and am slowly replacing as many of my W2K desktops with SuSe Linux as I can. My servers are already majority UNIX and Netware. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee

RE: [inbox] RE: [Full-Disclosure] What's wrong with this picture?

2004-02-26 Thread Curt Purdy
that, but I have always suspected the reason for the close follow-up releasing exploits after patch release is because the value of the 0-day that had been used for whatever purposes the writer wanted was now null. At that point, her pride takes over and she releases her work for the world to see. Curt

RE: [inbox] RE: [Full-Disclosure] CISSP Study material

2004-02-19 Thread Curt Purdy
Mark Fagan wrote: you could always attend the CBK review seminar, I think it cost me the guts of 3K Euro and takes one week, its probably cheaper in the UK. I found the CISSP Study Guide Gold Edition to be all the material I needed and a lot cheaper than 3k. Curt Purdy CISSP, GSEC, MCSE+I

RE: [inbox] [Full-Disclosure] IE crashes

2004-02-13 Thread Curt Purdy
Puneet wrote: snip and after 10 seconds when an applet loaded...first IE hanged and then the system got hanged.What's that which causes the system to halt Try FireFox a.k.a. FireBird at mozilla.org - awesome. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP

RE: [inbox] Re: [Full-Disclosure] IE crashes

2004-02-13 Thread Curt Purdy
Rabourdin Clement wrote: Crashed MozillaFirebird on FreeBSD 4.9 STABLE, too :( The applet is working but Mozilla goes down... But no system crash snip Simply comes up with a couple of pics on Firebird 7.1 and FireFox 8.0 on W2K. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [inbox] RE: [Full-Disclosure] Removing Fired admins

2004-02-13 Thread Curt Purdy
by the moderator. They have a nasty habit of doing that. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked

RE: [inbox] Re: [Full-Disclosure] Re: DoomJuice.A, Mydoom.A source code

2004-02-10 Thread Curt Purdy
drop the source for MyDoom.A on you're box. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House

RE: [inbox] [Full-Disclosure] Unbelievable: I just got sensored

2004-02-06 Thread Curt Purdy
, technically correct input. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity adviser

RE: [inbox] Re: [Full-Disclosure] Anti-MS drivel

2004-01-21 Thread Curt Purdy
contributing to the redmond bottom line of their big buck, cause most those PC's come pre-installed with a M$ OS underneath. The cheapest PC HP/Compaq carries is a box running Linux. Again the market. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] RE: [Full-Disclosure] Anti-MS drivel

2004-01-18 Thread Curt Purdy
. The combination of the most secure OS around with an experienced, quality support staff, fully integrated with Linux is a driving force. Novell has finally got it right and their growing market share in the enterprise will reflect that. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [inbox] Re: [Full-Disclosure] Anti-MS drivel

2004-01-18 Thread Curt Purdy
in multiple domain sites requiring either finding the server with the least corruption and making it authoritative, or restoring from a known good backup. No way to run an enterprise. Again, whenever a problem has shown up in NDS, a simple DSREPAIR has always fixed everything, without fail. Curt

RE: [inbox] Re: [Full-Disclosure] Show me the Virrii!

2004-01-07 Thread Curt Purdy
, the biggest pile of dog doo since 3.1 and telling customers they can't get 2K even if they prefer it. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked

RE: [inbox] [Full-Disclosure] Is bugtraq even worth it anymore?

2003-10-27 Thread Curt Purdy
to several securityfocus lists, but have not submitted for some time as I kept getting returned rejects even though they were on-topic valid points. A real shame but not unusual for big-$ corporate America to get their grubby little fingers on something good and run it into the ground. Curt Purdy

RE: [inbox] Re: [Full-Disclosure] RE: Linux (in)security

2003-10-24 Thread Curt Purdy
just hit a grand slam. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity adviser

RE: [inbox] Re: [Full-Disclosure] RE: Linux (in)security

2003-10-23 Thread Curt Purdy
are more researched and discovered because it so prevalent. Without a total re-architecture and re-write of Windows code, if and when (hopefully) Windows OS's become a minority, they will still be getting the vast majority of discovered and exploited holes. Lay a dollar to a dime on that. Curt Purdy

RE: [inbox] Re: [Full-Disclosure] RE: Linux (in)security

2003-10-22 Thread Curt Purdy
of Linux, it is still referred to as a New Technology Release basically synonymous with beta. There Production release is 4.8 that I have on some of our servers (not running a gui). I have 5.1 as well as Linux on workstations. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP

RE: [inbox] Re: [Full-Disclosure] Windows covert channel

2003-10-20 Thread Curt Purdy
be that he is referring to an exe packer as used to attach a trojan to a legitimate exe aka whackamole. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you

Re: [Full-Disclosure] NASA experience

2003-10-17 Thread Curt Purdy
a comprehenive vullnerability assessment and patching and remediation program that turned the hostile penetration rate from over 20% to less than 1% in a year. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you

RE: [inbox] [Full-Disclosure] Problems with MS03-042 (KB826232) patch?

2003-10-17 Thread Curt Purdy
policies, as described in KB 828026. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- White House cybersecurity

Re: [Full-Disclosure] FW: Last Microsoft Patch

2003-10-16 Thread Curt Purdy
with Swen, I am blushing, but I have also just finished a month-long security audit for a HIPAA client and have not kept up like I should have. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than

Re: [Full-Disclosure] FW: Last Microsoft Patch

2003-10-16 Thread Curt Purdy
Debates over the validity of an infosec-related point are useful and constructive; character assassination and personal attacks are not. Thank you madsaxon. Love the handle. Curt ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-Disclosure] FW: change of address

2003-10-15 Thread Curt Purdy
on www.kievonline.org site? thread and is trolling for addresses. I got it at an address I never use for this or any other list as well this address. Thank God for PopFile! Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you

[Full-Disclosure] FW: Last Microsoft Patch

2003-10-15 Thread Curt Purdy
patch out. Or are they thinking, "Send this out so all the stupid people will click on this before they click on a real trojan? Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions [EMAIL PROTECTED] If you spend more

RE: [Full-Disclosure] SPAM, credit card numbers, what would you do?

2003-10-14 Thread Curt Purdy
to the network. Also in that vein is Adrian Lamo, an underground hero of the highest caliber who has just been arrested for helping many large corporations like GE clean up their act. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

RE: [inbox] Re: [Full-Disclosure] MS RPC remote exploit.

2003-10-09 Thread Curt Purdy
can only imagine how many thousands of bots were deployed before blaster hit, as the kiddies were hitting their keyboards just as fast as their little fingers could type. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

Re: [Full-Disclosure] Spam with PGP

2003-10-08 Thread Curt Purdy
;) Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White House cybersecurity zar Richard Clarke

RE: [inbox] Re: [Full-Disclosure] Spam with PGP

2003-10-08 Thread Curt Purdy
The jumbled letters at the end don't fool PopFile. I think it actually marks those as I haven't had one in months. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Senior Systems Engineer Information Security Engineer DP Solutions [EMAIL PROTECTED] 936.637.7977 ext. 121

RE: [inbox] Re: [Full-Disclosure] CyberInsecurity: The cost of Monopoly

2003-09-30 Thread Curt Purdy
actually less upset at Microsoft's presure (what else would you expect from Uncle Bill) as I am at @Stake selling out. What ever happened to that great crew at L0pht Heavy Industries? Personally, I will never purchase another @Stake product or service again. Curt Purdy CISSP, GSEC, MCSE+I, CNE

RE: [inbox] Re: [Full-Disclosure] CyberInsecurity: The cost of Monopoly

2003-09-30 Thread Curt Purdy
, while I observe Uncle Bill's guinea-pigs. One of the things I love about *NIX is the stability. FreeBSD 5.1 (I run on my desktop) is more stable than any Microsoft .1 product ever hoped to be, but the FreeBSD crew is still classifying 4.8 the production version (I run on my servers). Curt Purdy

Re: [Full-Disclosure] CyberInsecurity: The cost of Monopoly

2003-09-30 Thread Curt Purdy
It's one thing to sell-out for commerce, it's quite another to give up your humanity by selling your soul to the devil, and basically that is what they have done by throwing one of their own to the wolves. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions

[Full-Disclosure] Soft-Chewy insides (was: CyberInsecurity: The cost of Monopoly)

2003-09-28 Thread Curt Purdy
When we get this far off-topic, how about putting up a new subject line with a was: Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you

RE: [inbox] Re: [Full-Disclosure] CyberInsecurity: The cost of Monopoly

2003-09-28 Thread Curt Purdy
and see that Microsoft is the central planner here and Bill Gates is Big Brother. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve

RE: [Full-Disclosure] CyberInsecurity: The cost of Monopoly

2003-09-27 Thread Curt Purdy
Tower of Babel that could all come crashing down at the displacement of a single foundation stone. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked

RE: [Full-Disclosure] Security firm Symantec has rubbed subscribers to the Full-Disclosure mailing list the wrong way

2003-09-16 Thread Curt Purdy
He did not say, though, how legislators would determine the difference between malicious information and that used for legitimate security research, or whether such a law might compromise freedom of speech." Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security En

Re: [Full-Disclosure] EULA

2003-09-09 Thread Curt Purdy
Actually, failure to achieve compliance with HIPAA could find hospital executives and physicians facing fines of up to $25,000. Certain criminal violations could cost individuals and organizations $250,000 and up to 10 years in jail. This is quoted out of more than one reference. Curt Purdy

RE: [inbox] Re: Fwd: Re: [Full-Disclosure] Administrivia: Binary Executables w/o Source

2003-08-19 Thread Curt Purdy
crackers. That's my .02 of bandwidth usage. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White

RE: [inbox] Re: [Full-Disclosure] Reacting to a server compromise

2003-08-08 Thread Curt Purdy
applicable to the optical media we now use, with one person responsible for handling and storage with a reliable witness. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more on coffee than on IT security, you

RE: [inbox] Re: [Full-Disclosure] Reacting to a server compromise

2003-08-04 Thread Curt Purdy
Actually the traditionally accepted court evidence is real-time printouts of data received by the syslog server. We ran out of room to store the paper and went to write-once cd's. We are looking at going to DVD to cut down on disk changes. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information

RE: [inbox] Re: [Full-Disclosure] Reacting to a server compromise

2003-08-04 Thread Curt Purdy
and are finding attacks that they would not have even guessed at a year ago. By law they must keep their logs three years, plenty of time for even scumbag lawyers to find it. If you have done due diligence, you will be a sitting duck. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security

RE: [inbox] [Full-Disclosure] Re: Reacting to a server compromise

2003-08-04 Thread Curt Purdy
the same restriction. Although I am not familiar with this hardware, most law inforcement I know use Encase, a $30K dd with a few analysis tools thrown in. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions If you spend more

RE: [inbox] Re: [Full-Disclosure] Reacting to a server compromise

2003-08-03 Thread Curt Purdy
field) dictates you make an immediate initial dd copy for the court. Then make as many working dd's as neccessary for forensics. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Senior Systems Engineer Information Security Engineer DP Solutions [EMAIL PROTECTED] 936.637.7977 ext. 121

  1   2   >