Re: Interesting discussion on ServerFault regarding an idiotic auditor ...
Dave Kahn <[email protected]> Thu, 28 Jul 2011 19:43:32 +0100
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <CAD_Anen55EFdMwauaoyiUM8yDt6SA9KSEbY4cmdvbo3Ye-_saA@mail.gmail.com> |
On 28 July 2011 03:20, Douglas Handy <[email protected]> wrote: > Jim, > > I would think that kind of request is a hacker seeing how stupid a securi= ty >> manager can be.. >> > > It is either that, or an attempt to determine if the security manager can= be > "socially engineered" and persuaded to give up information he shouldn't. = =A0It > at least has a small chance of really being part of what they are testing. > > But I give it much higher chances of being a hacker, and not really even > from the alleged audit firm. It can't be a legitimate request from an audit firm as it would be illegal for the firm to make it in the UK. If not illegal it would in any case be unethical as it would seriously undermine the client company's security even attempting to comply with it. Whoever asks to see a plaintext password? > I give it a near zero chance of being a serious auditor who is serious ab= out > requesting the information. =A0What probably troubles me the most is this > security manager would even consider trying to fake some data to hand ove= r, > instead of steadfastly refusing to comply and informing higher ups and the > legal beagles. Do we know if the poster is genuine? The whole thing sounds made up to me. -- = Dave... Two is not equal to three, even for very large values of two. -- Grabel's L= aw _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) ma= iling list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.