pen-test
[Top] [All Lists]

Re: Boot floppy

To: Zed Qyves <zqyves.spamtrap@gmail.com>
Subject: Re: Boot floppy
From: Tim <tim-pentest@sentinelchicken.org>
Date: Wed, 11 Apr 2007 08:00:39 -0400
Cc: Mifa <mifa@stangercorp.com>, pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <f26bc1930704102341q3b122660h8ed10d04e8819835@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <a40a81bbdf22981ceda4eda9f6055765@stangercorp.com> <f26bc1930704102341q3b122660h8ed10d04e8819835@mail.gmail.com>
Resent-date: Wed, 11 Apr 2007 11:31:46 -0600 (MDT)
Resent-from: pen-test-return-1078483913@securityfocus.com
Resent-message-id: <20070411173146.B79FE145264@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Mutt/1.5.13 (2006-08-11)
> Why do you think you have to go to such extremes if it is a company PC?
> 
> If he is TAKING the PC home instead of HAVING HIS PC at home all the
> time next time the PC is at company - and you re authorised to perform
> such a thing - take it apart...
> 
> If on the other hand you want to spy on that user and see what he is
> doing with his files I suggest checking with the company's legal
> department before doing anything else.
> 
> and finally sounds like a job for psexec...

I agree with these points.  Mifa, this question is probably best for the
forensics list.  The folks there are pretty experienced with this kind
of situation.  There are lots of legal issues you could find yourself in
hot water with, and you're better off asking investigators when doing an
investigation, not pentesters. (No offense intended to pentesters of
course.)

tim

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>