Re: Where can i find a complete list of ip's and countries ou network ?

2002-12-31 Thread James-lists
http://www.blackholes.us - Original Message - From: "Jefferson Costa" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, December 30, 2002 8:40 AM Subject: Where can i find a complete list of ip's and countries ou network ? > Hi everybody ! > > I'm lookingo for a web page or a do

MS IIS 5 server is hacked leaving undeletable folders and files

2002-12-31 Thread Don Phillipe
I have a small server I use for my home business and use it mainly for anyone who needs to send a large file that will not go through email. I have an anonymous UPLOAD FTP account that I open up to receive these. From time to time I forget and leave this open (I know this is stupid but I thought

Re: Where can i find a complete list of ip's and countries ou network ?

2002-12-31 Thread Meritt James
You may very well be out of luck. Due to the dynamic nature of all the IPs (and the associated administrative difficulties - it was a real paid a decade and a half or so ago when we had to do that!) and the immense number of systems, we shifted to name servers years ago. You may wish to try: htt

RE: Case Study books or Websites

2002-12-31 Thread Rapaille Max
A litlle bit old, but very interesting, for sure is Underground from SUELETTE DREYFUS and JULIAN ASSANGE You can buy a copy, or get a free Txt version at http://www.underground-book.com/ The book tell the story of some famous hacker, some 10 years or more Ago, until 2001 (In fact first publishi

RE: Popup security sales gimmick

2002-12-31 Thread Greg van der Gaast
I agree, I don't think any of this is actually being displayed by the web server itself. It just loads your local explorer within ie. The fact that I can view 20mb image files in a few seconds on a 28.8 connection makes it pretty obvious that I'm not receiving the data from the site. Nice for fud,

Re: AS: Incident Response Guidelines

2002-12-31 Thread Christophe de Livois
Here is an article on the subject: http://www.cio.com/archive/031502/plan_content.html?printversion=yes Hello, I'm about to start huge documentation phase on creating Incident Response Guidelines / Handling - including creating the structure, creating the Incident Response Team, documenting th

RE: Windows Network Audit Tool Question

2002-12-31 Thread Rosado, Rafael (Rafael)
You might want to consider running Microsoft's Baseline Security Analyzer (MSBA) - http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/ tools/Tools/MBSAhome.asp or GFI's Languard Network Scanner (http://www.gfi.com/lannetscan/index.htm). Both are open source/freeware and

http session expiry

2002-12-31 Thread YashPal Singh
Hi All, Environment: IIS 5.0, Windows 2000 server Can you please direct me to some links on http session expiry. The issues is that i am testing a web application. So i want to test that user can not access the web pages after session is expired. It will also be helpful if some information on IIS

RE: Incident Response Guidelines

2002-12-31 Thread Scott Schwendinger
I have used the Department of the Navy Automated Information Systems Securty Program manual to build continrnvy plans. This manual is a little dated, but it does have good sample plans, a preparatory action outline, and an action plan outline. This manual has provided great help in building well

Re: Popup security sales gimmick

2002-12-31 Thread Adexter
It seems that way. I have ran into similar sales gimmicks many times. I usually don't allow Java applets to run on my personal systems. Quite a few clients of mine have ran into similar things and been seriously "freaked out" as it could do that to a person. It is just a little Java Applet trick,

Re: [Re-post] Suggestions for basic software for security

2002-12-31 Thread GSimmonds
> > I would like to have some suggestion for software for security (port > scan, firewall, etc.); I have a Pentium III, 256 Mb of RAM, 20 GB of Hd, > dialup connection (I should upgrade to cable connection in few days) and > WinME (I am thinking to upgrade to XP). > Hello, You mentioned using Zon

RE: [Re-post] Suggestions for basic software for security

2002-12-31 Thread Richard H. Cotterell
Ref: Di Fresco Marco <[EMAIL PROTECTED]>'s message dated 27 December 2002, 18:45 hours. >> It isn't abundantly clear what you want to do. You >> say you're asking for "security software" for "port >> scan, firewall, etc.". You say you already have >> ZoneAlarm and VirusScan. > >Yes, I alr

Re: VPN

2002-12-31 Thread Chris Berry
From: Luan Rocha <[EMAIL PROTECTED]> I'm configuring a server(win2000 advanced server) to provide internet for the inside network and a VPN to do the maintaining. But i dont know why, i only can access the VPN through the inside network, but from internet i get an error that my server is not r

Re: copying a disk image to restore on linux

2002-12-31 Thread Kevin Currie
If you are going to use dd to backup a partition, you might want to zero out all of the unused space first, so it will compress better. dd if=/dev/zero of=/bigZEROfile ; rm /bigZEROfile The dd will fill the disk with a large file full of zeros, then exit when the disk is full, then delete the file

RE: VPN

2002-12-31 Thread Ted Frederick
Do your filters allow IP GRE and TCP PPTP traffic? That could be blocking you. Ted Frederick -Original Message- From: Luan Rocha [mailto:[EMAIL PROTECTED]] Sent: Saturday, December 28, 2002 1:24 PM To: Security basics Subject: VPN Hey, I'm configuring a server(win2000 advanced serve

RE: VPN

2002-12-31 Thread Rick Darsey
It sounds like either your router, or the Windows 2000 server is blocking VPN traffic from outside the LAN. You need to open several ports on the router to allow the VPN tunnel to terminate at the Windows 2000 server. Here is a partial list: access-list 101 permit gre any host xxx.xxx.xxx.xxx acc

RE: [Re-post] Suggestions for basic software for security

2002-12-31 Thread Kyle Lai, CISSP, CISA
Free security software: 1. Anti-Trojan software. Anti-Virus won't pick up some Trojans and hacker tools. You can download a free Anti-Trojan tool, Swat-It from www.lockdowncorp.com 2. Ad-Aware software. Get rid of spyware or advertisement that are installed on your system just by surfing on the

Re: Fiber optic vampire taps

2002-12-31 Thread Meritt James
What we did at another location was to run the network inside of piping and the pipes were then pressurized. Then monitor the pressure. Tapping the 'net without causing a drop in pressure was not trivial... ;-) YOu didn't mention the run. Jim Nick Iglehart wrote: > > > -BEGIN PGP SIGNE

RE: Popup security sales gimmick

2002-12-31 Thread Kyle Lai, CISSP, CISA
In some instance, these pop-ups use "messenger" service to pop-up the messages. In WinNT, 2000, and XP systems, you might want to consider disabling the "messenger" service. /Kyle Kyle Lai, CISSP, CISA KLC Consulting, Inc. 617-921-5410 [EMAIL PROTECTED] -Original Message- From: netsec n

Re: Popup security sales gimmick

2002-12-31 Thread Gene Cronk
I notice this doesn't work if you're behind a firewall (well, behind MY firewall, anyway:-D) netsec novice wrote: I ran into this popup and initially it concerned me. I thought I would post it here for confirmation on its validity. It appears to me that this site runs a script that simply

RE: Popup security sales gimmick

2002-12-31 Thread Optrics Engineering - Shaun Sturby, MCSE
Here is the source of the popup page. It looks like it does just that, open a iframe to display the local drive. a:link {font:8pt/11pt verdana; color:red} a:visited {font:8pt/11pt verdana; color:red} WARNING: No Privacy Protection Software Found WARNI

RE: Incident Response Guidelines

2002-12-31 Thread Robinson, Sonja
For all of you who have replied requesting a sample, I will be more than happy to respond. I am receiving hundreds of requests at the moment. We are short of staff due to the holidays and it make take a few days to respond to you all, please be patient. All I ask in return for the samples are, i

RE: Incident Response Guidelines

2002-12-31 Thread Rosado, Rafael (Rafael)
Check the document created by CIO Magazine, FBI and Secret Service Agency (CIO CYBERTHREAT RESPONSE & REPORTING GUIDELINES --> http://www.cio.com/research/security/incident_response.pdf). Although it is not very specific to internal incident response guidelines, it sheds some light over the proces

RE: Incident Response Guidelines

2002-12-31 Thread DeGennaro, Gregory
SANS also has incident response training ... track 4 is an outstanding class! I took the class (track) and it was awesome! www.sans.org for an area near you or for more information. Greg -Original Message- From: Ayers, Diane [mailto:[EMAIL PROTECTED]] Sent: Saturday, December 28, 2002

Where can i find a complete list of ip's and countries ou network ?

2002-12-31 Thread Jefferson Costa
Hi everybody ! I'm lookingo for a web page or a document that contain a list with ip's in the world e it's respectives countries. thks