PaulDotCom mailing list archives

Bypassing Vontu


From: dninja at gmail.com (Robin Wood)
Date: Thu, 22 Oct 2009 16:46:19 +0100

2009/10/22 Brian Schultz <theconqueror at gmail.com>:
Our security department is testing out Symantec's Vontu and I am playing the
guinea pig and?have to try and get documents out of our company's
environment. I have a really basic understanding of how it works. It has a
span port sitting and listening to all outgoing web traffic and there is
also an agent that sits on desktops and watches to see if any sensitive
information leaves via USB drive or e-mail.

Does anyone have any whitepapers or?info regarding how it actually works or
any tactics I should try?

What happens if you encrypt a zip file with the contents in? Make sure
that the original filename isn't one that is being looked for.

Or upload the file to a web server over https.

Robin


Current thread: