Penetration Testing mailing list archives

Re: [PEN-TEST] WebEx security?


From: "T. Barrick" <tbarrick () HOME COM>
Date: Tue, 31 Oct 2000 12:28:45 -0700

One point of view that I have not seen represented here is the ease at which
corporate espionage can be carried out with the assistance of an unskilled,
disgruntled employee.  One person replied that this app works right through the
company firewall - yes it does. This application, if utilized via https, could
completely open up your company LAN, in a completely non-sniffable fashion, to
anyone out there in cyberspace that the disgruntled employee had the nerve to
contact.  Spooky stuff to me.

Just my .02ยข

Toby

"Frazier, Thomas" wrote:

Is anybody here familiar with Webex (http://www.webex.com)?  It looks like a
pretty good online meeting, virtual office thingy.  However, on their
website they state that "Data streams are hashed to prevent wire tapping."
I think their buzzword compliance generator has the turbo button pressed. ;)

This is a possible solution for me and I want to make sure I am not sticking
my foot in my mouth by giving it a green light for security.  Any good or
bad feedback would be appreciated.

Thomas Frazier
Systems Specialist
Corporate Information Security
------------------------------
 Thomas.Frazier () usa xerox com
------------------------------


Current thread: