Re: ARP Poisoning

2002-11-09 Thread Matt Hemingway
** > > This email and any files transmitted with it are confidential and intended > solely for the use of the individual or entity to whom they are addressed. > > If you have received this message in error please notify SYSNET Ltd., at > telephone no: +353-1-2983000 or [EMAIL PROTECTED] > > *** >*** -- -- Matt Hemingway [EMAIL PROTECTED] http://www.pcnalert.com 626-585-2788 x136 --

Re: ARP Poisoning

2002-11-08 Thread Matt Hemingway
> > > __ > Do you Yahoo!? > U2 on LAUNCH - Exclusive greatest hits videos > http://launch.yahoo.com/u2 -- -- Matt Hemingway [EMAIL PROTECTED] http://www.pcnalert.com 626-585-2788 x136 --

Re: Vulnerability Assessment Software and/or Services

2002-10-07 Thread Matt Hemingway
ance, > > Kevin > > > -- > Kevin Bachelder > > Microsoft Certified Systems Engineer - Windows NT 4.0 (MCSE) > Microsoft Certified Professional - Windows 2000 (MCP) > Citrix Certified Administrator (CCA) > CompTIA A+ Certified Computer Repair Technician (A+) -- -- Matt Hemingway [EMAIL PROTECTED] http://www.pcnalert.com 626-585-2788 x136 --

Re: Increase in port 137 scans

2002-10-03 Thread Matt Hemingway
31 (0)6 - 28 46 47 45 > > E-Mail (business): [EMAIL PROTECTED] > > E-Mail (private): [EMAIL PROTECTED] > > MSN Messenger: [EMAIL PROTECTED] > > ICQ (UIN (seldom used)): 191458 -- -- Matt Hemingway [EMAIL PROTECTED] http://www.pcnalert.com 626-585-2788 x136 --

Re: Where can I find a secure file replication program?

2002-05-20 Thread Matt Hemingway
ind piece of software. > > Thanks in advance. > > Nico > > > _ > Chat with friends online, try MSN Messenger: http://messenger.msn.com -- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: Webservers

2002-05-12 Thread Matt Hemingway
(or free), > secure, easy-to-administer replacement?? > > I have a (legal) copy of O'Reilly Website Pro v2.0. Would that be a > good choice?? > > Tom -- ---- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: Secure FTP Server

2002-05-03 Thread Matt Hemingway
ime. It'll have some sensitive info so I need something > with good authorization. Anyone can point me in the right > direction? Thanks in advance... -- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: DMZ Stuff

2002-04-07 Thread Matt Hemingway
; 2) What is the better way to implement it ? -- ---- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: sniffer cable

2002-03-19 Thread Matt Hemingway
plans to > make one? > > Heath Calhoun -- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: sniffing a switch

2002-03-14 Thread Matt Hemingway
www.pgp.com> > > iQA/AwUBPI4lmdqAgf0xoaEuEQL2pQCffY5f4dArBsXzzBwqPVpQ3D5Fs8oAoL3m > XOh7wYu4O8KoTCmsuhhgosbz > =Ys0V > -END PGP SIGNATURE- -- Matt Hemingway SupplyEdge [EMAIL PROTECTED] 800-733-3380x136

Re: Security Magazines

2002-03-01 Thread Matt Hemingway
Paper magazine wise, I get Info Security News (http://www.infosecnews.com). Online wise: Security News Portal (http://www.securitynewsportal.com) is good and funny. http://www.infosyssec.com has alot of good info and references as does http://www.packetstormsecurity.com and http://www.antionlin

Re: Port scan reporting?

2002-02-28 Thread Matt Hemingway
There's nothing illegal about it. I would do a "whois" on Arin (http://www.arin.net) with that IP address, find and call whoever the ISP is and see if you can get them kicked or banned for abuse. It's a long shot but worth a try. Could be fun too! -Matt On Monday 25 February 2002 12:35, Ben

Re: Detecting Sniffers?

