Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: zeugma
He's call up a secretary and pose as a salespuke who needed access for something, and basically bullsh!t a password out of him/her. Social Engineering can be an art form all its own, but it is not really 'hacking' in the negative sense.
I used to code software for a IT security company. Despite all of the arguments about the quality of Windows versus Linux etc., most real security exploits have nothing to do with things like patches but rather with things like careless passwords and disgruntled employees. If I were the CIO for a big company with sensitive information, patching opersating systems would be way down on my list of how to protect the data.

24 posted on 01/30/2006 12:28:24 PM PST by DallasMike
[ Post Reply | Private Reply | To 12 | View Replies ]


To: DallasMike

"If I were the CIO for a big company with sensitive information, patching opersating systems would be way down on my list of how to protect the data."

That's kinda silly. Platform bugs are the easiest to fix. Just get a decent multi platform patch management system in place and keep stuff up to daye.

Unpatched boxes are childs play to own. Literally. Go look at "Metasploit" to see why.


29 posted on 01/30/2006 1:18:08 PM PST by adam_az (It's the border, stupid!)
[ Post Reply | Private Reply | To 24 | View Replies ]

To: DallasMike
If I were the CIO for a big company with sensitive information, patching opersating systems would be way down on my list of how to protect the data.

Except that patching is low hanging fruit..

46 posted on 01/31/2006 12:43:15 PM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 24 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson