Re: Perhaps the most OBVIOUS question you will ever see.

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 19:29:12 +1100

I'd just demonstrate why that is a big deal. If you have servers that are
not totally secured, if you see applications credentials and data sent in
clear and available to a guy in the parking lot - that will make the things
a big deal.

Until you show that the risk is actually a vulnerability, that will be just
a risk - and the risk seems to be accepted by the business. For now.

-- 
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
"Curious George" <curious@spampoop.com> wrote in message
news:99hKd.1635$Vt6.340@fe10.lga...
> Dear Colleagues:
>
> Here is the problem.  My boss insists that its "no big deal" and that
since
> the servers are on the inside and protected, we really don't have a thing
to
> worry about.


Relevant Pages

  • RE: Bank pen test
    ... The bank will be working to Risk. ... A vulnerability on an internal system is not always a large risk. ... If they want a pen test of only 20 servers there is no way to know if the ... the veteran Network Behavior Analysis ...
    (Pen-Test)
  • Re: Level of Exploitation
    ... But, for some companies, risk is ... Servers can always be replaced, reconfigured, updated and so one. ... Security Trends Report from Cenzic ... I think the Auditor's job is to assess vulnerability ...
    (Pen-Test)
  • Re: [fw-wiz] Isolating internal servers behind firewalls
    ... Does every desktop require access to every server's file share port, ... If you have a/or several intranet IIS servers, ... If one thinks Windows file sharing is not risky, then I have no basis to argue the point any further. ... information at risk. ...
    (Firewall-Wizards)
  • Re: Postfix smtpd DNS lookup delay
    ... the connection. ... Small risk, but still a risk. ... it may want to do logging based on the service configuration ... Many servers want to (or can be configured ...
    (alt.os.linux.suse)
  • Re: Perhaps the most OBVIOUS question you will ever see.
    ... If you have servers that are ... Until you show that the risk is actually a vulnerability, ... My boss insists that its "no big deal" and that ...
    (microsoft.public.pocketpc.wireless)