Archive

Archive for May, 2005

Another variation of prank calls

May 16th, 2005

We get all sorts of pranksters/”hackers” on Skype. Some of them less serious, some more so. Here’s another variation.
x says: people calling, saying it is a Skype admin test call and please leave your PC on and alone for a few hours
x says: sounds very dodgy and dangerous to me, sounds like hacking
x says: maybe you should publicise on the front page that Skype never initiate test calls
x says: what do they do when people leave the pc alone?, not entirly sure but some sort of hacking software to extract info from the PC
So, to make it clear, Skype never initiates test calls to random people. Unless of course it’s previously agreed and you know to expect it. If you get a random user claiming a Skype test call and it hasn’t been previously agreed, they’re most likely tricking you into … something. Don’t exactly know what that would be, [...]

Original post by Jaanus and a wordpress plugin by Elliott

Computer security Systems

Cisco’s NAC torn open at Black Hat

May 2nd, 2005

Two flaws in Cisco’s Network Admission Control (NAC) architecture allow unauthorised PCs to be viewed as legitimate devices on a network, according to German security researchers.

A tool that takes advantage of the flaws was demonstrated at last month’s Black Hat security conference in Amsterdam by Michael Thumann, chief security officer, and Dror-John Roecher, senior security consultant at German penetration-testing firm, ERNW.

The NAC technology lets IT managers set rules that prevent a client device from accessing a network unless the device complies with specific policies on antivirus software, firewalls, software patches and other issues, Cisco said.

The NAC architecture uses Cisco Trust Agent technology, which sits on each client, to determine whether a device complies with established policies. Based on the findings of the agent, a policy management server either lets the device log on to the network or puts it into a quarantine zone.

Computer security Systems, Networking security , , , ,