IT-Analysis.com
IT-Analysis.com Logo
Enterprise SME Business Issues Technology Services Channels
Module Header
David TebbuttTeblog
David Tebbutt
19th November - Collaboration: the old way. Why not?
Martin BanksBanks Statement
Martin Banks
18th November - This Cloud has a silver lining
Peter AbrahamsAbrahams Accessibility
Peter Abrahams
18th November - Major new accessibility features in Firefox 3.0.4
Martin BanksBanks Statement
Martin Banks
17th November - Psychology of data ownership may be changing at last
Tony LockFreeform Comment
Tony Lock
16th November - Clouds yet to fill the IT skies
Module Header
Q. Which database do you use most?
 
  • addtomyyahoo4
  • Subscribe in NewsGator Online
  • Add to My AOL
  • Subscribe with Bloglines
  • Add to netvibes
  • Add to Google
Blogs > Nigel Stanley
Support Forums, Hackers and Security
Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 16th October 2006
Copyright Bloor Research © 2006
Logo for Bloor Research

Ahh, the internet. A most amazing place.

One of the most compelling uses for the internet must be for technical support. After all, the internet is the place where cool techies hang out and provides an ideal market place, free or otherwise, for them to demonstrate their expertise.

I was doing some research the other day (actually battling to configure a W2K laptop for broadband access) and needed some assistance with a setting. I simply did a search on Google and found the answer to my problem. On that journey I visited a couple of support forums and noticed something very interesting. When you have a support problem you need to give out a load of information—OS type and version, software installed, patches, nature of problem, network settings etc.—plus you need to give a return email address.

At this point corporate security bods need to be paying attention. Are they aware that some of their techies may be giving away vital information of great interest to hackers on these forums? Yep, you've got it. By taking all this data kindly provided by your tech support guys hackers are able to form a clearer picture of what IT you are running and fine tune their targeting plans.

If your people do use public forums for support, insist they use an email address that does not refer to their employer by name, just to be a little safer.

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

Advertisement



Published by: IT Analysis Communications Ltd.
T: +44 (0)203 051 5760 | F: +44 (0)870 345 9922
Email: