human factors Questions


Passwords
Hi all, What do you recommend for initial password issue, that is, provided a new user with a password for the first time without compromising it. I find the entire help desk giving password initially or sysadmins doing that is not save enough even though the user will be prompted to change it at first [...]

Answer Question   |  November 24, 2007  8:11 AM
Access control, Application security, backdoors, Biometrics, Browsers, Business/IT alignment, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, Exchange security, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

Laptop Security…
Hi, I am the head of my department and by the nature of the job I hold some confidential information on my laptop. How do I ensure that 1. Nobody can access any files on my laptop from the LAN or the internet (not even sys admins) 2. If somebody tries to access, can I [...]

Answer Question   |  June 27, 2006  9:31 AM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, DataCenter, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

strange processes showing up in the task list some random numbers.TMP
I suspect I have some trojan downloader? I keep finding strange processes showing up in the task list. These are some random numbers and letters with a .TMP extension? They cause my internet connection to either run very slow or in most cases it stops the connection to the internet. When I kill the .TMP [...]

Answer Question   |  June 17, 2006  10:28 PM
Access control, backdoors, Browsers, Current threats, filtering, Hacking, human factors, Interoperability, Servers, Software, Spyware, SSL/TLS, Tech support, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Local LAN Vulnerabilities and Open Ports NAT
QUESTION: How someone would go about exploiting a vulnerability within a LAN sitting behind a router running NAT/NAPT…where would you start? Hacking the open port? Routing Tables? Accessing remote administration on the modem? (disable NAT)?? bah… MY SYSTEM/SETUP: I have 1 XP SP2 Machine running providing PPTP VPN connections and a Webcam Security System (webcamxp) [...]

Answer Question   |  May 26, 2006  7:43 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Network Resource Allocation cum Planning cum Technical Problem
This is the real commercial problem face by my company. Well, the reason I ask this problem is I salute and respect all of you as I believe all of you are as good as network solution company out there, or even better!! Lets me rephrase the entire problem again. Company expand so fast that [...]

Answer Question   |  May 22, 2006  10:17 AM
3Com, Access, Access control, Active Directory, Altiris, Application security, Availability, Avaya, backdoors, Bandwidth, Benchmarking, Bind, Biometrics, BMC, Browsers, Budgeting, Business/IT alignment, Cabling, Career development, Cisco, Compliance, Computer Associates, configuration, CRM, Current threats, Database, DataCenter, DB2, Dell, Desktop management applications, Desktops, DHCP, Digital certificates, Disaster Recovery, DNS, E-business, Encryption, Enterasys, Enterprise Desktop, Ethernet, Exchange, Fault isolation, FDDI, filtering, Firewalls, Forensics, Foundry, Frame Relay, General Directories, H.323, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, IBM, IBM/Tivoli, Identity & Access Management, Incident response, Instant Messaging, Intel, Interoperability, InterSystems, Intrusion management, IPv4, IPv6, Juniper Networks, LANDesk, Laws, LDAP, Linux, Lotus Domino, Lucent, Management, Marimba, Microsoft Office, Microsoft Operations Manager, Microsoft Systems Management Server, Microsoft Windows, MPLS, MySQL, NetBIOS, Network applications management, Network management software, Network monitoring, Network protocols, Network security, Network testing, Networking, Networking services, NFS, Nortel, Novell, Novell IPX/SPX, Novell NDS, Online transaction processing, Oracle, OS, Partner facing, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Project management, Protocol analysis, provisioning, Regulations, Remote management, Risk management, ROI & cost justification, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, SIP, Software, Spyware, SQL, SQL Server, SSL/TLS, standards, Storage, Switches, Sybase, Systems management software, TCP, Tech support, Trojans, Unisys, Vector Networks, Vendors, Viruses, VPN, vulnerability management, Web security, WINS, Wireless, worms
asked by:
5 pts.

Design NEW network cum NEW IT infrastructure-2
Company expand so fast that the IT infrastructure is not fast enough to cater high volume of traffic; the initial design is not scalable. The number of new branch offices setup caused the company pay a high price in the leased line communication. Salesman and management staffs dial into company networks via 56K modem to [...]

Answer Question   |  May 17, 2006  8:21 AM
3Com, Access control, Application security, Availability, Avaya, backdoors, Bandwidth, Benchmarking, Biometrics, Browsers, Budgeting, Business/IT alignment, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, Dell, DHCP, Digital certificates, Disaster Recovery, DNS, Encryption, Enterasys, Exchange, Fault isolation, filtering, Firewalls, Forensics, Foundry, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, Identity & Access Management, Incident response, Instant Messaging, Interoperability, Intrusion management, Juniper Networks, Lucent, Network applications management, Network management software, Network monitoring, Network security, Network testing, Networking, Networking services, Nortel, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Protocol analysis, provisioning, Remote management, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Software, Spyware, SSL/TLS, Switches, TCP, Tech support, Trojans, Vendors, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
5 pts.

