Security Basics mailing list archives

Re: NASA Security Audit


From: "Anders Reed-Mohn" <anders_rm () utepils com>
Date: Fri, 10 Oct 2003 11:28:52 +0200


Blocking this at the linux platform so he
cant get through is a powerful way of shielding the flaws in microsoft
architecture.

And if I were to perform such an audit/test, this is exactly the kind of
thing that
would get the system admin in trouble.

think about it.. what are you really doing here?  If I understand you
correctly,
you are just covering up a problem, pretending it is not there,
instead of trying to fix it.

This will be obvious to an auditor, if he's any good...

Besides, if it does work, or fool, some people, this will lead to the
sysadmin not fixing the real problem later either, because the
patch applied seems to be ok.

Dangerous territory, man ...

Cheers,
Anders :)



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: