<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Basics</title>
    <link>http://seclists.org/#basics</link>
    <atom:link href="http://seclists.org/rss/basics.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
    <pubDate>Fri, 19 Mar 2010 23:30:26 GMT</pubDate>
    <lastBuildDate>Fri, 19 Mar 2010 23:30:26 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>RE: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/126</link>
    <description>&lt;p&gt;Posted by BECKY MACDONALD on Mar 19&lt;/p&gt;Interesting....&lt;br&gt;
&lt;br&gt;
Certainly supports the concept of securing the end-node and not the network. I think he makes several valid points &lt;br&gt;
throughout and I too like the idea of sharing Internet connections from both the user and provider standpoints. However &lt;br&gt;
the security professional in me says I should secure all points of access (layer security is always best) and keep all &lt;br&gt;
unauthorized access of my network. The security side of me wins this one :)...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 23:29:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/126</guid>
  </item>
  <item>
    <title>RE: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/125</link>
    <description>&lt;p&gt;Posted by BECKY MACDONALD on Mar 19&lt;/p&gt;Interesting....&lt;br&gt;
&lt;br&gt;
Certainly supports the concept of securing the end-node and not the network. I think he makes several valid points &lt;br&gt;
throughout and I too like the idea of sharing Internet connections from both the user and provider standpoints. However &lt;br&gt;
the security professional in me says I should secure all points of access (layer security is always best) and keep all &lt;br&gt;
unauthorized access of my network. The security side of me wins this one :)...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 19:19:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/125</guid>
  </item>
  <item>
    <title>Re: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/124</link>
    <description>&lt;p&gt;Posted by Adam Mooz on Mar 19&lt;/p&gt;Larry,&lt;br&gt;
&lt;br&gt;
If you have the public AP infront of the private AP then, if someone&lt;br&gt;
is able to subvert the router itself (not a difficult task) then they&lt;br&gt;
have complete control of your traffic.  The private AP should be in&lt;br&gt;
front of the public AP in this case (although this is not the rule.)&lt;br&gt;
&lt;br&gt;
----------------------------------------------------------&lt;br&gt;
Adam Mooz&lt;br&gt;
Blog: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.adammooz.com&quot;&gt;http://www.adammooz.com&lt;/a&gt;&lt;br&gt;
LinkedIn: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.linkedin.com/ln/adammooz&quot;&gt;http://www.linkedin.com/ln/adammooz&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 19:06:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/124</guid>
  </item>
  <item>
    <title>Change to SANS GIAC recert process</title>
    <link>http://seclists.org/basics/2010/Mar/123</link>
    <description>&lt;p&gt;Posted by Eggleston, Mark on Mar 19&lt;/p&gt;Hello Folks,&lt;br&gt;
&lt;br&gt;
As a SANS GIAC alum, I didn't get anything in my email but I'm excited&lt;br&gt;
about the change in the recert process:&lt;br&gt;
&lt;br&gt;
&amp;quot;On March 1st, 2010, GIAC will begin to offer expanded certification&lt;br&gt;
maintenance options. Besides the existing method of retaking the&lt;br&gt;
standard certification exam, we will offer two main additional options.&lt;br&gt;
One alternative is for you to submit a published technical research&lt;br&gt;
paper, such as a GIAC Gold Paper. Another...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 18:56:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/123</guid>
  </item>
  <item>
    <title>Re: Skype / Vsee</title>
    <link>http://seclists.org/basics/2010/Mar/122</link>
    <description>&lt;p&gt;Posted by M.D.Mufambisi on Mar 19&lt;/p&gt;The risk around such applications really is the easy leakage of&lt;br&gt;
corporate information. Chat applicatios present a great risk around&lt;br&gt;
this. Corporate documents can be easily transmitted out the network.&lt;br&gt;
Another issue is that individuals do not normally know where to draw&lt;br&gt;
the line between occasional &amp;quot;chatting&amp;quot; and wasting company time.&lt;br&gt;
Viruses and malware could also be transmitted this way. Chat traffic&lt;br&gt;
is encrypted and as such, these...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 17:32:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/122</guid>
  </item>
  <item>
    <title>Re: Palevo Worm Infection</title>
    <link>http://seclists.org/basics/2010/Mar/121</link>
    <description>&lt;p&gt;Posted by Albert R. Campa on Mar 19&lt;/p&gt;check out the 3 CVEs linked on this site. Some old MS vulnerabilities.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.symantec.com/security_response/writeup.jsp?docid=2009-072313-3630-99&quot;&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2009-072313-3630-99&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
__________________________________&lt;br&gt;
Albert R. Campa&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 16:30:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/121</guid>
  </item>
  <item>
    <title>RE: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/120</link>
    <description>&lt;p&gt;Posted by Lauren Twele on Mar 19&lt;/p&gt;You also have to consider audit logs, policy management and provisioning. An identity management solution sounds like &lt;br&gt;
the way to go here&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: listbounce () securityfocus com [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:listbounce&quot;&gt;mailto:listbounce&lt;/a&gt; () securityfocus com] On Behalf Of Channel, Lawrence F CTR &lt;br&gt;
USAF ACC ACC/A8ZX&lt;br&gt;
Sent: Wednesday, March 17, 2010 9:59 AM&lt;br&gt;
To: security-basics () securityfocus com&lt;br&gt;
Cc: John Lightfoot&lt;br&gt;
Subject: RE: Home wireless free hotspot&lt;br&gt;
&lt;br&gt;
John,...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 16:28:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/120</guid>
  </item>
  <item>
    <title>RE: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/119</link>
    <description>&lt;p&gt;Posted by Lauren Twele on Mar 19&lt;/p&gt;IF you want to block all employee access to web mail (e.g., Gmail,&lt;br&gt;
Hotmail, Yahoo, etc) from within your corporate network:&lt;br&gt;
--&amp;gt;THEN you should set up firewall rules as suggested by the attached &lt;br&gt;
--&amp;gt;email (SinglePoint not needed)&lt;br&gt;
&lt;br&gt;
IF you want to control access by allowing only SOME employee access to&lt;br&gt;
web mail...:&lt;br&gt;
--&amp;gt; THEN you should license SinglePoint from Symplified&lt;br&gt;
&lt;br&gt;
IF you want to audit access to web mail...:&lt;br&gt;
--&amp;gt; THEN you should...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 16:20:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/119</guid>
  </item>
  <item>
    <title>Re: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/118</link>
    <description>&lt;p&gt;Posted by Johnathan on Mar 19&lt;/p&gt;Signing a contract is not a legal agreement? There isn't any service provider that I am aware of that will just take &lt;br&gt;
your word for agreeing to their terms of services, terms and conditions and/or terms of use.  &lt;br&gt;
&lt;br&gt;
I never said anything about breaking the law, the term legal does not always imply &amp;quot;breaking the law&amp;quot;. Not fullfiling &lt;br&gt;
your end of a signed agreement may not be breaking the law, but in the states, many situations can be...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 16:11:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/118</guid>
  </item>
  <item>
    <title>Access 2003 MDE bypass.</title>
    <link>http://seclists.org/basics/2010/Mar/117</link>
    <description>&lt;p&gt;Posted by Rivest, Philippe on Mar 19&lt;/p&gt;Hi&lt;br&gt;
 &lt;br&gt;
i'm looking for a way to get access to the code once a mdb file has been&lt;br&gt;
converted to a mde file.&lt;br&gt;
Its my own code &amp;amp; application (Access 2003),i already have access to the&lt;br&gt;
code but i want to ensure that if publish in a mde format no one will have&lt;br&gt;
access to my code.&lt;br&gt;
&lt;br&gt;
Also, are you aware if theres a way to remove a signature from an mde code&lt;br&gt;
(signature is based on a certificate).&lt;br&gt;
 &lt;br&gt;
Thanks&lt;br&gt;
&lt;br&gt;
  &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://logo.transforce.org/ligneg.gif&quot;&gt;http://logo.transforce.org/ligneg.gif&lt;/a&gt;&amp;gt;...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 16:05:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/117</guid>
  </item>
  <item>
    <title>Re: Reporting SSH abuse</title>
    <link>http://seclists.org/basics/2010/Mar/116</link>
    <description>&lt;p&gt;Posted by mgk on Mar 19&lt;/p&gt;Hi&lt;br&gt;
&lt;br&gt;
We take reports like this seriously when we receive them and take them &lt;br&gt;
up with customers.  Theres no harm in sending a report with some logs. &lt;br&gt;
Wording such as, it seems as though this is the situation is less &lt;br&gt;
confrontational than, Attacks are coming from your network, sort it out.&lt;br&gt;
&lt;br&gt;
Here are a few we have had:-&lt;br&gt;
&lt;br&gt;
Looks like your custommer with IP xxxxxxxxx is doing ssh attacks to my &lt;br&gt;
server.&lt;br&gt;
Please take care about&lt;br&gt;
  Best Regards&lt;br&gt;
&lt;br&gt;
and&lt;br&gt;
&lt;br&gt;
Hi,...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:52:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/116</guid>
  </item>
  <item>
    <title>RE: Home wireless free hotspot</title>
    <link>http://seclists.org/basics/2010/Mar/115</link>
    <description>&lt;p&gt;Posted by Murda on Mar 19&lt;/p&gt;I am fascinated by the implications of this thread and by what it is the OP wishes to do and its potential &lt;br&gt;
ramifications. It seems to me that the whole privacy and anonymity aspects of this situation and similar will become &lt;br&gt;
more of a battleground over the next few years in most western countries; Australia is already gearing up for a net &lt;br&gt;
filter that will curtail the kind of content that can be accessed. How it will work is anyone's guess and...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:46:28 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/115</guid>
  </item>
  <item>
    <title>Re: Skype / Vsee</title>
    <link>http://seclists.org/basics/2010/Mar/114</link>
    <description>&lt;p&gt;Posted by Shawn Merdinger on Mar 19&lt;/p&gt;Hi WW,&lt;br&gt;
&lt;br&gt;
While dated (December, 2006) Skype's giude for network admis might be helpful&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.skype.com/security/network-admin-guide-version2.2.pdf&quot;&gt;http://www.skype.com/security/network-admin-guide-version2.2.pdf&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
--scm&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how &lt;br&gt;
it benefits your company and...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:26:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/114</guid>
  </item>
  <item>
    <title>Check if root is allowed on SSH server - remotely?</title>
    <link>http://seclists.org/basics/2010/Mar/113</link>
    <description>&lt;p&gt;Posted by savekov on Mar 19&lt;/p&gt;Hi guys ,&lt;br&gt;
&lt;br&gt;
is there any special way I could check remotely if the ROOT login is allowed&lt;br&gt;
or not in SSH server?&lt;br&gt;
I dont have any account on this server to login to the server and check the&lt;br&gt;
config files.&lt;br&gt;
Im just curious is there any way I could remotely find out if the root is&lt;br&gt;
allowed or not allowed?&lt;br&gt;
&lt;br&gt;
Thanks ...guys&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
Securing Apache Web Server with thawte Digital Certificate&lt;br&gt;
In...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:22:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/113</guid>
  </item>
  <item>
    <title>Palevo Worm Infection</title>
    <link>http://seclists.org/basics/2010/Mar/112</link>
    <description>&lt;p&gt;Posted by martin on Mar 19&lt;/p&gt;Hi All&lt;br&gt;
&lt;br&gt;
We've just had some clients get infected with the above worm.  The&lt;br&gt;
worm has definitely spread via removeable drives, but it appears to&lt;br&gt;
have also spread directly between networked PC's within the same&lt;br&gt;
broadcast domain.  None of our users however had admin rights on any&lt;br&gt;
PC, so I'm curious what vulnerability the virus is using to spread&lt;br&gt;
itself amongst our machines.&lt;br&gt;
&lt;br&gt;
According to the link below, it's spreading via &amp;quot;known software...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:16:58 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/basics/2010/Mar/112</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
