Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd |
|---|---|
| Date: | Mon, 23 Apr 2007 14:08:09 -0400 |
You guys know Ross left eEye weeks ago... http://blogs.zdnet.com/security/?p=148 -----Original Message----- From: full-disclosure-bounces@lists.grok.org.uk [mailto:full-disclosure-bounces@lists.grok.org.uk] On Behalf Of Paul Schmehl Sent: Monday, April 23, 2007 12:23 PM To: full-disclosure Subject: Re: [Full-disclosure] Apparently eEye's blog got p0wnd --On Monday, April 23, 2007 05:00:49 -0400 Valdis.Kletnieks@vt.edu wrote:
On Sun, 22 Apr 2007 11:46:41 CDT, Paul Schmehl said:--On April 22, 2007 10:45:17 AM +0200 poo <skodliv@gmail.com> wrote:or maybe ross retard got his login info ownedWhy take the whole site down then? All you'd have to do is disable
his
account.Umm? Maybe for some real *basic* security reason? For instance, doing forensics or making *sure* that Ross was the only pwnage, and that it wasn't anything more serious? So tell me Paul - if *your* password got pwned, would you take the
machine
down, or not? :)
If *mine* got pwned, I'd take the machine down, but if an unprivileged user got pwned, I'd simply have them change their password, *unless* there was evidence of problems on that host. Just because someone's account got hijacked doesn't mean that further damage necessarily happened. Lots of people have no access to anything except their own stuff. Paul Schmehl (pauls@utdallas.edu) Senior Information Security Analyst The University of Texas at Dallas http://www.utdallas.edu/ir/security/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd, Paul Schmehl |
|---|---|
| Next by Date: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd, Paul Schmehl |
| Previous by Thread: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd, Paul Schmehl |
| Next by Thread: | Re: [Full-disclosure] Apparently eEye's blog got p0wnd, Paul Schmehl |
| Indexes: | [Date] [Thread] [Top] [All Lists] |