Slashdot Mirror


User: frodo+from+middle+ea

frodo+from+middle+ea's activity in the archive.

Stories
0
Comments
852
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 852

  1. Re:Questions... on Spyware for Corporate Espionage · · Score: 1
    Was the password set by an individual who then gave each part to the respective person, or did each of the 3 type their own part of the password that they came up with?

    It was generatede by one person , who then split it between 3 people. But root login was allowed only from terminals, (no root login over intranet , very strict policy, su command disabled). And the person , who generated the password, was not allowed anywhere near the terminals, he had no access the server rooms, so he couldn't use it .

    it is still a bit weak ,as in he could pass the password to someone who has access to the terminal, but any password breach would immediately point to him , and he would not only loose his job but risk criminal insvigation.

    Neat idea though, and sounds like they had a good security policy.

    no kidding, Mention the word craker and everybody in a typical corporate freaks out, not these guys, they used to hire them regularly to find holes in their netowrk/systems. They were very much positive to white caps, though I don't know their stance on grey caps.

  2. Re:Questions... on Spyware for Corporate Espionage · · Score: 4, Interesting
    I can sympathise with you , but you do realise that you are working (or have worked) for one idiot CEO.

    Two years ago I was working for a major bank's international head office, and the security there was paranoidal. It was a sys-admins dream come true.

    • No internet access, except for only those who need it. only http and https allowed.
    • No FTP or telnet, only ssh allowed, and ssh server , configured to allow access only from a very restricted subdomain
    • All system/sys DB accounts disabled after initial setup. No database with customer data could go live unless the system/sys a/cs were disabled
    • Audit loggig of every data that goes in-out
    • Root password split btween 3 persons, i.e. all three have to be present to log in as root..priceless
    • A new password generated for every previleged a/c login. i.e. password valid for only one login
  3. Re:Questions... on Spyware for Corporate Espionage · · Score: 1
    Yes this may not be prevented , but can definitely be detected by periodically checking proxy server logs.

    first off all, I am very uncomfortable with a corporate LAN , which is on the internet. The least you can do is set up a gateway and NAT the local lan. And use a proxy server.

    A periodic check of proxy-server log, should indicate any suspicious activity, and can be prevented in future.

  4. Questions... on Spyware for Corporate Espionage · · Score: 4, Insightful
    Pardon my ignorance, but...

    • What kind of stupid sys-admin allows .vbs, .js , .exe, .sws attachements thru the corporate email ?
    • What kind of idiot sys-admin would allow the corporate users , to run their PCs with admin previleges , so that any unwanted junk s/w be installed on their PCs ?
    • Which genius allows unrestricted access to confidential corporate data to its users ?
    • Why do the corporate firewalls not block out-bound traffic to all ports but a select few HTTP/SSL ect ?
  5. Re:why... on The Riches of Open Source · · Score: 1
    funny , you should catch the altruistic angle. I noticed it too, but ignored it .

    well cought and well said.

  6. why... on The Riches of Open Source · · Score: 2, Interesting
    why do i suddenly have some new found respect for these business world people ?

    Finally someone ther has enough sense and not just a MBA degree.

    Seriously if common sense would prevail in IT industry over marketing hype and FUD, ...Oh the possibilities.

  7. Re:Blind man with a bat on SCO Hints at *BSD Lawsuits Next Year, And More · · Score: 1

    Funny, I always thought of him as the french guard, who fart's in everbody's general direction.

  8. Watched star wars, you say ... on Whistle While You Work · · Score: 1
    Have you ever watched Star Wars ?

    -1 Redundunt , shall we say

  9. Re:Darl Named a top 25 CEO on SCO News Roundup · · Score: 1
    I mean come on, granted that this guy Darl is a major league a-hole,but he is doing a great job as far as a CEO is concerned.

    After all if you are a CEO, all you need to do is create enough confidence in stock investors, and he is doing that for sometime.

    Now when the $|-,1+ hits the fan, then its going to be a totally different story, but by then he would have sold all his stocks, retired on a a fat bonus and earning 10% on his savings, and crusing in bahamas.

    Not bad if you ask me.

  10. Re:Are you channeling a troll, sir? on Gateway Forges Partnership With SuSE · · Score: 1
    You don't need to recompile the kernel to watch DivX movies. You just need a new version of mplayer.

    Dude, Have you ever tried getting help from mplayer authors ? All you get is RTFA, even if you have read TFA and not able to find what you want. The help , faq, codec infos all are so apthetically written, they would fail both the english class and technical writing class too.

