PaulDotCom mailing list archives

Proactive Measures


From: andycapp92 at gmail.com (Andrew Anderson)
Date: Tue, 3 Feb 2009 07:47:50 -0700

I'm with Robin on this one.  I took my eeepc (which I had set up with only a
base install + minor tweaks) to Defcon last year....  never even opened it.

This year I am thinking I'll spend some time in the wireless village or
perhaps one of the challenges so I might actually have to turn it on....
but I really (since I had my Crackberry) never had any reason to connect
outside of the con.  I found it amusing really what I was willing to do
without when I knew there was a high likelihood I was being
targetted/scrutinized by someone.

I haven't read all the lists, but after last years Sunday afternoon
presentation...  I'd add a process of doing a regular check on a traceroute
to your server of choice to check for changes (how you'd determine if any
changed were legit, I'm not clear on though).


---


2009/2/1 Arch Angel <arch3angel at gmail.com>

Hey Everyone,

I have been pondering the idea of creating a list of things a person can do
prior to going to an event such as DefCon or Shmoocon to protect
themselves.  I thought since we getting closer to Shmoocon it might make for
an interesting list as everyone begins to add their special tweaks.

Here are a couple that come to mind for me, although it is not all of them
it will get the list started :-)

Hardcode DNS - 208.67.220.220 & 208.67.222.222
Disable Bluetooth
Disable Wireless if at all possible
SSH & Tunnel
Configure local firewall to only allow whats absolutely needed and drop
anything else
Create a checksum of the system before leaving & check it while at the
event
Change passwords before leaving
Change passwords as soon as you return
Never leave your equipment unattended
Never check banking or other important sites while at the event
Disable any unneeded users on the system

Test the laptop prior to leaving

Just a quick list off the top of my head, I'll think about it more while I
am at work tonight...

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




-- 
Andrew Anderson
andrew at a2-technologies.com, andycapp92 at gmail.com

403.827.3802
403.249.4278
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090203/786fc669/attachment.htm 


Current thread: