<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; Corporate</title> <atom:link href="http://m32consulting.com/category/security/corporate/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Tue, 13 Mar 2012 21:54:58 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Critical Flaw In RDP Exposes ALL Versions of Windows To Remote Code Execution Risk</title><link>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk</link> <comments>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/#comments</comments> <pubDate>Tue, 13 Mar 2012 21:54:58 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[black tuesday]]></category> <category><![CDATA[code]]></category> <category><![CDATA[code execution]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[isc]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[network]]></category> <category><![CDATA[RDP]]></category> <category><![CDATA[rdp protocol]]></category> <category><![CDATA[release]]></category> <category><![CDATA[remote desktop]]></category> <category><![CDATA[risk]]></category> <category><![CDATA[SANS]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[worm]]></category> <category><![CDATA[Wormable]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=245</guid> <description><![CDATA[An EXTREMELY critical flaw in Microsoft&#8217;s RDP protocol (Remote Desktop) has been discovered and disclosed by Microsoft today. This vulnerability is about as critical as they get; especially for corporate customers. In short, any attacker who sends specially crafted code to any computer running Microsoft Windows that hat has Remote Desktop enabled can essentially take control of [...]]]></description> <content:encoded><![CDATA[<div
class="wp-caption alignright" style="width: 266px"><a
href="http://en.wikipedia.org/wiki/File:Remote_desktop_connection_icon.PNG" target="_blank"><img
class="zemanta-img-inserted zemanta-img-configured" title="Remote Desktop Connection Icon" src="http://upload.wikimedia.org/wikipedia/en/b/b0/Remote_desktop_connection_icon.PNG" alt="Remote Desktop Connection Icon" width="256" height="256" /></a><p
class="wp-caption-text">Image via Wikipedia</p></div><p>An <strong>EXTREMELY </strong>critical flaw in <a
class="zem_slink" title="Microsoft" href="http://www.forbes.com/companies/microsoft/" rel="forbes" target="_blank">Microsoft&#8217;s</a> <a
class="zem_slink" title="Remote Desktop Protocol" href="http://en.wikipedia.org/wiki/Remote_Desktop_Protocol" rel="wikipedia" target="_blank">RDP</a> protocol (<a
class="zem_slink" title="Remote Desktop Services" href="http://www.microsoft.com/windowsserver2008/en/us/rds-product-home.aspx" rel="homepage" target="_blank">Remote Desktop</a>) has been discovered and disclosed by Microsoft today. This vulnerability is about as critical as they get; especially for corporate customers. In short, any attacker who sends specially crafted code to any computer running Microsoft <a
class="zem_slink" title="Windows" href="http://www.microsoft.com/WINDOWS" rel="homepage" target="_blank">Windows</a> that hat has Remote Desktop enabled can essentially take control of it. Microsoft has already released an article about it <a
title="Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387)" href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020" target="_blank">here</a> (<a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020">MS12-020</a>).</p><p>All users are advised to update their machines as soon as possible, as this nasty exploit has the potential to become very nasty, very fast.</p><p>&nbsp;</p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.networkworld.com/news/2012/030912-microsoft-to-patch-windows-bug-257141.html?source=nww_rss" target="_blank">Microsoft to patch Windows bug called &#8216;Holy Grail&#8217; by one researcher</a> (networkworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://support.microsoft.com/kb/2671387" target="_blank">KB 2671387</a> (support.microsoft.com)</li><li
class="zemanta-article-ul-li"><a
href="http://isc.sans.edu/diary.html?storyid=12775&amp;rss" target="_blank">March 2012 Microsoft Black Tuesday, (Tue, Mar 13th)</a> (isc.sans.edu)</li><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/businesscenter/article/251760/microsoft_issues_urgent_patch_for_wormable_rdp_vulnerability.html" target="_blank">Microsoft Issues Urgent Patch for &#8216;Wormable&#8217; RDP Vulnerability</a> (pcworld.com)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=90b6d9d2-10a7-4c47-a2a0-e7ebc640d755" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a
href="http://m32consulting.com/tag/black-tuesday/" title="black tuesday" rel="tag">black tuesday</a>, <a
href="http://m32consulting.com/tag/code/" title="code" rel="tag">code</a>, <a
href="http://m32consulting.com/tag/code-execution/" title="code execution" rel="tag">code execution</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/isc/" title="isc" rel="tag">isc</a>, <a
href="http://m32consulting.com/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/rdp/" title="RDP" rel="tag">RDP</a>, <a
href="http://m32consulting.com/tag/rdp-protocol/" title="rdp protocol" rel="tag">rdp protocol</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/remote-desktop/" title="remote desktop" rel="tag">remote desktop</a>, <a
href="http://m32consulting.com/tag/risk/" title="risk" rel="tag">risk</a>, <a
href="http://m32consulting.com/tag/sans/" title="SANS" rel="tag">SANS</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a
href="http://m32consulting.com/tag/windows/" title="Windows" rel="tag">Windows</a>, <a
href="http://m32consulting.com/tag/worm/" title="worm" rel="tag">worm</a>, <a
href="http://m32consulting.com/tag/wormable/" title="Wormable" rel="tag">Wormable</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>LulzSec Hacks Sony&#8230;Again&#8230;And Scores PSN Source Code</title><link>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lulzsec-hacks-sony-again-and-scores-psn-source-code</link> <comments>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/#comments</comments> <pubDate>Tue, 07 Jun 2011 00:56:38 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Corporate]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[ACHIEVEMENT]]></category> <category><![CDATA[Cell]]></category> <category><![CDATA[floating point]]></category> <category><![CDATA[geohotz]]></category> <category><![CDATA[George Hotz]]></category> <category><![CDATA[IBM]]></category> <category><![CDATA[ibm cell processor]]></category> <category><![CDATA[legal assault]]></category> <category><![CDATA[lulz]]></category> <category><![CDATA[LulzSec]]></category> <category><![CDATA[OtherOS]]></category> <category><![CDATA[pbs]]></category> <category><![CDATA[playstation 3]]></category> <category><![CDATA[point performance]]></category> <category><![CDATA[ps3]]></category> <category><![CDATA[psn]]></category> <category><![CDATA[release]]></category> <category><![CDATA[sony hq]]></category> <category><![CDATA[Source]]></category> <category><![CDATA[supercomputer]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=201</guid> <description><![CDATA[LulzSec, also known as Lulz Security, which has become infamous for their past and more recent hacks including PBS and Sony, has hacked Sony HQ&#8230;again. This time they scored around 54 megabytes of the developer&#8217;s source code to the PlayStation Network. What does it mean? Hold on to your butts. The group published a press [...]]]></description> <content:encoded><![CDATA[<p>LulzSec, also known as Lulz Security, which has become infamous for their past and more recent hacks including PBS and Sony, has hacked Sony HQ&#8230;again. This time they scored around <a
title="LulzSec Claims Another Sony Hack" href="http://www.wired.com/threatlevel/2011/06/lulzsec-sony-again/" target="_blank">54 megabytes of the developer&#8217;s source code to the PlayStation Network</a>. What does it mean? Hold on to your butts.<a
title="ACHIEVEMENT UNLOCKED: HACK SONY 6 TIMES!" href="http://lulzsecurity.com/releases/sownage_2_press_release.txt" target="_blank" class="broken_link"> The group published a press release detailing the hack</a> while simultaneously releasing all stolen code to the public through various channels. The implications of this are enormous, as Sony&#8217;s PSN is now wide-open to any exploits found in the previously obfuscated code. Expect Sony&#8217;s problems to continue for a while.</p><p>The targeting of Sony stems from their<a
title="Sony Settles PlayStation Hacking Lawsuit" href="http://www.wired.com/threatlevel/2011/04/sony-settles-ps3-lawsuit/" target="_blank"> legal assault on George Hotz, otherwise known as GeoHotz,</a> who had found and published a way to circumvent protection mechanisms on the PlayStation 3. This was a big deal after the company removed the &#8220;Other OS&#8221; feature through a firmware update that allowed the installation of Linux on the console to use the powerful IBM Cell processor that powers the machine. The PS3 has been known to be used by organizations like the US Air Force in supercomputer clusters due to the Cell processor&#8217;s vastly superior floating-point performance which is highly desired for processing large amounts of data for modeling.</p><p>Stay tuned&#8230;</p>Tags: <a
href="http://m32consulting.com/tag/achievement/" title="ACHIEVEMENT" rel="tag">ACHIEVEMENT</a>, <a
href="http://m32consulting.com/tag/cell/" title="Cell" rel="tag">Cell</a>, <a
