Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Report: DHS cyber security lagging
Kevin Poulsen, SecurityFocus 2004-12-16

The U.S. Department of Homeland Security is having some homeland cyber security issues on its systems providing remote access to telecommuters, according to a newly-released report by the DHS Inspector General's office.

Comments Mode:
Report: DHS cyber security lagging 2004-12-17
Anonymous (3 replies)
Report: DHS cyber security lagging 2004-12-20
Anonymous (1 replies)
Report: DHS cyber security lagging 2004-12-20
Anonymous (1 replies)
Report: DHS cyber security lagging 2004-12-19
PB
Quote: "any genuine effort at password hacking would be hobbled by the Department's policy of limiting failed login attempts"

Someone should inform Mr. Cooper about hash sniffing, and remote hash grabbing directly from servers (yes, even 2K3 servers) with pwdump3e & Co.

Any administrator, or someone with an admin or system service password, or someone who's able to escalate privileges, or someone esploiting a 0day for which a patch doesn't yet exist, or someone with social engineering skills, could successfully use pwdump3e against any 2000/2K3 server or workstation.

To do this, bad guys need only one password or a bug, and often it is not so difficult to have it.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/10148/29576#29576
Report: DHS cyber security lagging 2004-12-20
Anonymous (2 replies)
Report: DHS cyber security lagging 2004-12-21
Tommy Ward







 

Privacy Statement
Copyright 2009, SecurityFocus