Re: userenv and NETLOGON errors
- From: "Matt Gibson" <mattg@xxxxxxxxxxxxxxx>
- Date: Mon, 20 Jun 2005 11:49:38 -0700
If all it takes to bring down a network is knowledge of the internal IP
schema, then you're screwed from the get-go.
Feel free to XXX out the public IP address, but any hacker hanging around
here who wants to know what your IP address setup is, already has more
information (Default server IP, default IP settings). We're trying to
determine which people have incorrect default settings, and bring them back
to the norm.
Security by obsecurity isn't any security at all. Especially when we're all
basically the same here.
Matt Gibson - GSEC
"Tony Su" <TonySu@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5B702688-54AB-418E-A084-429325C4DF8E@xxxxxxxxxxxxxxxx
> Matt,
> This question on whether to post IPCONFIG has been discussed to death.
>
> A short discussion which I participated is in Susan's blog archives. I'm
> not
> the only person to question this practice, in summary the information by
> itself is not a fatal compromise but
> - It's a substantial amount of very useful information to a hacker
> - Like everything else posted to a public forum/Internet, the information
> lives forever.
>
> In other words, the exploit that uses the information may not be common
> practice today, but if the information is still valid 8 years from now and
> the exploit is developed that uses that information, you'll regret what
> you
> thought was a minor indescretion.
>
> Tony
>
>
>
>
> "Matt Gibson" wrote:
>
>>
>> > Although others might disagree with me, I generally discourage posting
>> > IPCONFIGS for security reasons, but if there is no alternative the
>> > bottom
>> > line is getting fixed.
>>
>> Posting this makes people think there IS a security risk to it.
>>
>> You're spreading FUD, and making it harder for us to help people in this
>> newsgroup.
>>
>> Please stop.
>>
>> Matt Gibson - GSEC
>>
>>
>>
.
- Follow-Ups:
- Re: userenv and NETLOGON errors
- From: Tony Su
- Re: userenv and NETLOGON errors
- References:
- userenv and NETLOGON errors
- From: jaredea
- Re: userenv and NETLOGON errors
- From: Matt Gibson
- Re: userenv and NETLOGON errors
- From: Tony Su
- Re: userenv and NETLOGON errors
- From: Matt Gibson
- Re: userenv and NETLOGON errors
- From: Tony Su
- userenv and NETLOGON errors
- Prev by Date: Command to run setup wizard
- Next by Date: Re: FWC for XP Pro x64?
- Previous by thread: Re: userenv and NETLOGON errors
- Next by thread: Re: userenv and NETLOGON errors
- Index(es):
Relevant Pages
|