Penetration Testing mailing list archives

Re: Boot floppy


From: Michael Munt <michael.munt () nhs net>
Date: Fri, 13 Apr 2007 10:18:01 +0100

Mifa,

if the machine is not on the domain, how is it using the resources of the domain. Surely you can block the machine from connecting to your resources, this will then allow you to gain access to the machine with a "legitimate" reason to find out whats wrong.

hth
michael



Mifa wrote:
Thanks for the info.  Backups are not done on a machine thats off our network.  I can not access my admin privilages 
becasue the machine is not on a domain and is not simply locked with windows. Further , the admin account is 
disabled/missing; to be honest Im not shure how.  I had hoped to do a quick reboot from a floppy because its fast.

 We suspect that we  have someone who is sending company job files to another company. If so this would make the second 
person doing such.  One of our employes left this company to start another company and he had friends.   We dare not 
point out any one without proof or fire anyone without knowing we the correct person; especially when this person has 
been with the company most of its existance.  To get that proof I think the hardware key logger would be a good option 
to get the password ect then log in, but not any good for the longer term.   Also, we are keeping a copy of all emails. 
 The other option is to disclose our suspecions and have him turn in the computer the next time he comes into the 
office; which we will do if we must.  Being a small company based on trust its the last option short of fireing wich 
the owner will not do without proof.  Now you see the sensitive delima here.  We do have every right and policy, but....


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



**********************************************************************
This message  may  contain  confidential  and  privileged information.
If you are not  the intended  recipient please  accept our  apologies.
Please do not disclose, copy or distribute  information in this e-mail
or take any  action in reliance on its  contents: to do so is strictly
prohibited and may be unlawful. Please inform us that this message has
gone  astray  before  deleting it.  Thank  you for  your co-operation.

NHSmail is used daily by over 100,000 staff in the NHS. Over a million
messages  are sent every day by the system.  To find  out why more and
more NHS personnel are  switching to  this NHS  Connecting  for Health
system please visit www.connectingforhealth.nhs.uk/nhsmail
**********************************************************************


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


Current thread: