Web security Questions


strange processes showing up in the task list some random numbers.TMP
I suspect I have some trojan downloader? I keep finding strange processes showing up in the task list. These are some random numbers and letters with a .TMP extension? They cause my internet connection to either run very slow or in most cases it stops the connection to the internet. When I kill the .TMP [...]

Answer Question   |  June 17, 2006  10:28 PM
Access control, backdoors, Browsers, Current threats, filtering, Hacking, human factors, Interoperability, Servers, Software, Spyware, SSL/TLS, Tech support, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Local LAN Vulnerabilities and Open Ports NAT
QUESTION: How someone would go about exploiting a vulnerability within a LAN sitting behind a router running NAT/NAPT…where would you start? Hacking the open port? Routing Tables? Accessing remote administration on the modem? (disable NAT)?? bah… MY SYSTEM/SETUP: I have 1 XP SP2 Machine running providing PPTP VPN connections and a Webcam Security System (webcamxp) [...]

Answer Question   |  May 26, 2006  7:43 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Network Resource Allocation cum Planning cum Technical Problem
This is the real commercial problem face by my company. Well, the reason I ask this problem is I salute and respect all of you as I believe all of you are as good as network solution company out there, or even better!! Lets me rephrase the entire problem again. Company expand so fast that [...]

Answer Question   |  May 22, 2006  10:17 AM
3Com, Access, Access control, Active Directory, Altiris, Application security, Availability, Avaya, backdoors, Bandwidth, Benchmarking, Bind, Biometrics, BMC, Browsers, Budgeting, Business/IT alignment, Cabling, Career development, Cisco, Compliance, Computer Associates, configuration, CRM, Current threats, Database, DataCenter, DB2, Dell, Desktop management applications, Desktops, DHCP, Digital certificates, Disaster Recovery, DNS, E-business, Encryption, Enterasys, Enterprise Desktop, Ethernet, Exchange, Fault isolation, FDDI, filtering, Firewalls, Forensics, Foundry, Frame Relay, General Directories, H.323, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, IBM, IBM/Tivoli, Identity & Access Management, Incident response, Instant Messaging, Intel, Interoperability, InterSystems, Intrusion management, IPv4, IPv6, Juniper Networks, LANDesk, Laws, LDAP, Linux, Lotus Domino, Lucent, Management, Marimba, Microsoft Office, Microsoft Operations Manager, Microsoft Systems Management Server, Microsoft Windows, MPLS, MySQL, NetBIOS, Network applications management, Network management software, Network monitoring, Network protocols, Network security, Network testing, Networking, Networking services, NFS, Nortel, Novell, Novell IPX/SPX, Novell NDS, Online transaction processing, Oracle, OS, Partner facing, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Project management, Protocol analysis, provisioning, Regulations, Remote management, Risk management, ROI & cost justification, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, SIP, Software, Spyware, SQL, SQL Server, SSL/TLS, standards, Storage, Switches, Sybase, Systems management software, TCP, Tech support, Trojans, Unisys, Vector Networks, Vendors, Viruses, VPN, vulnerability management, Web security, WINS, Wireless, worms
asked by:
5 pts.

Design NEW network cum NEW IT infrastructure-2
Company expand so fast that the IT infrastructure is not fast enough to cater high volume of traffic; the initial design is not scalable. The number of new branch offices setup caused the company pay a high price in the leased line communication. Salesman and management staffs dial into company networks via 56K modem to [...]

Answer Question   |  May 17, 2006  8:21 AM
3Com, Access control, Application security, Availability, Avaya, backdoors, Bandwidth, Benchmarking, Biometrics, Browsers, Budgeting, Business/IT alignment, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, Dell, DHCP, Digital certificates, Disaster Recovery, DNS, Encryption, Enterasys, Exchange, Fault isolation, filtering, Firewalls, Forensics, Foundry, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, Identity & Access Management, Incident response, Instant Messaging, Interoperability, Intrusion management, Juniper Networks, Lucent, Network applications management, Network management software, Network monitoring, Network security, Network testing, Networking, Networking services, Nortel, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Protocol analysis, provisioning, Remote management, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Software, Spyware, SSL/TLS, Switches, TCP, Tech support, Trojans, Vendors, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
5 pts.

Design NEW network cum NEW IT infrastructure
Company expand so fast that the IT infrastructure is not fast enough to cater high volume of traffic; the initial design is not scalable. The number of new branch offices setup caused the company pay a high price in the leased line communication. Salesman and management staffs dial into company networks via 56K modem to [...]

Answer Question   |  May 17, 2006  7:54 AM
Access control, Application security, Availability, backdoors, Bandwidth, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
5 pts.

LAN vulnerability behind a Router – with firewall – connected to the Internet (Through an Open Port!)
Hi, I would just like some reassurance: I have a Router on my LAN that connects all host PCs to each other and the Internet. Question: a) How exposed is my LAN behind the Router that has a port open for Internet access (and in future anther for remote desktop terminal connection) would a port [...]

Answer Question   |  May 12, 2006  7:30 AM
Access control, Browsers, Cabling, filtering, Firewalls, Forensics, Hardware, Hubs, Incident response, Intrusion management, Network security, Networking, Remote management, Routers, Security, Servers, SSL/TLS, Switches, VPN, Web security, Wireless
asked by:
0 pts.

LAN vulnerability behind a Router – with firewall – connected to the Ineternet (Through an Open Port!)
Hi, I would just like some reassurance: I have a Router on my LAN that connects all host PCs to each other and the internet. Qu: How exposed is my LAN behaind the Router that has a port open for internet access (and in future anther for remote desktop terminal connection) would a port scanner [...]

Answer Question   |  May 24, 2006  7:28 AM
Access control, Browsers, Cabling, filtering, Firewalls, Forensics, Hardware, Hubs, Incident response, Intrusion management, Network security, Networking, Remote management, Routers, Security, Servers, SSL/TLS, Switches, VPN, Web security, Wireless
asked by:
0 pts.

What is SSI injection
I recently read an article that mentioned SSI injection. I’m aware of SQL injection, but not SSI. Can anyone explain what it is and what should be done to protect against it? Thanks

Answer Question   |  May 5, 2006  3:31 PM
Access control, Application security, backdoors, Browsers, Current threats, Database, Development, Encryption, Exchange, filtering, Hacking, human factors, Instant Messaging, Secure Coding, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Cross-site scripting attacks
I’m looking for advice on cross-site scripting. What can these attacks do and what can I do to protect Web sites/applications against them? Are there any resources you recommend? Thanks

Answer Question   |  November 13, 2009  2:54 PM
Access control, backdoors, Browsers, Current threats, Development, filtering, Hacking, human factors, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

route mail with fax service in sbs 2003
i have a sbs 2003 on my network and i configure him to get all the fax of my company, the only problem is that when i configure him to route all the incoming fax to some mail it does not seem to work, i check the event log and i get error 32083 and [...]

Answer Question   |  April 27, 2006  3:30 PM
Access, Access control, AIM, Application security, Availability, backdoors, Backup & recovery, Bandwidth, Biometrics, Brightmail, Browsers, Budgeting, Business/IT alignment, Career development, CipherTrust, ClearSwift, CLP, Compliance, configuration, CRM, Current threats, Data analysis, Database, DataCenter, Desktops, Digital certificates, Disaster Recovery, Encryption, Ethernet, Exchange, Exchange security, FDDI, filtering, Firewalls, Forensics, Frame Relay, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Laws, Management, McAfee, MessageLabs, Microsoft Office, Microsoft Windows, Network protocols, Network security, Networking, OS, Outsourcing, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Postini, Project management, provisioning, Regulations, Risk management, Rockliffe, ROI & cost justification, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spam, SpamAssassin, Spyware, SQL Server, SSL/TLS, standards, Storage, Symantec, TrendMicro, Trojans, Vendors, Viruses, VPN, vulnerability management, Web development, Web security, Web services, Web Services Standards, Wireless, worms
asked by:
5 pts.

look fax in OWA
i have a sbs 2003 and it connect to modem to get fax, and iv’e configured him to get users to outlook web access but i want to know if there is a way to see fax on the server from the owa? is there a way that user log on to owa and then [...]

Answer Question   |  April 18, 2006  6:04 PM
Access control, Brightmail, Browsers, CipherTrust, Exchange, Exchange security, filtering, Security, Servers, Spam, SSL/TLS, Web security, Web services, Web site design & management
asked by:
5 pts.

asked by:
0 pts.

Connection Management
Hello, I am working on a project that we have a deployed a Personal Firewall product on laptop users. The Personal Firewall allows us to define a server based access profile or FW rules for each type of connection and IP range. ie. Ethernet, WLAN etc. The issue is this personal FW activates BOTH connection [...]

Answer Question   |  March 27, 2006  4:14 AM
Access control, backdoors, Browsers, Compliance, CRM, Current threats, Desktop management applications, Disaster Recovery, filtering, Hacking, human factors, Mobile, Network applications management, Network management software, Policies, Risk management, Security, Security Program Management, Servers, Spyware, SSL/TLS, Trojans, Viruses, Web security, worms
asked by:
0 pts.

Blocking pop access over http
Dear you, How can I exactly block the following: 1- Hotmail pop access over http 2- Block skype phone calls 3- Block sites like gotomypc.com etc 4- Block internet file share drives like yousendit.com google drive Thank you Kindi

Answer Question   |  March 22, 2006  12:37 AM
Access control, Application security, Browsers, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Incident response, Instant Messaging, Intrusion management, Network security, Secure Coding, Servers, SSL/TLS, VPN, Web security, Wireless
asked by:
0 pts.

Dynamic Local User in W2K clients
Hello. Does anyone have an idea on how to configure a Wondows 2000 client to show the SID of any user that logs in to that computer. We run a Novell Netware 6.5 network, and have about 60 W2K clients. I have a generic local account for the W2K stations. When a user logs in, [...]

Answer Question   |  March 10, 2006  11:46 AM
Access control, Biometrics, Browsers, DataCenter, Digital certificates, filtering, Identity & Access Management, Microsoft Windows, Networking, provisioning, Security tokens, Servers, Single sign-on, SSL/TLS, Web security
asked by:
0 pts.

Explanation & remedy for Web-based Attack
Fully Patched fresh Windows 2003 with PLESK 7.5.6 Compromised again in 30 minutes after a CLEAN rebuild here is How attack occurs ========================== first we observe service.dll Nadeware.msi in system32 folder and a clone of srv-u FTP had run. then we observe an account named help added to administrators group ! we also found C:Program [...]

Answer Question   |  March 16, 2006  12:28 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

Allowing IE to Install Selected Software
When restricting users to non-Power Users settings, how do we allow a Web Browser Front End to an application to download and install: a) Active X-Controls b) Files c) Registry Keys. I assume that there are settings we can make via GPO?

Answer Question   |  February 24, 2006  12:52 AM
Access control, Application security, Browsers, Database, Development, Encryption, Exchange, filtering, Instant Messaging, Secure Coding, Security, Servers, SSL/TLS, Web security
asked by:
0 pts.

Terminal server installed on a WIndows 2000 DC – GPO question
I have a Windows 2000 Domain controller with Terminal Server installed on it. I understand that running TS on a DC is not recommended, but I have to use what I have available. My question is how do I lockdown a user with a GPO when they log on remotely and not when they log [...]

Answer Question   |  February 14, 2006  2:43 PM
Access control, Browsers, DataCenter, filtering, Networking, Servers, SSL/TLS, Web security
asked by:
0 pts.