pen-test
[Top] [All Lists]

Re: Boot floppy

To: pen-test@securityfocus.com
Subject: Re: Boot floppy
From: Michael Munt <michael.munt@nhs.net>
Date: Fri, 13 Apr 2007 10:18:01 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <58c12813e5cd4e1c8c25f554d7509016@stangercorp.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <58c12813e5cd4e1c8c25f554d7509016@stangercorp.com>
Resent-date: Fri, 13 Apr 2007 17:55:26 -0600 (MDT)
Resent-from: pen-test-return-1078483938@securityfocus.com
Resent-message-id: <20070413235526.B7FF42374FF@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.10 (Windows/20070221)
Mifa,

if the machine is not on the domain, how is it using the resources of the domain. Surely you can block the machine from connecting to your resources, this will then allow you to gain access to the machine with a "legitimate" reason to find out whats wrong.

hth
michael



Mifa wrote:
Thanks for the info.  Backups are not done on a machine thats off our network.  
I can not access my admin privilages becasue the machine is not on a domain and 
is not simply locked with windows. Further , the admin account is 
disabled/missing; to be honest Im not shure how.  I had hoped to do a quick 
reboot from a floppy because its fast.

 We suspect that we  have someone who is sending company job files to another 
company. If so this would make the second person doing such.  One of our 
employes left this company to start another company and he had friends.   We 
dare not point out any one without proof or fire anyone without knowing we the 
correct person; especially when this person has been with the company most of 
its existance.  To get that proof I think the hardware key logger would be a 
good option to get the password ect then log in, but not any good for the 
longer term.   Also, we are keeping a copy of all emails.  The other option is 
to disclose our suspecions and have him turn in the computer the next time he 
comes into the office; which we will do if we must.  Being a small company 
based on trust its the last option short of fireing wich the owner will not do 
without proof.  Now you see the sensitive delima here.  We do have every right 
and policy, but....


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



**********************************************************************
This message  may  contain  confidential  and  privileged information.
If you are not  the intended  recipient please  accept our  apologies.
Please do not disclose, copy or distribute  information in this e-mail
or take any  action in reliance on its  contents: to do so is strictly
prohibited and may be unlawful. Please inform us that this message has
gone  astray  before  deleting it.  Thank  you for  your co-operation.

NHSmail is used daily by over 100,000 staff in the NHS. Over a million
messages  are sent every day by the system.  To find  out why more and
more NHS personnel are  switching to  this NHS  Connecting  for Health
system please visit www.connectingforhealth.nhs.uk/nhsmail
**********************************************************************


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>