<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>OS or app? in </title>
<link>http://www.dslreports.com/forum/r22514483</link>
<description></description>
<language>en</language>
<pubDate>Wed, 10 Feb 2010 09:03:16 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 09:03:16 EDT</lastBuildDate>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22522443</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It is not "Don't trust the network", but "don't trust the users"!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22522443</guid>
<pubDate>Tue, 09 Jun 2009 15:52:48 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22518922</link>
<description><![CDATA[<A HREF="/useremail/u/609695"><b>KevNYC</b></A> : SkyNet anyone?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22518922</guid>
<pubDate>Mon, 08 Jun 2009 22:43:01 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22516173</link>
<description><![CDATA[<A HREF="/useremail/u/1611710"><b>PapaMidnight</b></A> : <div class="bquote"><small>said by  cyclone_z <A HREF="/useremail/u/1367503"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  KodiacZiller <A HREF="/useremail/u/1578887"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br><div class="bquote"><small>said by  PToN <A HREF="/useremail/u/488582"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>Is the list on the post made at insecure.org is true, i would wonder if it would be a new vulnerability in *nix..? There is a lot of HP-UX listed there as well as AIX and Sun...<br> </div>Could just be that the T-mobile admins were lazy about security updates.  This is how their systems were breached back in 2005.  They failed to patch a security exploit that had been widely known about for a while.<br> </div>Having worked for one of the companies that sells one of those operating systems, I will tell you that often times big companies are lax on internal security.  They have a good firewall, but systems on the other side are unpatched.  They make the mistake of trusting the network, but all it takes is one security breach, and then someone is in a wonderland of vulnerable systems.  The company I worked for was running a number of unpatched Windows servers, and that got them in trouble when a windows virus got through via email.  It then started spreading on the internal network.  There were also engineers using Unix workstations running outdated releases of our Unix-based OS for which we were no longer making security patches.  They were also using things like rsh, telnet, etc., which don't encrypt anything.  Were someone from the outside to get a compromised machine and set ethernet in promiscuous mode -- oh man, a cornucopia of passwords! <br><br>T-Mobile may be doing something similar.  The lesson is don't trust the network, even if you have a firewall.  <br> </div>Not quite sure the lesson is so much of "Don't trust the network".<br><br>More along the lines of as we always say in the security world: "The weakest element in any security system is the human element."]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22516173</guid>
<pubDate>Mon, 08 Jun 2009 14:30:36 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22516012</link>
<description><![CDATA[<A HREF="/useremail/u/1367503"><b>cyclone_z</b></A> : <div class="bquote"><small>said by  KodiacZiller <A HREF="/useremail/u/1578887"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  PToN <A HREF="/useremail/u/488582"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Is the list on the post made at insecure.org is true, i would wonder if it would be a new vulnerability in *nix..? There is a lot of HP-UX listed there as well as AIX and Sun...<br> </div>Could just be that the T-mobile admins were lazy about security updates.  This is how their systems were breached back in 2005.  They failed to patch a security exploit that had been widely known about for a while.<br> </div>Having worked for one of the companies that sells one of those operating systems, I will tell you that often times big companies are lax on internal security.  They have a good firewall, but systems on the other side are unpatched.  They make the mistake of trusting the network, but all it takes is one security breach, and then someone is in a wonderland of vulnerable systems.  The company I worked for was running a number of unpatched Windows servers, and that got them in trouble when a windows virus got through via email.  It then started spreading on the internal network.  There were also engineers using Unix workstations running outdated releases of our Unix-based OS for which we were no longer making security patches.  They were also using things like rsh, telnet, etc., which don't encrypt anything.  Were someone from the outside to get a compromised machine and set ethernet in promiscuous mode -- oh man, a cornucopia of passwords! <br><br>T-Mobile may be doing something similar.  The lesson is don't trust the network, even if you have a firewall.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22516012</guid>
<pubDate>Mon, 08 Jun 2009 13:59:59 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22515411</link>
<description><![CDATA[<A HREF="/useremail/u/1578887"><b>KodiacZiller</b></A> : <div class="bquote"><small>said by  PToN <A HREF="/useremail/u/488582"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Is the list on the post made at insecure.org is true, i would wonder if it would be a new vulnerability in *nix..? There is a lot of HP-UX listed there as well as AIX and Sun...<br> </div>Could just be that the T-mobile admins were lazy about security updates.  This is how their systems were breached back in 2005.  They failed to patch a security exploit that had been widely known about for a while.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22515411</guid>
<pubDate>Mon, 08 Jun 2009 12:19:03 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22514808</link>
<description><![CDATA[<A HREF="/useremail/u/488582"><b>PToN</b></A> : Well, once he said he got it he close any possible backdoor he/she might have left.<br><br>He wanted this for $$$ and not for any other purpose. Any respectable hacker/cracker knows that one of the rules is to never close any doors to a system you might need later, else he would have said nothing and he might have been able to use the servers for much bigger things. However, this is just an extortion case..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22514808</guid>
<pubDate>Mon, 08 Jun 2009 10:30:30 EDT</pubDate>
</item>

<item>
<title>Re: OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22514590</link>
<description><![CDATA[<A HREF="/useremail/u/1212505"><b>bigfitch</b></A> : If this is true.  It just adds more proof that everything is accesable if you have the know how and the time. <br><br>Wonder if said hacker left himself a backdoor to get more info for his next auction. Lol]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22514590</guid>
<pubDate>Mon, 08 Jun 2009 09:51:24 EDT</pubDate>
</item>

<item>
<title>OS or app?</title>
<link>http://www.dslreports.com/forum/remark,22514483</link>
<description><![CDATA[<A HREF="/useremail/u/488582"><b>PToN</b></A> : Is the list on the post made at insecure.org is true, i would wonder if it would be a new vulnerability in *nix..? There is a lot of HP-UX listed there as well as AIX and Sun...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22514483</guid>
<pubDate>Mon, 08 Jun 2009 09:28:33 EDT</pubDate>
</item>

</channel>
</rss>
