|
LITTLEBLACKDOG.COM
|
| Author |
Message |
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Mon Mar 17, 2008 5:51 am Post subject: lock it up f00l |
|
An an infosec dude, one of my pet peeves is unsecured workstations. Especially IT folk w/ root level access to systems. I can't tell you how many times I've sent emails and the like to entire departments. It's time to step up my game a little. I'm looking for a script that will live on a public share & change the victims background to some lame David Hasselhoff picture. The idea is to get in and get out quickly.
|
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
|
|
|
|
|
Webster
Guide Dog


Joined: 16 Feb 2002 Age: 28 Posts: 8694
Location: Vacationland
|
Posted:
Mon Mar 17, 2008 6:39 am Post subject: |
|
|
|
|
|
Pakiii
Tail-Wagger


Joined: 22 Jul 2002 Posts: 2083
Location: KS, USA
|
Posted:
Mon Mar 17, 2008 7:16 am Post subject: |
|
Are you wanting something that you push down, or something where if you wandered around and found an unsecured workstation that you could hop on real quick and run it on there? |
_________________ "Because men know that the conquest of one's own weakness is a far, far, more difficult task than any other, they tend to believe that he who can conquer himself can also conquer whatever problem is at hand" - Rear Admiral Harley Cope
|
|
|
|
|
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Mon Mar 17, 2008 7:16 am Post subject: |
|
This should answer both Websters and Pakiiis questions/comments
Turn and burn type mission... the objective it to pull a quick prank by navigating to the share from the victims desk then leaving a secured workstation with a "windows key | l" |
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
Last edited by fear_nothing on Mon Mar 17, 2008 7:21 am; edited 1 time in total
|
|
|
|
|
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Mon Mar 17, 2008 7:19 am Post subject: |
|
So far so good, but it's not making the changes stick until after a logout. Which defeats the purpose
Quote:@echo off
call :quiet>nul 2>&1
goto :EOF
:quiet
:: Configure Wallpaper
REG ADD "HKCU\Control Panel\Desktop" /V Wallpaper /T REG_SZ /F /D "%SystemRoot%\Prairie Wind.bmp"
REG ADD "HKCU\Control Panel\Desktop" /V WallpaperStyle /T REG_SZ /F /D 0
REG ADD "HKCU\Control Panel\Desktop" /V TileWallpaper /T REG_SZ /F /D 2
:: Make the changes effective immediately
%SystemRoot%\System32\RUNDLL32.EXE user32.dll, UpdatePerUserSystemParameters
Based off this batch file found here:
http://www.jsifaq.com/SF/Tips/Tip.aspx?id=10732 |
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
|
|
|
|
|
T
Curmudgeon

Joined: 17 May 2001 Posts: 16085
Location: Airstrip One
|
Posted:
Mon Mar 17, 2008 8:43 am Post subject: |
|
KiX is your friend, specifically the SETWALLPAPER function. |
_________________ Got questions? Click here.
Still got questions? Click here, too.
affabletoaster, Akely, anglachel, blahpony, CMTG, EdisonRex, Elk, Equin, evilness, Fido, fathertyme, Goddess, Jaymac, je, jodygirl, KingKobra, Lycander, mally, Max, OhioArt2, perrito_blanco, Rover, Spot, sully_51, Superdwarf, the taz man, thriftyjack, twiztid, wrathiron, yiayia49
A journey of 3,500 miles begins with a single comic.
Would you like good music at a price that is right? CD Baby, baby.
The best way to blow off steam is to blow off someone's nadgers.
|
|
|
|
|
Pakiii
Tail-Wagger


Joined: 22 Jul 2002 Posts: 2083
Location: KS, USA
|
Posted:
Mon Mar 17, 2008 8:44 am Post subject: |
|
Why not have your script run and then logoff the user? |
_________________ "Because men know that the conquest of one's own weakness is a far, far, more difficult task than any other, they tend to believe that he who can conquer himself can also conquer whatever problem is at hand" - Rear Admiral Harley Cope
|
|
|
|
|
CMTG
Leg Humper


Joined: 23 Feb 2002 Posts: 4892
Location: On average, Cheltenham.
|
Posted:
Mon Mar 17, 2008 10:53 am Post subject: |
|
Pakiii wrote:Why not have your script run and then logoff the user?
Session preservation.
The douchebag from internal support that logs me off instead of locking my workstation is signing up for some pain if I have to restart a 4 hour build. |
_________________ Pie. I wish I could
constrain my hungry greed but...
Sadly, defeated.
"Have I seen you at the gym? I don't go to the gym, I'm just naturally like this..."
- Captain Hammer
|
|
|
|
|
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Mon Mar 17, 2008 11:49 am Post subject: |
|
CMTG wrote:Pakiii wrote:Why not have your script run and then logoff the user?
Session preservation.
The douchebag from internal support that logs me off instead of locking my workstation is signing up for some pain if I have to restart a 4 hour build.
Whilst I lean toward the BOFHside, generally I don't like to cause unnecessary work. However the user is responsible for his/her terminal... it should have been locked up.
No reason for not securing your workstation |
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
|
|
|
|
|
CMTG
Leg Humper


Joined: 23 Feb 2002 Posts: 4892
Location: On average, Cheltenham.
|
Posted:
Mon Mar 17, 2008 4:33 pm Post subject: |
|
fear_nothing wrote:CMTG wrote:Pakiii wrote:Why not have your script run and then logoff the user?
Session preservation.
The douchebag from internal support that logs me off instead of locking my workstation is signing up for some pain if I have to restart a 4 hour build.
Whilst I lean toward the BOFHside, generally I don't like to cause unnecessary work. However the user is responsible for his/her terminal... it should have been locked up.
No reason for not securing your workstation 
So lock it then, don't log me off. And if you really want root access to our collection of aging build machines, be my guest. Everyone in development has, I have plausible deniability. |
_________________ Pie. I wish I could
constrain my hungry greed but...
Sadly, defeated.
"Have I seen you at the gym? I don't go to the gym, I'm just naturally like this..."
- Captain Hammer
|
|
|
|
|
anglachel
Guide Dog


Joined: 08 Nov 2003 Posts: 8318
Location: MN
|
Posted:
Mon Mar 17, 2008 5:43 pm Post subject: |
|
fear_nothing wrote:CMTG wrote:Pakiii wrote:Why not have your script run and then logoff the user?
Session preservation.
The douchebag from internal support that logs me off instead of locking my workstation is signing up for some pain if I have to restart a 4 hour build.
Whilst I lean toward the BOFHside, generally I don't like to cause unnecessary work. However the user is responsible for his/her terminal... it should have been locked up.
No reason for not securing your workstation 
Not having my foot put up your ass it YOUR responsablity...
No reason for Touching my work station.
I like to call it "security through making an example of that last guy."
Besides, the last person to leave me a message about how I should lock my workstation when I walk away for a second in notepad, got a similar message... except he was sitting in his cube, infront of his computer using it, My message though offered that locking your computer offers little in the way of security.
Closing the message was a bad Idea.. it lead to [ur=http://www.f-secure.com/hoaxes/sheepexe.shtmll]sheep.exe[/url] being fired off... and every time he killed one of them two more came...
after a 10-12 sheep the windows 16 bit subsystem couldn't take it any more and the computer slowed to a crawl. I killed the process remotely about that time. |
_________________
Quidquid latine dictum sit, altum sonatur.
Death to Shuttleworth!
|
|
|
|
|
T
Curmudgeon

Joined: 17 May 2001 Posts: 16085
Location: Airstrip One
|
Posted:
Mon Mar 17, 2008 5:54 pm Post subject: |
|
http://www.littleblackdog.com/post184655.html |
_________________ Got questions? Click here.
Still got questions? Click here, too.
affabletoaster, Akely, anglachel, blahpony, CMTG, EdisonRex, Elk, Equin, evilness, Fido, fathertyme, Goddess, Jaymac, je, jodygirl, KingKobra, Lycander, mally, Max, OhioArt2, perrito_blanco, Rover, Spot, sully_51, Superdwarf, the taz man, thriftyjack, twiztid, wrathiron, yiayia49
A journey of 3,500 miles begins with a single comic.
Would you like good music at a price that is right? CD Baby, baby.
The best way to blow off steam is to blow off someone's nadgers.
|
|
|
|
|
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Tue Mar 18, 2008 4:19 am Post subject: |
|
anglachel wrote:fear_nothing wrote:CMTG wrote:Pakiii wrote:Why not have your script run and then logoff the user?
Session preservation.
The douchebag from internal support that logs me off instead of locking my workstation is signing up for some pain if I have to restart a 4 hour build.
Whilst I lean toward the BOFHside, generally I don't like to cause unnecessary work. However the user is responsible for his/her terminal... it should have been locked up.
No reason for not securing your workstation 
Not having my foot put up your ass it YOUR responsablity...
No reason for Touching my work station.
I like to call it "security through making an example of that last guy."
Besides, the last person to leave me a message about how I should lock my workstation when I walk away for a second in notepad, got a similar message... except he was sitting in his cube, infront of his computer using it, My message though offered that locking your computer offers little in the way of security.
Closing the message was a bad Idea.. it lead to [ur=http://www.f-secure.com/hoaxes/sheepexe.shtmll]sheep.exe[/url] being fired off... and every time he killed one of them two more came...
after a 10-12 sheep the windows 16 bit subsystem couldn't take it any more and the computer slowed to a crawl. I killed the process remotely about that time.
Whats so fundamentally tough about locking your company workstation when your not there? |
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
|
|
|
|
|
squashman
Big Dog


Joined: 08 Oct 2001 Posts: 3471
Location: 1265 Lombardi Ave.
|
Posted:
Tue Mar 18, 2008 6:53 am Post subject: |
|
So you don't force the Lock Workstation thru the screen saver with group policy. If they are not going to lock it then lock it for them. Every minute.
I am like you. I don't get up until I lock the work station. I even have a shortcut on my desktop should I be holding the mouse when I want to walk away. |
|
|
|
|
|
|
fear_nothing
Moderator


Joined: 07 Nov 2001 Posts: 2750
Location: The end of the internet
|
Posted:
Tue Mar 18, 2008 7:12 am Post subject: |
|
squashman wrote:So you don't force the Lock Workstation thru the screen saver with group policy. If they are not going to lock it then lock it for them. Every minute.
I am like you. I don't get up until I lock the work station. I even have a shortcut on my desktop should I be holding the mouse when I want to walk away.
We do but its too long - it's set at 60 minutes. Which givesan evil do-er more than enough time to muck things up. |
_________________ -Fear
Remember when it comes to Information Security only the paranoid will survive….
Slashdot poster: I don't use commercial applications. I don't use programs for my security tests. I do the tests myself everyday.
Slashdot reply: You don't use programs? What, you put the cat-5 in your mouth and try to *taste* the intruders?
An infinite number of monkeys pounding away on keyboards will eventually produce a report showing that Windows is more secure and has a lower TCO, than linux.
|
|
|
|
|
|
|
| Goto page 1, 2 Next
|
View next topic
View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
Powered by phpBB
© 2001, 2002 phpBB Group
phpBB SEO
All times are GMT - 8 Hours
Help us keep advertisements off this site. Donate today!
|
|