Re: Modem connection

2003-08-14 Thread Brad Mills
None, > Q. is there an answer to that? i can't setup a hardware firewall, and i need windows to run more often than linux (for the time being.) > Why not? No physical space? If you have an old 'doorstop' machine, grab a 20-meg smoothwall *.iso and live live in peace. We fed a few machines here

Re: SSH mail server experiments

2003-08-09 Thread Brad Mills
Skibi, > BTW does onyone can give me a hint with secure ftp? Is stunnel the nly > option or there is another service? > have a look at WinSCP - http://winscp.sourceforge.net/eng/ " ...WinSCP is an open source SFTP (SSH File Transfer Protocol) and SCP (Secure CoPy) client for Windows using SSH (S

Re: Bank Automated Teller Machine Biometrics

2003-08-08 Thread Brad Mills
Ulisses, >I´ve heard there are flaws in Iris and Facial recognition. Does anybody know where i can find information about these flaws ? Research counterpane.com's stuff, I think Bruce had an article iris stuff recently... see the Crypto-Gram articles. cheers, /b

Re: Question for all

2003-08-04 Thread Brad Mills
Chris, > Well, the best plan would be to wipe your hard drive and start over, but > barring that, my next step would be to use SpybotSD, it's pretty good at > cleaning out garbage like that. If it works you might consider sending a > donation, the developer does all that work for free. > Agre

Re: Redhat 8.0 networking/routing/security issue...

2003-07-30 Thread Brad Mills
Nokio, > Anyway. I'm fairly new with Linux networking and i'm a little stumped. I > have three boxes, none have OS's yet, but i'm planning on one having Windows > XP Pro, and the other two with Redhat 8.0. My plan is to have one of the > Redhat boxes set up kind of as a router(?) so my two comp

Re: configuration settings

2003-07-23 Thread Brad Mills
Morton, > You might want to check out http://www.astero.com - they have an excellent > firewall (requires a standalone box with a 400 MHz processor and 128 MB > RAM); it runs on a hardened Linux distro, and you can include Kapersky AV > for a nominal price (or free, if you particpate actively in t

Re: finding who has logged in on Win2k Pro

2003-07-22 Thread Brad Mills
Jose, > We have possibly had some type of incident at our work place. I'd like to > know if it is possible to check and see the "User Login" history on a Win2K > pro machine. Is this history log enabled by default? What are some other > ways? A starting point would be your Security logs, under

Re: Microsot Liability for vulnerabilities

2003-07-22 Thread Brad Mills
Ronish, Let good ol' capitalism take ahold, let the market bear it out. Let the largest consumer of computer stuff in the world set a standard, betcha others will follow: http://hsc.house.gov/files/Testimony_Schneier.pdf (above link from http://www.sans.org/newsletters/newsbites/vol5_28.php) /

Re: building an FAQ for Security-Basics

2003-07-18 Thread Brad Mills
Kelly, > I will be building an FAQ for the Security-Basics mailing list over the > coming month or so. I would appreciate comments and opinions on what you > think should be included in the first version of the FAQ. Would there be any room for a 'mentality' or 'attitude' category? I've read in

Re: Top 10 (secure) programs

2003-07-09 Thread Brad Mills
Shane, > How about people posting their favorite ‘’secure’’ programs for email, > etc... :-) Windows: Virtual Access. Plain text, you can select not to view html, and *anything* not in plain ol' text comes as an attachment. Further, you can set it to require a double-click to open said attch'd

Re: Windows 2000 port 10000

2003-07-07 Thread Brad Mills
Salvatore, > Does anyone know what port 1 is used for. (snip) I believe this is the default port for Linux (other os?) application Web Min, such as https://x.x.x.x:1/ cheers, /b --- Evaluating SSL VPNs' C

Re: Top 50 or less Security Sites

2003-07-07 Thread Brad Mills
Niall, > Would anyone hava a llist of the top 50 or less security sites. such a list is unknown to me, here's my 2 phennings: http://www.sans.org/ "SANS is the trusted leader in information security research, certification and education. The SANS (SysAdmin, Audit, Network, Security) Institute

Re: Data erasing tool

2003-07-04 Thread Brad Mills
> We are looking for a tool that will erase all data beyond recovery from a > hard drive. We going to get rid of few computers and do not want data to get > into anyone's hand. Both freeware and commercial ware are ok. Would prefer a > solution which is bootable from a cd (OS independent). DBAN -

Re: Port scanning question

2003-07-04 Thread Brad Mills
Thom, > As a relative newcomer to the security field, but with a reasonable amount > of experience in sys admin roles, I am now responsible for the network > security of the (small) company I work for. One of the things I would like > to do is determine if (when) our web server, which hosts our a

Re: Part 2 - Best tools to put on Linux Laptop

2003-07-03 Thread Brad Mills
Tim, > If you were building a laptop for the purpose of network monitoring, > sniffing, forensics and security audits, what tools would you put on it? > Thanks again, Using one of the free linux's (mandrake 9.1) with the distro comes nmap, and nmapfe (nice gui) as well as tcpdump. Ethereal is i

Re: Penetration Test

2003-06-25 Thread Brad Mills
Linkcraft, > Hi, I wish to know if you can direct me to some of the > web site for the following informations:- > > 1. Forms or templates to be used for penetration test > on: > 1.1 Planning and preparation. (snips) Google it for: Open-Source Security Testing Methodology Manual Created by Pete

Re: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618

2003-06-25 Thread Brad Mills
Hilal, > i am not sure if i am asking the right question within the same subject,but > i am configuring the firewall throught the telnet connecting / from winxp > workstation. > > Is there any possibility for any internal user to use any tools that will > haijack my telnet password - password

Re: Center Control and Department's Firewall

2003-06-23 Thread Brad Mills
Khan, > We are in process of creating policy on how much (if > any)control can we give to department's administrators > to the firewall that will be installed at demarc > point. (snips) > Have a look at smoothwall GPL, right out of the box it blocks anything above :1024, and has 2 zones. 3 nic

Re: VA vs PT tool

2003-06-16 Thread Brad Mills
James, et al - > I didn't see this on your list below but I would be surprised if no one > had suggested it... > > Nessus (www.nessus.org) will do *some* of that depending upon the > vulnerability and how you configure Nessus to do the scan. The > following are advantages/disadvantages dependin

Re: Locking down workstation

2003-06-11 Thread Brad Mills
Dana, et al, > Here is a good start for you on some resources to assist you in hardening > your workstation(s). > > The NSA released some unclassified documents on ways to reduce the attack > surface of you Microsoft based operating systems. I found the Windows XP and > 2000 guides a good startin

Re: Firewall and DMZ topology

2003-06-10 Thread Brad Mills
William, > I would like to set up a SOHO network with a firewall and DMZ for mostly > web serving and email. Of course, there are private PCs on the internal > network, Windows and Linux. > > My connection is a dynamic IP on a pppoe and I already have an old > laptop used as a simple firewall set

Re: Firewall configuration statistics

2003-06-09 Thread Brad Mills
> That makes absolutely no sense. Plus I am not looking for a philosophical > answer. I was looking statistics for marketing. Does anyone know of a good > reference site for firewall and other security statistics. > Try www.SANS.org - likely best source of info ;) as they are un-concerned about s