Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Let's check out cocc.com |
|---|---|
| Date: | Sat, 31 Dec 2005 13:14:02 +1300 |
Technica Forensis wrote: [corrected for top-posting-itis] <<snip>>
---------- Forwarded message ---------- Date: Fri, 30 Dec 2005 04:20:28 -0500 From: "Preston, Ian" <Ian.Preston@cocc.com> To: Dave Horsfall <dave@horsfall.org> Subject: Out of Office AutoReply: [Full-disclosure] complaints about the g overnemnt spying! I will be out of the office until Tuesday, January 4th. If you need immediate assistance, please address your message to internetplus@cocc.com. You can also dial x625 to reach the Internet Plus hunt group. If you need to contact me directly, my cell phone # is 203 525 5770
<<snip>>
should we all call his cell phone?
To really make the point, we should each do it at a pre-arranged _local_ time -- like, say mid-night New Year's Eve/New Years Day... Another thing to do with such cases (if you're really bored and have the time) is to report them to the security contact at the originating domain. In this case you may just choose the internetplus@ address mentioned in the actual message, but for the obsessively verbose ones -- you know, the ones like: I'm at a conference until ... For database queries contact Tom ... For backup issues contact Dick ... For other support issues contact Mary ... reporting them to the company's security contact is both a good thing (the twat clearly is giving up way too much internel-only info they should have policies against, so warning them is a genuinely good thing), and a better thing (their security contact will likely have the mail admin kill/fix such auto-responses so we see no more from them in the list) and a really evil thing (the staff member will return from conference to a meeting with security and possibly even get slapped with a security policy infringement note on their HR record). Regards, Nick FitzGerald _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Fwd: [Full-disclosure][WAY OFF TOPIC] complaints about the government spying!, J.A. Terranson |
|---|---|
| Next by Date: | [Full-disclosure] Replay Attack Vulnerability on Sonys Instant Video Everywhere Service, Nils Ohlmeier |
| Previous by Thread: | Re: [Full-disclosure] Let's check out cocc.com, InfoSecBOFH |
| Next by Thread: | [Full-disclosure] Good proxy chaining applications, pagvac |
| Indexes: | [Date] [Thread] [Top] [All Lists] |