Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Watching the Watchers
Matthew Tanase, 2005-04-18

Misuse of database information by insiders happens everyday, and there's little we can do about it.

Comments Mode:
Watching the Watchers 2005-04-18
Anonymous
Watching the Watchers 2005-04-19
BeauKey
Yes, you and I have to watch. Technically it is correct that more detailed audit trails etc. will not provide information of misuse of (authorisation to) data.
Many times there is circumstantial evidence which proove someone is out of line. One method is a variant on the honeypot. Use, when subscribing to a network service, a unique name. E.g. if you subscribe to the Washinton Post use the name:"Beaukey W.P. Lastname" en note the time/date and circumstance of the subscription. You'll be suprised that this name can (and will) pop-up in a different context!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/318/31433#31433
Watching the Watchers 2005-04-19
Anonymous
Watching the Watchers 2005-04-19
Anonymous (1 replies)
Watching the Watchers 2005-04-20
Anonymous
Watching the Watchers 2005-04-19
Anonymous
Watching the Watchers 2005-04-20
LoneD (2 replies)
Watching the Watchers 2005-04-20
Anonymous (1 replies)
Watching the Watchers 2005-04-22
Roger
Watching the Watchers 2005-04-20
Homer Simpson
Watching the Watchers 2005-04-21
Anonymous
Watching the Watchers 2005-04-22
Doug Sibley







 

Privacy Statement
Copyright 2009, SecurityFocus