<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stumbling upon Security Issues</title>
	<atom:link href="http://www.spylogic.net/2008/06/stumbling-upon-security-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/</link>
	<description></description>
	<lastBuildDate>Sun, 18 Sep 2011 21:48:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tyler</title>
		<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/comment-page-1/#comment-55</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Wed, 04 Jun 2008 11:32:08 +0000</pubDate>
		<guid isPermaLink="false">#comment-55</guid>
		<description>The same as you I would have done the same thing - reporting it to the owners.  It always surprises me of this when I hear about them even though it shouldn&#039;t.  Good find...hopefully they&#039;ll fix it.</description>
		<content:encoded><![CDATA[<p>The same as you I would have done the same thing &#8211; reporting it to the owners.  It always surprises me of this when I hear about them even though it shouldn&#8217;t.  Good find&#8230;hopefully they&#8217;ll fix it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/comment-page-1/#comment-53</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 04 Jun 2008 00:24:32 +0000</pubDate>
		<guid isPermaLink="false">#comment-53</guid>
		<description>Thanks for the comments.  Yes, war dialing sometimes gets overlooked...and can still be the easy way in to a network.  Seems like most new HVAC installations are Internet enabled with the default security settings of &quot;no security&quot;. ;-)</description>
		<content:encoded><![CDATA[<p>Thanks for the comments.  Yes, war dialing sometimes gets overlooked&#8230;and can still be the easy way in to a network.  Seems like most new HVAC installations are Internet enabled with the default security settings of &quot;no security&quot;. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/comment-page-1/#comment-52</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 02 Jun 2008 23:33:50 +0000</pubDate>
		<guid isPermaLink="false">#comment-52</guid>
		<description>Sadly I have seen a couple HVAC systems connected to the Internet, in most cases the manufacture or vendor required the company to do this so they could &quot;remotely administer the system.&quot;&lt;br /&gt;
&lt;br /&gt;
Systems like this are the primary reason I still recommend people war dial their exchanges.  More often than not when war dialing a large company I will discover an HVAC or elevator control system connect to a modem.  Tip - If you come across a modem set to 300, 1200 or 2400 baud it is probably a control system of some sort.  And of course it goes without saying you should only wardail ranges you are authorized to scan.&lt;br /&gt;
&lt;br /&gt;
What would I of done in the scenario above?  Probably the same actions you took and try to contact the site administrator.</description>
		<content:encoded><![CDATA[<p>Sadly I have seen a couple HVAC systems connected to the Internet, in most cases the manufacture or vendor required the company to do this so they could &quot;remotely administer the system.&quot;</p>
<p>Systems like this are the primary reason I still recommend people war dial their exchanges.  More often than not when war dialing a large company I will discover an HVAC or elevator control system connect to a modem.  Tip &#8211; If you come across a modem set to 300, 1200 or 2400 baud it is probably a control system of some sort.  And of course it goes without saying you should only wardail ranges you are authorized to scan.</p>
<p>What would I of done in the scenario above?  Probably the same actions you took and try to contact the site administrator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quzart</title>
		<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/comment-page-1/#comment-51</link>
		<dc:creator>Quzart</dc:creator>
		<pubDate>Mon, 02 Jun 2008 15:21:11 +0000</pubDate>
		<guid isPermaLink="false">#comment-51</guid>
		<description>Hmmm, I think I would  &#039;leave a present&#039;, like putting a textfile on the server, or changing something that doesn&#039;t mess up the whole system. Then I would email them that something isn&#039;t right and let them know what I changed so they know it is serious.</description>
		<content:encoded><![CDATA[<p>Hmmm, I think I would  &#8216;leave a present&#8217;, like putting a textfile on the server, or changing something that doesn&#8217;t mess up the whole system. Then I would email them that something isn&#8217;t right and let them know what I changed so they know it is serious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tarek</title>
		<link>http://www.spylogic.net/2008/06/stumbling-upon-security-issues/comment-page-1/#comment-50</link>
		<dc:creator>Tarek</dc:creator>
		<pubDate>Mon, 02 Jun 2008 10:49:43 +0000</pubDate>
		<guid isPermaLink="false">#comment-50</guid>
		<description>It depends, I sometimes prefer to put a Black Hat when I am in the Evil and Wanna-Have-Some Phun mood, but I guess most of the time I will prefer putting a White Hat on instead</description>
		<content:encoded><![CDATA[<p>It depends, I sometimes prefer to put a Black Hat when I am in the Evil and Wanna-Have-Some Phun mood, but I guess most of the time I will prefer putting a White Hat on instead</p>
]]></content:encoded>
	</item>
</channel>
</rss>

