Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

beardednose
I rented one of those Do-It-Yourself carpet cleaners over the weekend. Because there were 2 others in line at the desk (who wanted something else), the clerk handed me the rental book and asked me to fill out my info and hand it back.

The book had about 10 pages of info on folks that had rented their machines lately..Name, address, driver's license #, birthdate, phone #, and in some cases, their VISA # and expiration. There were two renters per page and I was the second renter on the current page. I could have easily copied down the info on that page, or even better, pulled out the previous pages and stuffed them in my skirt pocket.

In addition, the book was just laying on the counter. It was inside a locked service counter area, but so what. I could have reached over the counter and grabbed it at the right moment.

Noting how sloppy they were with personal info, I wrote down my info somewhat incorrectly, assuming they would not double check (they didn't). [I didn't have time to go to another place; I had to clean my carpet for an upcoming event; besides, the next guy is probably just as bad].

After renting the machine, I tracked down the manager and explained my concerns (I told him GSO would DDOS his store website if he crossed me...ha ha). He was real nice and explained the book was supposed to be kept in the safe and the clerks were supposed to fill out the info after asking the renter all the Q's. He said he'd fix it.

When I returned the unit later, the manager processed the return, and found the book on the counter again (after the service desk for closed for the night!). He also said the clerk did what she did because their was a line and she wanted to get to the other folks. I explained that such behavior not only put his customers at risk, but also the company. He said he'd take care of it. I doubt anything will change.

Any comments? What other types of issues like this has anyone found recently?

p.s. As usual, the carpet was much cleaner except for the standard spots. Long live little children! laugh.gif
A2_
my roommate's girl is actually over here right now cleaning the living room carpet :/. could have taken the whole book and used all the info to card the manager 30 books on information security. or you could have employed the scare tactic, asking him if hed like his business' fuckup compared to the likes of lexis nexis', aol's, or citigroup's... seeing 'beardednose' talk about his/her skirt pocket is a little confusing, m or f?

BN says: will explain later; don't want to get off topic...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.