2002-02-22 Thread Matt Hemingway
I would suggest using Ettercap (http://ettercap.sourceforge.net) to sniff in the switched network. Sniff Host A from Host B. Have Ethereal (www.ethereal.com) capture on Host C. You might find something interesting with the ARP requests/changes. Another thing you can do (this is what I do) is

Re: disabling port 79

2002-02-22 Thread Matt Hemingway
No impact. A very wise decision. It's one of the first things I do after setting up a new machine. -Matt On Wednesday 20 February 2002 07:55, Dean Fox wrote: > I am contemplating to remove/disable finger or port 79 from some > workstations and/or servers. Is there any negative impact for doi

Re: Password Management

2002-02-20 Thread Matt Hemingway
Sounds like you need a directory service. NIS will work. Although to have it work with Windows you will need Services for Unix. You may also want to look into LDAP. Sun seems to have chosen Netscape Directory Service for LDAP and to replace NIS/NIS+. -Matt On Monday 18 February 2002 21:29,

Re: SSH on Solaris 2.4

2002-02-12 Thread Matt Hemingway
This probably won't help but. Do you have a file called ssh_prng_cmds in your ssh directory? Edit the file to only run commands that are valid for the system. I'm guessing it's running something that is not valid for Solaris 2.4. -Matt On Monday 11 February 2002 02:12, Oliver Bierma

Re: Certificates (MCSE,CCNA,...)

2002-02-12 Thread Matt Hemingway
I've been taking classes at a local community college to obtain the CCNA cert. The school has a deal with Cisco so the book is all online (and free) and is made by Cisco. There are 4 classes that cost about $40 each. So all said and done about $160. The cool thing about it being online, is

Re: SSH on Solaris 2.4

2002-02-08 Thread Matt Hemingway
We had a hell of a time getting SSH installed on a 2.5 system. We had to compile without PAM support, make sure the GNU version of gcc was installed and that bc, zlib and few other packages we're up to date. I would check out what SSH needs, package wise, and make sure everything is the right

Re: Is there any free replacement for zone alarm ?

2002-01-04 Thread Matt Hemingway
I like Tiny's personal firewall. http://www.tinysoftware.com -Matt On 3 Jan 2002 at 12:27, Daniel Chojecki wrote: > Dear Subscribers ! > > I`m looking for free replacement (GNU or freeware) for ZoneAlarm (i > mean firewall software for Win9x/NT/2k). > > I was looking through archives/lists/we

Re: ADSL Security questions

2001-11-27 Thread Matt Hemingway
Sounds like your're there. I don't know the extent of Mandrakes "High" security level, but I would due the following (at least): 1. Turn off telnet, rlogin and ftp. Instead use SSH, slogin and sftp. 2. Turn off all unnecessary services in /etc/services and /etc/inetd.conf. If you have any q

Re: Multiple port mirroring?

2001-11-21 Thread Matt Hemingway
I know 3com switches have a matrix port, in which you could set it up to sniff from that. -Matt On Sunday 18 November 2001 22:03, Marc Mc Guinness wrote: > Hello! > > Am Mittwoch, 14. November 2001 19:24 schrieb David Ellis: > > What you could actually do is create a mirrored port on your > > s

Re: IIS Hack Attempt

2001-11-20 Thread Matt Hemingway
Code Red. Code Blue. Nimda. Take your pick. -Matt On Thursday 15 November 2001 10:18, Ryan Ratkiewicz wrote: > Can someone help me decipher this? > > 11:30:48 207.217.205.149 GET /scripts/root.exe 404 > 11:30:48 207.217.205.149 GET /MSADC/root.exe 404 > 11:30:49 207.217.205.149 GET /c/winnt

Re: Remote Admin of DMZ

2001-11-20 Thread Matt Hemingway
If you can tunnel VNC through SSH that would be pretty secure. I don't know of any applications off hand that will do that though (although I remember Terraterm having those capabilities). -Matt p.s. if you want REAL secure...install linux. :-) On Monday 19 November 2001 14:17, Matt LY

Re: What firewall?

2001-11-20 Thread Matt Hemingway
Actually, the Cisco Pix firewall is not 100% command line interface. It has a very nice GUI interface that can be used as well. -Matt On Sunday 18 November 2001 12:26, Roger Bou Aoun wrote: > Well according to my experience, if you want quality and something easy > to use with a nice Graphica

Re: Attack Lists

2001-11-18 Thread Matt Hemingway
Try http://www.dshield.org/ On Wednesday 14 November 2001 11:07, Jason Jaszewski wrote: > Does anyone know of any lists published online or elsewhere that record IP > addresses of computers doing (or that have done) port scans on other > (remote) systems? I have a list I'd like to compare to some

Re: List of Windows NT/2000 files and what they do

2001-11-14 Thread Matt Hemingway
Have you tried doing a search on Google (www.google.com) for the files in question? I've run upon this many a time and Google has been my savior. You may also want to try searching on Microsoft's site for those files as well. -Matt On Monday 12 November 2001 10:24, May, Jason S wrote: > Does

Re: Packet Sniffing in a Switched LAN

2001-11-13 Thread Matt Hemingway
Matt On Friday 09 November 2001 15:32, Marc Mc Guinness wrote: > Hello! > > Am Donnerstag, 8. November 2001 23:24 schrieb Matt Hemingway: > > If it's a switched network, which the subject of this e-mail > > states, than Ethereal won't work. The best tool for a switc

Re: Outlook & FTP Passwords

2001-11-13 Thread Matt Hemingway
I believe using APOP will encrypt the POP3 password. As for FTP, you should install OpenSSH and use SFTP as that encrypts the password. -Matt On Thursday 08 November 2001 20:21, Akbar Ali wrote: > Hi all, > > Is there a way to encrypt passwords for Outlook & FTP? I ran a sniffing > tool & it w

Re: Packet Sniffing in a Switched LAN

2001-11-09 Thread Matt Hemingway
If it's a switched network, which the subject of this e-mail states, than Ethereal won't work. The best tool for a switched network is ettercap (ettercap.sourceforge.net). Personally I use Arpwatch (no url available) to find all hosts on the network and than use Ettercap to sniff the victim.

Re: Penetration testing

2001-10-23 Thread Matt Hemingway
Just try to put yourself in an outsiders shoes. Pretend like you know *nothing* about your network. Tools like nmap, nessus, saint, sara, fping and the like work great together in security auditing. -matt On Mon, 22 Oct 2001 08:17:53 -0700 (PDT) Security <[EMAIL PROTECTED]> wrote: > To

Re: Promiscuous pcmcia network card

2001-10-19 Thread Matt Hemingway
Have you tried a 3com card? Have you checked anything out on nmap, nessus or ethereal's page concerning laptops/pcmcia ethernet cards? -matt On Wed, 17 Oct 2001 09:02:32 -0500 David H Hickman <[EMAIL PROTECTED]> wrote: > > Hello. I need to run nmap, nessus and ethereal on a laptop. So far

Re: help needed....

2001-09-26 Thread Matt Hemingway
Regarding packet sniffing on a switched network, I don't know if there is anything for Windows, but for Linux there's ettercap (ettercap.sourceforge.net). It pretty much poisons the ARP table of the source and destination of the host you want to sniff. "Man in the middle" is what they call

Re: Windows 98 Sniffer

2001-09-21 Thread Matt Hemingway
There is a Windoze port of Ethereal which works quite well: http://www.ethereal.com/distribution/win32/ There is also a Windoze port of Snort. I don't know how stable it is though: http://www.snort.org/downloads.html#1.19 Thats all you need! Cheers, -matt On Wednesday 19 September 2001 14

Re: Is it "legal" to nmap offending hosts?

2001-09-12 Thread Matt Hemingway
I say if someone runs nmap on your host you should be able to run it right back on one of their's. If someone hits me in the face, I hit them right back. If someone calls me stupid, I call them a f'ing moron. If someone scans my computer, I DoS them.but thats just me. :-) -matt O