Design NEW network cum NEW IT infrastructure
Company expand so fast that the IT infrastructure is not fast enough to cater high volume of traffic; the initial design is not scalable. The number of new branch offices setup caused the company pay a high price in the leased line communication. Salesman and management staffs dial into company networks via 56K modem to [...]

Answer Question   |  May 17, 2006  7:54 AM
Access control, Application security, Availability, backdoors, Bandwidth, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
5 pts.

What is SSI injection
I recently read an article that mentioned SSI injection. I’m aware of SQL injection, but not SSI. Can anyone explain what it is and what should be done to protect against it? Thanks

Answer Question   |  May 5, 2006  3:31 PM
Access control, Application security, backdoors, Browsers, Current threats, Database, Development, Encryption, Exchange, filtering, Hacking, human factors, Instant Messaging, Secure Coding, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Cross-site scripting attacks
I’m looking for advice on cross-site scripting. What can these attacks do and what can I do to protect Web sites/applications against them? Are there any resources you recommend? Thanks

Answer Question   |  November 13, 2009  2:54 PM
Access control, backdoors, Browsers, Current threats, Development, filtering, Hacking, human factors, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

route mail with fax service in sbs 2003
i have a sbs 2003 on my network and i configure him to get all the fax of my company, the only problem is that when i configure him to route all the incoming fax to some mail it does not seem to work, i check the event log and i get error 32083 and [...]

Answer Question   |  April 27, 2006  3:30 PM
Access, Access control, AIM, Application security, Availability, backdoors, Backup & recovery, Bandwidth, Biometrics, Brightmail, Browsers, Budgeting, Business/IT alignment, Career development, CipherTrust, ClearSwift, CLP, Compliance, configuration, CRM, Current threats, Data analysis, Database, DataCenter, Desktops, Digital certificates, Disaster Recovery, Encryption, Ethernet, Exchange, Exchange security, FDDI, filtering, Firewalls, Forensics, Frame Relay, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Laws, Management, McAfee, MessageLabs, Microsoft Office, Microsoft Windows, Network protocols, Network security, Networking, OS, Outsourcing, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Postini, Project management, provisioning, Regulations, Risk management, Rockliffe, ROI & cost justification, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spam, SpamAssassin, Spyware, SQL Server, SSL/TLS, standards, Storage, Symantec, TrendMicro, Trojans, Vendors, Viruses, VPN, vulnerability management, Web development, Web security, Web services, Web Services Standards, Wireless, worms
asked by:
5 pts.

asked by:
0 pts.

Connection Management
Hello, I am working on a project that we have a deployed a Personal Firewall product on laptop users. The Personal Firewall allows us to define a server based access profile or FW rules for each type of connection and IP range. ie. Ethernet, WLAN etc. The issue is this personal FW activates BOTH connection [...]

Answer Question   |  March 27, 2006  4:14 AM
Access control, backdoors, Browsers, Compliance, CRM, Current threats, Desktop management applications, Disaster Recovery, filtering, Hacking, human factors, Mobile, Network applications management, Network management software, Policies, Risk management, Security, Security Program Management, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Folder Security
We have a folder containing lots of confidential docs that supposedly accessible to all employees that should have read permission only. They should not be able to Print/Copy/SaveAs/E-Mail and do other docs stuff. Our IT staff had made the folder read only though people could still re-save the files elsewhere and print from there … [...]

Answer Question   |  March 23, 2006  6:54 PM
Application security, backdoors, Current threats, Database, Desktops, Encryption, Exchange, Hacking, human factors, Instant Messaging, Management, Microsoft Windows, Networking, OS, Secure Coding, Security, Servers, Spyware, SQL Server, Trojans, Viruses, worms
asked by:
0 pts.

Explanation & remedy for Web-based Attack
Fully Patched fresh Windows 2003 with PLESK 7.5.6 Compromised again in 30 minutes after a CLEAN rebuild here is How attack occurs ========================== first we observe service.dll Nadeware.msi in system32 folder and a clone of srv-u FTP had run. then we observe an account named help added to administrators group ! we also found C:Program [...]

Answer Question   |  March 16, 2006  12:28 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

Penetration Testing Career
Hi Friends I want an advice from you guys. I have work exp in Web Developement and Quality Assurance. But my interest lies in security and penetration testing. Could you guys guide me where to start from. If there is any good material which can help me doing the same or some site where I [...]

Answer Question   |  March 20, 2006  3:58 AM
backdoors, Compliance, CRM, Current threats, Disaster Recovery, Firewalls, Forensics, Hacking, human factors, Incident response, Intrusion management, Network security, Policies, Risk management, Security, Security Program Management, Spyware, Trojans, Viruses, VPN, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

Fixing violation errors found with CHKOBJITG
I have just begun running the command to check object itegrity on my system. I have encountered 2 basic errors – BADSIG & ALTERED. Can you please explain how I now correct these errors? The objects are basic IBM supplied code (i.e. ADDTCPLNK in QTCP library). I have no idea how these objects were compromised, [...]

Answer Question   |  February 15, 2006  7:19 AM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.