Announcement

Collapse
No announcement yet.

setting up a business - advices?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #46
    duke, well, first off that's not how it's done. We could not compromise their data, at least not until we are very well established and even then it's a bit iffie, most likely we will leave marks at places so they can be verified later on that we did visit there (server, folders etc).

    I don't need to test run this, I have done it. Well not like you think so don't worry. And besides, I guarantee I could do this to a fortune 10 company right now and steal a crapload of info and not break a sweat, be detected and possibly even make them pay salary for me under fake name, and break away free and easy and never be found out what truly happened. Talk is cheap, let's just say it's not something that is 'not feasible', it's more of a question of how easy it will be and how fast can we compromise data before one single question will be asked. So why do I boast about being able if willing? because I work in one and it's HORRIBLE, the security that is. There's LOTS of things they could do to improve the security, starting from few policies and enforcing them. And also perhaps hiring someone who is up to date with this stuff. And loads of other things, most likely it means organizational change in security etc.

    But yes, I most likely will be able to do this, I mean, there likely is a company that will let me do this on a research purpose at least. Not sure about actual auditing yet. I'd love to do it though.

    And the talk about trojans, that's just one thing to show off, stealing few passwords for later on purposes, just as one thing. The idea is to compromise the security in all levels, as many times as possible, it's mostly to show the customer how easy it was and how their security sucked horribly, so that they change the attitude and start looking at new ways to improve it, mainly focusing on the user, not the system only.

    Security screening, I don't mean anything new that is not already done in some places. I don't mean anything illegal.

    And one important aspect is not to make new obstacles for work. Most helping solutions are easy and mostly a question of attitude. And this is to for example... demonstrate why ID badges are used. If I can get in for example without one, and no one asks me a single question and I can be there for a week, stealing and messing around, it's a problem. A rule that is not enforced or cared after. What's the point if you don't use them? Might as well not use the whole system at all, it only costs to make them badges.

    There are kazillion things that needs to be reminded, focusing on the key weaknesses. This is of course if you have valuable information you want to protect. If not, they you don't need to pay that much attention, however if you do, then they should pay attention that they are living with false sense of security, and false sense of security kills

    Many places and I know this with first hand experience have problems with help desk. Basically it's their job to help, but they should know what they can not tell, indicate or even tip off. Social engineering is basically manipulating people to tell things they aren't supposed to. And that's why it works, because people are people.
    In da butt.
    "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
    THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
    "God is dead" - Nietzsche. "Nietzsche is dead" - God.

    Comment


    • #47
      Corporate network security is a hard sector, as Kontiki noted you don't have the credentials for a company to let you near its computer system. What's more, small companies either don't need it or can't afford it, and large companies probably already have internal teams or established consultants.

      Unless you have an innovative approach that blows your competitors out of the water, the going will be very tough.
      (\__/) 07/07/1937 - Never forget
      (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
      (")_(") "Starting the fire from within."

      Comment


      • #48
        Well I have researched the field, this is not my worry.

        As said, I was looking for business advices. I am aware of the issues mentioned.
        In da butt.
        "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
        THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
        "God is dead" - Nietzsche. "Nietzsche is dead" - God.

        Comment


        • #49
          Try getting Mitnick as your mentor.
          Que l’Univers n’est qu’un défaut dans la pureté de Non-être.

          - Paul Valery

          Comment


          • #50
            Sorry to be a grammar nazi, but may I just advise that the collective noun for advice is advice, not advices?

            Comment


            • #51
              It's weird if you choose to be a grammar nazi now, I make mistakes all the time.

              laurentiues, that would be cool, but he runs his own company now and he is almost unreachable . I mean, would be cool, but not likely going to happen. I do have a 'mentor' though who is an expert on surveillance. So.. it's not all bad

              UR, and getting back to what I said, yes you are right and I am aware of that (the customers), but it's like in any business, if you are not going to invent something totally new which is like 99% of cases, then you have to compete. THis should be a no-brainer, yes? Besides, there is not so much competition in where I live. At least not yet.

              Plus most security auditing is pretty much unique, meaning they have different types of things they do, and so do I. And I tend to focus on issues and details that most do not pay attention to. Some do, but in the particular field, the competition is not as high as in most fields.
              In da butt.
              "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
              THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
              "God is dead" - Nietzsche. "Nietzsche is dead" - God.

              Comment


              • #52
                Get a black dude

                Monkey!!!

                Comment


                • #53
                  I can't, unless I'm going outside Finland with it. Why? Because there's so few black men and women in here that they will be remembered most likely. The idea is not to be remember or recognized later on .

                  So my company will be racist as well. Maybe the programmer, or someone who isn't operating though.. doesn't matter then.
                  In da butt.
                  "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
                  THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
                  "God is dead" - Nietzsche. "Nietzsche is dead" - God.

                  Comment


                  • #54
                    How about doing some guerilla marketing by cracking into governments and companies systems?

                    Or set up your own cracker group and then turn it into the interpol, then start cooperating with then while keeping the group going as an undercover front.

                    Case Study #1: Wastedtime





                    * Wastedtime

                    Specialized in early Screeners. Was a target of Operation Site Down, but is widely believed to have been at least partially run by the FBI out of Charlotte, North Carolina. Since that operation, the group and its members have completely disappeared, supporting this conclusion.


                    The group released lot of stuff before going offline.

                    Que l’Univers n’est qu’un défaut dans la pureté de Non-être.

                    - Paul Valery

                    Comment


                    • #55
                      Well what you're suggesting is illegal

                      I said we would be doing de mos, but that's when you get a permission to do one...

                      Of course you can always steal as much as you can, go to jail (in here, maybe 3 weeks) get back, get legal, get rich.

                      But nah.. not for me.
                      In da butt.
                      "Do not worry if others do not understand you. Instead worry if you do not understand others." - Confucius
                      THE UNDEFEATED SUPERCITIZEN w:4 t:2 l:1 (DON'T ASK!)
                      "God is dead" - Nietzsche. "Nietzsche is dead" - God.

                      Comment

                      Working...
                      X