BBC 'vague' reporting again!

Richard Clayton ukcrypto at chiark.greenend.org.uk
Mon, 1 Dec 2008 16:13:23 +0000


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <732076a80812010801n600a6f11j42b4e2d0b798e42b@mail.gmail.com>
, Benjamin Donnachie <benjamin@py-soft.co.uk> writes

>    LiveWire from WetStone claims to do the same thing without 
>    requiring dedicated software on the target machine; it just 
>    requires administrator access.

I have seen a compelling demo (discretion suggests that I don't say of
quite what and where, but it was in the UK) of a system that would
listen in to a network (wired or wireless), then access a machine, run a
series of exploits against that machine until one worked [people are
terribly sloppy about patch installation] then upload a little program
which provided remote access to file systems and their contents....

... essentially what the bad guys use, but packaged into a product that
provides any Tom Dick or Harriet with leet skillz (along with all the
logging that a chain of evidence might require...)

- -- 
richard                                              Richard Clayton

They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety.         Benjamin Franklin

-----BEGIN PGP SIGNATURE-----
Version: PGPsdk version 1.7.1

iQA/AwUBSTQNI5oAxkTY1oPiEQLLTACg1g3SI/2SuGF5evUPdP1y5/VN9r8AoOCe
qQVcRuu7w67Ejgp3/IVvZ5Dm
=qPBC
-----END PGP SIGNATURE-----