    Don't get me wrong , mplayer is one true amazing product, but compiling it, installing it with win32 dlls, realplayer dlls, quicktime support is a royal PITA.

    As compared to that recompiling the kernel is much much easier, all one needs is a basic understanding of PC architecture, and read all the help about each option. I know it can be very timeconsuming to read all that help, but afeter you have read it and follow the instructions step-by-step , you can't go too wrong.

    I don't mean to troll, but I am speaking from personal experience.

    As to grandma question, i think recompiling kernel and installing mplayer both are out of question.

  11. Re:This should shut everyone up on Microsoft Word Document ML Schemas Published · · Score: 1

    And if not , then this will definitely shut them up.

  12. How about..... on 3 New Defendants Named In MP3s4free.net Case · · Score: 3, Funny

    How about suing the dog of the kid that live's next door to the ISP's employee's mother-in-law's sister's step-son's friend ?
    I am sure he is also connected in some way or OTHER to this, no ?

  13. Re:enough on Gore Vidal Savages Electronic Voting · · Score: 1
    Newsflash :- It's not the same Gore, this guy is Gore Vidal, a political and social critique, the guy who lost was "Al gore", (The inventor of internet, oatleast as per dublya).

    Btw, thanks for almost killing me, boromir.

  14. Re:Corruption? on Gore Vidal Savages Electronic Voting · · Score: 1

    Yes, but there is a very tracable trail of that corruption, just look up all his former posts.

  15. Re:Check this out MPAA on Jail Time for Movie Swappers · · Score: 1

    Just tell him, you had $3x with his wife.

  16. Please Please Please stop it... on SCO Fires back, Subpoenas Stallman, Torvalds et al · · Score: 2, Funny
    The only thing now left for me to see, is "Darl, linux, Stallman et all" on the front cover of Soap Opera Digest.

    This drama is giving all those soaps a serious run for their money.

  17. What the F@#$ are they talking about ? on Microsoft Proclaims Death of Free Software Model · · Score: 3, Insightful
    Death of Free software ?

    Pure high quality top management PR bull$hit. I don't see free software dying anytime soon, as long as debain, gentoo, slackware, LFS are around.

    And if Microsoft's business model is indeed true and going by their word, that s/w amounts to only a fraction of total cost, then whether linux is free or not, really doesn't matter does it ?

    So going by microsoft's argument, it really doesn't matter costwise (only software) whether you are using linux or Windows. But by using linux you get a much stable, scalable, SECURE, reliable , easily configurable, accountable s/w, instead of propritory, unsecure, un-scalable, s/w.

  18. Re:This isn't surprising... on Gangs Extort Companies With DDoS Attacks · · Score: 1
    In this case, though, if the DDOSers are, as suspected nothing but a bunch of nerds, then Women will top all priorities.

    Don't belive me ? ask anyone here on /.

  19. Think before you post.... on SpaceDev Auctioning Microsatellite Mission On Ebay · · Score: 1
    I don't think anyone would have a problem shipping a satellite to iraq or afghanisthan, after all where would they launch it from and using what fuel?

    Its not like iraq has billions of $$ worth of fuel, oh wait, ..nevermind.

  20. Re:Another 'comissioned' report... on Security FUD On Linux · · Score: 3, Funny

    Truth (Marketing definition) :- A blatant lie, told with utmost confidence, and backup up by forged yet sensational statistics and meaningless pie-charts, and bar graphs.

  21. Re:Do Musicians care about Linux? on Linux-Based Musical Keyboard Workstation Debuts · · Score: 1
    Well these guys definitely do.

    they even encoded it in ogg.

  22. Re:How long on Linux-Based Musical Keyboard Workstation Debuts · · Score: 1

    gee, but for the explaination in the brackets, i would have never got it. thanks so much

  23. Re:I don;t know about 9 on The Ten Most Overpaid Jobs In The U.S. · · Score: 1

    But then african elks don't run...

  24. Re:Question on O'Reilly On What Happened To BountyQuest · · Score: 1

    What happens, if you return the product for any reason, and the company wants to recredit you the money.
    Can they recredit the money to your actual CC number using your disposable CC number ?

  25. Re:Question on O'Reilly On What Happened To BountyQuest · · Score: 4, Informative
    Seriously,

    When I buy of the web, I want to cross verify my order, address, CC details etc., atleast once before I hit the final submit button. Especially with the shady practice of Amazon and the others to add, unwanted gift wrappings even if i didn't order one explictly, or to default to next-day air shipping (more $s) , even if I want free 5-7 days ground shipping.

    I want to make sure, They charge my CC, nothing more, if not any less. :-)