Seenthis
•
 
Identifiants personnels
  • [mot de passe oublié ?]

 
RSS: Martin Korolczuk
tous les messages de Martin Korolczuk

Martin Korolczuk

@martin
http://unearaigneeauplafond.fr
  • Martin Korolczuk @martin 17/09/2011 20:48
    1
    @grommeleur
    1

    Our security auditor is an idiot, how do I give him the information he wants? - Server Fault
    http://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-w

    A security auditor for our servers has demanded the following within two weeks:

    – A list of current usernames and plain-text passwords for all user accounts on all servers
    – A list of all password changes for the past six months, again in plain-text
    – A list of “every file added to the server from remote devices” in the past six months
    – The public and private keys of any SSH keys
    – An email sent to him every time a user changes their password, containing the plain text password

    We’re running Red Hat Linux 5/6 and CentOS 5 boxes with LDAP authentication.

    As far as I’m aware, everything on that list is ether impossible or incredibly difficult to get, but if I don’t provide this information we lose access to our payments platform, and any income we might have got while we move away. Any suggestions for how I can solve or fake this information?

    #sécurité_informatique #audit #serveur #discussion #témoignage

    • #security auditor
    • #PayPal
    • #Linux
    • #cryptography
    • #remote devices
    • #security auditor
    Martin Korolczuk @martin
    Écrire un commentaire

thèmes

  • #audit
  • #discussion
  • #sécurité_informatique
  • #serveur
  • #témoignage

  • Position: security auditor
  • Company: PayPal
  • Technology: Linux
  • Technology: cryptography
  • IndustryTerm: remote devices
  • IndustryTerm: security auditor
thématisation automatique par OpenCalais
À propos de Seenthis Propriété intellectuelle Recommandations API