Many chiefs, few little indians and a packet sniffer

Peon

Expert Member
Joined
Sep 28, 2006
Messages
3,839
Reaction score
1,127
Location
In my burrow
Fellow Admins

Just as textbooks teach one all about the following. Have a SMME client 25 PC network. However instead of 1 boss there are about 10 bosses and they are all equal and bought into the business/building etc,etc.

The mistrust and paranoia is extreme. A claim has been made emails are being read by other 'chiefs'. On the domain CP i have checked no forwarding is going on. I will change all the passwords and setup SSL connections to server from now on.

The same person who claims that emails are being read believes one of the 'chiefs' is paying for outside black hat help in reading other peoples stuff. Sure enough the easiest is Cain + MetaSploit in such a situation. However if there is a outside influence how can I catch or identify the guilty party???? ARP poisoning can be traced but chances are good he/she would spoof MAC address.

Also Active Directory and strict digital comms is out of the question as each 'chief' wants to do their own thing but still be on the network. I need to lock down everything and go on the offense. Or their paranoia of each other is infecting me :P

Meditating on my next move. Ideas anyone?
 
Sorry I read the thread title and assumed it was a post about our government. My apologies, I'm leaving now...:p
 
DJ: Punishment will be donating some of your post count towards me thank you.....
 
Depends on how good this black hat is. If he/she is really good, they would be spoofing through a man-in-the-middle attack. Open Gmail through tor, set new tor identity, open gmail again. If the IPs in the gmail logs haven't changed, you've got a man in the middle (make sure the exit nodes on the tor connections are different).

If this black hat is not so good, and they're just sniffing, they can't decrypt any of the modern TLS/SSL protocols since they use Diffie-Hellman key exchange which allows for secure key exchange in environments where the medium is considered compromised from the start.
 
Im also thinking TLS/SSL sessions on outgoing/incoming with new passwords. Also perhaps a dose of reality might help with this lot.
 
Regardless of what you do that business won't be around for long. That much paranoia among business partners isn't sustainable. Also, I bet this is a law firm.

No idea how you'd catch the guilty party. You don't know what your looking for, how its done or by whom. The only time *that* is considered a viable start to an investigation is if its supposed to be a witch hunt.

The crucial part I'd investigate is whether there is any solid proof that emails were read. Some people are just scary good at deducing other people's thinking. That combined with people who get a fright every time they see their own shadow leads to BS like this: Mysterious shady figures being possibly maybe allegedly paid by an unknown party to perform black magic of an unknown nature.

Also maybe announce that you've added additional logging for good measure. Can't really hurt (esp if you actually do so).
 
Regardless of what you do that business won't be around for long. That much paranoia among business partners isn't sustainable.

I agree.

With regards to OP, there is nothing you can do to make this client happy other than mediate. It does not matter if you have implement the most secure solution available to them, there will always be doubt. If mediation is unsucessfull, you will eventually lose the client to someone else, or the business collapses.

This puts you as their technology 'provider/partner/what ever' in a difficult position in recommending mediation, as this could be seen as outside meddling in company affairs. I would tread very lightly and be mindfull of what you discuss with the client.

Best of luck!
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X