Re: [Full-disclosure] Working exploit for Debian generated SSH Keys

2008-05-23 Thread Tonnerre Lombard
Salut, Michael, On Tue, 20 May 2008 13:41:41 -0400, Michael Holstein wrote: > Smoke Detector + Webcam = cheapo RNG We were talking about PRNGs here, which are highly complex mathematical constructs, not hardware RNGs, which are also slightly hairy though. There are a couple of books on PRNG desig

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Jesse Bacon
Why don't you sell them on a RedHat based SMB filesharing solution and install a copy of Security Blanket. (http://www.trustedcs.com) RedHat provides regular updates that keep it pretty secure and with Security Blanket on there it will stay secure. Additionally the presence of a non windows file

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Izaac
On Thu, May 22, 2008 at 09:51:01AM -0700, Daniel Sichel wrote: > it's not documented anywhere. So, please help me explain why netbios and > file shares on machines not within your network are bad ideas. This situation is ultimately and entirely your fault. You, i.e. your IT department, has failed

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Castigliola, Angelo
Daniel, I think you will find that this is a common problem in the industry. There are going to be times where non-company owned assets are going to need to plug into your network with business justifications such as a vendor visiting onsite or in your case where the vendor agrees to manage the

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Marcus Graf
Hi Izaac, >> it's not documented anywhere. So, please help me explain why >> netbios and file shares on machines not within your network are bad >> ideas. > > This situation is ultimately and entirely your fault. > > You, i.e. your IT department, has failed to provide the services and > resourc

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Paul Schmehl
--On Thursday, May 22, 2008 20:45:06 -0700 coderman <[EMAIL PROTECTED]> wrote: > On Thu, May 22, 2008 at 9:51 AM, Daniel Sichel <[EMAIL PROTECTED]> > wrote: >> My management here wants to put a server on our LAN, not administered by us >> ... > > all of the responses to this are retarded. > > tell

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Elazar Broad
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Its not even funny how often this happens. I have a friend who does some consulting work for small businesses, and the amount of times that he has come across medical practices that run their billing and record keeping software on the same "fully-loade

Re: [Full-disclosure] Need some help with management

2008-05-23 Thread Paul Schmehl
--On Friday, May 23, 2008 11:56:15 -0400 Elazar Broad <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Its not even funny how often this happens. I have a friend who does > some consulting work for small businesses, and the amount of times > that he has come across

[Full-disclosure] Thank you for help with management.

2008-05-23 Thread Daniel Sichel
Thank you to all who responded to my request for how to deal with a non secure server. Responses ranged from lol witty to incisive. I will definitely be asking the general manager for a key to his house and I will be requiring a release from liability in writing. It was very helpful, thank you a

Re: [Full-disclosure] Thank you for help with management.

2008-05-23 Thread Valdis . Kletnieks
On Fri, 23 May 2008 14:26:07 PDT, Daniel Sichel said: > Thank you to all who responded to my request for how to deal with a non > secure server. Responses ranged from lol witty to incisive. I will > definitely be asking the general manager for a key to his house and I > will be requiring a relea

Re: [Full-disclosure] Thank you for help with management.

2008-05-23 Thread Michael Krymson
I wonder if anyone else on this forum supports Cisco VOIP servers? Do you think you manage those? :) What about edge routers managed by your network service provider? This is not as outlandish a request as it sound like and my point with that is to illustrate that this does happen. Before you poss

[Full-disclosure] A cyber human shield?

2008-05-23 Thread n3td3v
A cyber human shield? A rogue government could take traditional military tactics [1] and put them into the cyberspace warfare arena. This evidently [2] hasn't been thought about after I read the military article cited by S/U/N <[EMAIL PROTECTED]>. [1] http://en.wikipedia.org/wiki/Human_shield [2

Re: [Full-disclosure] A cyber human shield?

2008-05-23 Thread n3td3v
"COL. CHARLES W. (CHARLIE) WILLIAMSON III is the staff judge advocate, Air Force Intelligence, Surveillance and Reconnaissance Agency, at Lackland Air Force Base, Texas. He has served as a flight test manager for small, air-breathing missiles; as a judge advocate at two base-level legal offices; as

Re: [Full-disclosure] Thank you for help with management.

2008-05-23 Thread Micheal Cottingham
I think the issue of why management doesn't want IT to have access/manage to the server needs to be answered. If it were me, I'd ask them point-blank if they trust me, and if they don't, why am I their network admin/security guy/whatever the case may be. But that's me. ;) On Fri, May 23, 2008 at 6

[Full-disclosure] [ MDVSA-2008:106 ] - Updated gnutls packages fix denial of service vulnerabilities

2008-05-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:106 http://www.mandriva.com/security/ ___