Re: Is VMS losing the Financial Sector, also?



On Wed, 11 Jul 2007, Larry Kilgallen wrote:

In article <Pine.LNX.4.61.0707111012460.9046@xxxxxxxxxxxxxxxxxxxxx>, Rob Brown <mylastname@xxxxxxxx> writes:
On Wed, 11 Jul 2007, Bob Koehler wrote:

I can see how this would prevent me running a password grabber on a terminal I didn't own. But at the risk of exposing my own account, I could still run it against the terminal I am logged in at.

There is no risk of exposure to your account if you write the software properly.

Just a SMOP.

There is some risk of you being discovered through auditing.

True.

I don't see any protection against that if the potential victim does not avoid the trap.

That is what SET TERMINAL/PERMANENT/SECURE_SERVER is about.

That merely give the potential victim a means to avoid the trap, but does not enforce it.

Definitely not foolproof, but I can't think of anything that would improve it. BillG mentioned using HITMAN or the equivalent, which will help, but still leaves a window of opportunity.


--

Rob Brown b r o w n a t g m c l d o t c o m
G. Michaels Consulting Ltd. (780)438-9343 (voice)
Edmonton (780)437-3367 (FAX)
http://gmcl.com/

.



Relevant Pages

  • Re: bank account details
    ... paid directly into my bank account. ... Whats the risk in giving my account and sort code numbers out? ... A scammer will avoid that and if are so ...
    (uk.people.consumers.ebay)
  • Re: User Accounts
    ... account that surfs the web, and confining everything that comes down the ... Especially since folder permissions has less downside risk than filtering ... >every tool and feature in XP to lock down security as best as is possible. ... and settings do not stay the same when user account rights ...
    (microsoft.public.windowsxp.security_admin)
  • Re: User Accounts
    ... >every tool and feature in XP to lock down security as best as is possible. ... code that is exposed to the "outside", the higher the risk of exploit. ... If I limit an account in XP Home, it falls back to hiding paths, ... and settings do not stay the same when user account rights are ...
    (microsoft.public.windowsxp.security_admin)
  • Re: 5 Tips for Avoiding Cardiovascular Disease
    ... cardiovascular disease (CVD), folks wanting to avoid CVD have a need ... Lowering risk is NOT equivalent to avoiding CVD. ... Diabetic subjects without cardiovascular disease have a fatal stroke ...
    (sci.med.cardiology)