Re: [Full-disclosure] Congratulations Andrew

2010-06-16 Thread wilder_jeff Wilder
By that same standard.. if you leave your house unlocked does that give someone the right to enter it? just my thoughts Date: Wed, 16 Jun 2010 19:58:27 +0200 From: uuf6...@gmail.com To: tbi...@gmail.com CC: full-disclosure@lists.grok.org.uk; valdis.kletni...@vt.edu Subject: Re: [Full-discl

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread wilder_jeff Wilder
There is a big difference between being secure and being compliant.If its a company's desire to be compliant, they may never be secure. However, if they strive to be secure, they will always be compliant no mater what framework they are chasing. I agree... money spent on compliance is us

[Full-disclosure] When will they ever get it !?!?!?!

2008-08-07 Thread wilder_jeff Wilder
As you will all know I am one never to post, but I had to bring this to a discussion point. I received an e-mail today from the Gallup Journal inviting me to join their LEET management spam list. Within this inventation, they had provided me with my username (Ahhh how nice) and my password (

Re: [Full-disclosure] Geeks

2008-05-19 Thread wilder_jeff Wilder
The CISSP is a management certification... not a techie cert... I dont need to hack to keep one out.. -Jeff-BEGIN GEEK CODE BLOCK-Version: 3.1GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M--V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++G e* h--- r- y+++*--END G

[Full-disclosure] Snort Signature to detect credit cards

2008-05-08 Thread wilder_jeff Wilder
Does anyone have a snort signature to detect credit cards or social security numbers? Thank you in advance, Jeff___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

Re: [Full-disclosure] asking about certificate

2008-01-28 Thread wilder_jeff Wilder
Actually the QSA is for the employee... the QSC & ASV is for the company. In order for a person to have/keep/maintain their QSA cert, they must work for QSC. If a QSA quits working for a QSC, they no longer have their QSA certification.-Jeff WilderCISSP,QSA,CCE,C/EH-BEGIN GEEK COD

[Full-disclosure] Enable secret 5 : Cisco Password

2007-05-22 Thread wilder_jeff Wilder
Anyone have any tools to crack a cisco secret 5 password? I know cain will crack a 7 password... If you would please respond off list I would be appreicative. any help out there? -Jeff Wilder CISSP,CCE,C/EH ___ Full-Disclosure - We believe in it.

Re: [Full-disclosure] marc's list getting bigger, grab while you can

2007-01-15 Thread wilder_jeff Wilder
The site is off line now. :) -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e* h--- r- y+++* --END GEEK CODE BLOCK---

[Full-disclosure] Wireless access points

2006-05-16 Thread wilder_jeff Wilder
Is anyone aware of a method to scan your network for wireless devices using the ethernet side of the device rather then the wireless? I have a remote location that I need to scan for wireless deivces and am looking for a method execute them remotely. any ideas? -Jeff __

RE: [Full-disclosure] Privilege escalation in McAfeeVirusScan Enterprise8.0i (patch 11) and CMA 3.5 (patch 5)

2005-12-22 Thread wilder_jeff Wilder
How often does McAfee try to run this file? -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e* h--- r- y+++* --END GEEK

[Full-disclosure] Broadcast storm in my network/ any ideas

2005-12-22 Thread wilder_jeff Wilder
All, I have a Windows 2000 terminal server that is consistantly sending out broadcasts to 255.255.255.255:111... below is a capture from a snort box I have running. In the last 18 hours I have had about 2000 packets from this box to this address about every 30 seconds. Snort reports the sign

RE: [Full-disclosure] Character vulnerabilities

2005-12-21 Thread wilder_jeff Wilder
WOOO HO! I'll second that -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e* h--- r- y+++* --END GEEK

[Full-disclosure] Exploit code repository

2005-12-19 Thread wilder_jeff Wilder
Does anyone know of a location where the exploit code for the issues we address on this list can be found?... Much of the time I see the e-mails roll through wiht just a high level discription of the information. I have the new and old copies of Metaspoit installed and running ... but would li

RE: [Full-disclosure] 0-day for sale on ebay

2005-12-08 Thread wilder_jeff Wilder
OMG THAT IS JUST TOO FUNNY!!! -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e* h--- r- y+++* --END GEEK CODE BLOCK

Re: [Full-disclosure] IT security professionals in demand in 2006

2005-12-06 Thread wilder_jeff Wilder
I didnt know that they gave out scores?... have they started doing that? -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e*

Re: [Full-disclosure] IT security professionals in demand in 2006

2005-12-06 Thread wilder_jeff Wilder
I'll second that -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-- R* tv b++ DI++ D++ G e* h--- r- y+++* --END GEEK CODE BLOCK-- From

Re: [Full-disclosure] IT security professionals in demand in 2006

2005-12-05 Thread wilder_jeff Wilder
Not to validate the cissp... but try to get a good security job with out it. I do not have to know how to forge the steel, machine the metal, build an engine in order to drive a car. I understand the the inner workings of an application how how it interacts with the differnent layes... There

RE: [Full-disclosure] Re: SOX whistleblowers' clause Compliance

2005-12-01 Thread wilder_jeff Wilder
Can some please send me the actual regulation that states or validates the comments of http://www.nonprofitrisk.org/nwsltr/archive/employprac091005-p.htm ? I am in this very situation right now. -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O

RE: [Full-disclosure] Hacking Boot camps!: certifications

2005-11-23 Thread wilder_jeff Wilder
I wanted to chime in on all this SANS VS. any other certification VS. training... The only thing a certification does for anyone is validate to a prospective employeer that you, at the time you took the test, knew enough to pass it. Depending on how high that bar is set will determine if you r

Re: [Full-disclosure] Hacking Boot camps!

2005-11-23 Thread wilder_jeff Wilder
I went to a " Hacking Class".. it was put on by the infosec institute... The class was written and delivered by a Jack Koziol, one of the authors of The Shellcoder's Handbook: Discovering and Exploiting Security Holes. The class I took was Advanced Ethical Hacking... it was AWESOME! It was a g

Re: [Full-disclosure] Hacking Boot camps!

2005-11-22 Thread wilder_jeff Wilder
Speaking of script kiddie stuff... bbs's and the like... anyone remember VCL?.. virus creation labratory? -Jeff Wilder CISSP,CCE,C/EH -BEGIN GEEK CODE BLOCK- Version: 3.1 GIT/CM/CS/O d- s:+ a C+++ UH++ P L++ E- w-- N+++ o-- K- w O- M-- V-- PS+ PE- Y++ PGP++ t+ 5- X-

[Full-disclosure] Microsoft EFS

2005-10-10 Thread wilder_jeff Wilder
Does anyone know if MS EFS can be cracked if you do not have access to the recovery agent? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/