PaulDotCom mailing list archives

Bypassing Vontu


From: cmerkel at gmail.com (Chris Merkel)
Date: Thu, 22 Oct 2009 10:54:59 -0500

Thomas Ptchek from Matasano tore DLP a new one in a discussion we were
a part of about a year ago. I'd check their blog for details.

My suggestion: start with data hiding technology that end users are
generally capable of using, such as a password protected zip. Then
move toward more complicated methods.

On 10/22/09, Brian Schultz <theconqueror at gmail.com> wrote:
Our security department is testing out Symantec's Vontu and I am playing the
guinea pig and have to try and get documents out of our company's
environment. I have a really basic understanding of how it works. It has a
span port sitting and listening to all outgoing web traffic and there is
also an agent that sits on desktops and watches to see if any sensitive
information leaves via USB drive or e-mail.

Does anyone have any whitepapers or info regarding how it actually works or
any tactics I should try?


-- 
Sent from my mobile device

- Chris Merkel


Current thread: