Penetration Testing
A L0phCrack Alternative Dec 07 2010 07:42PM
olufemimogaji gmail com (4 replies)
Re: A L0phCrack Alternative Dec 08 2010 02:44PM
Syed Khaden (syed secure-bytes com)
Re: A L0phCrack Alternative Dec 08 2010 12:19PM
Paul Halliday (paul halliday gmail com) (1 replies)
Re: A L0phCrack Alternative Dec 10 2010 09:30AM
Saif El Sherei (SSherei npcegypt com)
Re: A L0phCrack Alternative Dec 08 2010 09:11AM
Alla Bezroutchko (alla gremwell com)
RE: A L0phCrack Alternative Dec 08 2010 01:26AM
Tom Steele (Tom Steele motricity com) (3 replies)
services.exe modifying synattackprotect? Dec 09 2010 05:23PM
techlists comcast net (2 replies)
RE: services.exe modifying synattackprotect? Dec 10 2010 05:03PM
Style War (stylewar hotmail com)
Re: services.exe modifying synattackprotect? Dec 10 2010 08:36AM
Christophe Vandeplas (christophe vandeplas com)
On Thu, Dec 9, 2010 at 6:23 PM, <techlists (at) comcast (dot) net [email concealed]> wrote:
> Why would 'C:\Windows\system32\services.exe' be trying to change the following registry key?
>
> \REGISTRY\MACHINE\SYSTEM\ControlSet\SERVICES\TCPIP\PARAMETERS\SYNATTACKP
ROTECT
>
> Is this an indication of an attack or a normal part of the 'services.exe' process?

Hi PG,

You should read this paper [1] to understand what the synattackprotect
parameter does.
The big question is more: To what is the parameter changed?

If it was changed to 0, so deactivating synattack protection, I would
seriously ask myself questions.
But if it was changed to 1, enabling another protection... then I'd
check with my sysadmin if some Active Directory group policies were
changed (manually or because of the installation of a patch)

[1] http://technet.microsoft.com/en-us/library/cc938202.aspx

------------------------------------------------------------------------

This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------

[ reply ]
RE: A L0phCrack Alternative Dec 08 2010 03:13PM
Paul Griggs (Paul Griggs cadre net) (1 replies)
RE: A L0phCrack Alternative Dec 10 2010 11:37AM
Demetris Papapetrou (dpapapetrou internalaudit gov cy)
Re: A L0phCrack Alternative Dec 08 2010 02:32AM
Augusto Pereyra (aepereyra gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus