pen-test
[Top] [All Lists]

Re: Boot floppy

To: Pen-Testing <pen-test@securityfocus.com>
Subject: Re: Boot floppy
From: "Shreyas Zare" <shreyas@technitium.com>
Date: Wed, 11 Apr 2007 11:18:21 +0530
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <a40a81bbdf22981ceda4eda9f6055765@stangercorp.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <a40a81bbdf22981ceda4eda9f6055765@stangercorp.com>
Resent-date: Wed, 11 Apr 2007 00:07:07 -0600 (MDT)
Resent-from: pen-test-return-1078483901@securityfocus.com
Resent-message-id: <20070411060707.0CA7814F741@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hi,

Try using social engineering. Tell him you are given a job to patch
all machines in the company for some security update then patch his
machine with a good rootkit. You may give him the update (infected) in
any CD or USB media so that he would install it himself. Or use any
idea which will not look suspicious to the target.

Regards,

On 4/10/07, Mifa <mifa@stangercorp.com> wrote:
We have a user who takes a company  computer home with them (no its not a lap 
top).  We have a good reason to need to look at their files.  However, we want 
to do so without that employ knowing.  They seem to know something about 
security becasue auto runs is disabled and the workstation is always locked 
with a third party software.  INserting a U3 drive will not run a program 
either.  Are there any programs that will boot from a floppy then copy a 
program to the c drive then wite an auto start entry into the registry?  This 
was the only way I can think of to get the user to install a program..

Any other ideas how we maight gain access?  It has to be fast (bathroom breaks 
ect).  I dont have time to load a live cd. Further, robooting would cause the 
user to loose work.



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------





--
(This e-mail was composed and sent completely using recycled electrons)

Shreyas Zare
Co-Founder, Technitium
eMail: shreyas@technitium.com

..::< The Technitium Team >::..
Visit us at www.technitium.com
Contact us at theteam@technitium.com

Technitium Personal Computers
We belive in quality.
Visit http://pc.technitium.com for details.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>