href="http://m32consulting.com/tag/floating-point/" title="floating point" rel="tag">floating point</a>, <a
href="http://m32consulting.com/tag/geohotz/" title="geohotz" rel="tag">geohotz</a>, <a
href="http://m32consulting.com/tag/george-hotz/" title="George Hotz" rel="tag">George Hotz</a>, <a
href="http://m32consulting.com/tag/ibm/" title="IBM" rel="tag">IBM</a>, <a
href="http://m32consulting.com/tag/ibm-cell-processor/" title="ibm cell processor" rel="tag">ibm cell processor</a>, <a
href="http://m32consulting.com/tag/legal-assault/" title="legal assault" rel="tag">legal assault</a>, <a
href="http://m32consulting.com/tag/lulz/" title="lulz" rel="tag">lulz</a>, <a
href="http://m32consulting.com/tag/lulzsec/" title="LulzSec" rel="tag">LulzSec</a>, <a
href="http://m32consulting.com/tag/otheros/" title="OtherOS" rel="tag">OtherOS</a>, <a
href="http://m32consulting.com/tag/pbs/" title="pbs" rel="tag">pbs</a>, <a
href="http://m32consulting.com/tag/playstation-3/" title="playstation 3" rel="tag">playstation 3</a>, <a
href="http://m32consulting.com/tag/point-performance/" title="point performance" rel="tag">point performance</a>, <a
href="http://m32consulting.com/tag/ps3/" title="ps3" rel="tag">ps3</a>, <a
href="http://m32consulting.com/tag/psn/" title="psn" rel="tag">psn</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/sony-hq/" title="sony hq" rel="tag">sony hq</a>, <a
href="http://m32consulting.com/tag/source/" title="Source" rel="tag">Source</a>, <a
href="http://m32consulting.com/tag/supercomputer/" title="supercomputer" rel="tag">supercomputer</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>LNK Zero-Day Exploit: Siemens WinCC SCADA systems targeted</title><link>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ln-zero-day-exploit-siemens-wincc-scada-systems-targeted</link> <comments>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/#comments</comments> <pubDate>Mon, 26 Jul 2010 05:20:59 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[2WSXcder]]></category> <category><![CDATA[Chymine]]></category> <category><![CDATA[Ivanlef]]></category> <category><![CDATA[july 14]]></category> <category><![CDATA[LNK]]></category> <category><![CDATA[SCADA]]></category> <category><![CDATA[Siemens]]></category> <category><![CDATA[siemens wincc]]></category> <category><![CDATA[WinCC]]></category> <category><![CDATA[zero day]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=104</guid> <description><![CDATA[It turns out that the original targets for the highly-dangerous Windows Shell LNK Zero-Day Exploit were Siemens WinCC SCADA systems with hard-coded credentials used in large infrastructure systems like factories and power grids. Once the attacker had successfully executed the LNK exploit, they accessed the Siemens WinCC program and extracted sensitive data from the database [...]]]></description> <content:encoded><![CDATA[<p>It turns out that the original targets for the highly-dangerous Windows Shell LNK Zero-Day Exploit were Siemens WinCC SCADA systems with hard-coded credentials used in large infrastructure systems like factories and power grids. Once the attacker had successfully executed the LNK exploit, they accessed the Siemens WinCC program and extracted sensitive data from the database the software uses. It is highly suspected that the exploit was explicitly used for espionage toward Iran and Indonesia at the very least, but by whom or what exact purpose is not clear. What is clear is that the Siemens WinCC software was targeted. The Siemens WinCC software has what is considered one of the top vulnerabilities in software according to CWE/SANS, which is the use of fixed-credentials. This type of vulnerability has been publicly disclosed for over two years and the password to this specific software (2WSXcder) has been publicly known since <a
href="http://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&amp;16127&amp;Language=en&amp;PageIndex=3" target="_blank">at least</a> <a
href="http://iadt.siemens.ru/forum/viewtopic.php?p=2974&amp;sid=58cedcf3a0fc7a0b6c61c7bc46530928" target="_blank">2008</a>. Siemens was made aware of the issue on July 14 and shortly started to asses the problem and notify customers.</p><p>In the meantime, a security researcher known as Ivanlef0u has <a
href="http://www.ivanlef0u.tuxfamily.org/?p=411" target="_blank">posted a proof-of-concept of the exploit</a> (site is in French), while Win32/TrojanDownloader.Chymine.A and Win32/Autorun.VB.RP are in the wild already actively actively using this exploit according to ESET. Expect to see this exploit to be a bit prolific due to its new and unique nature combined with the relative ineffectiveness of detection/removal systems thus far.</p><p><a
href="http://www.wired.com/threatlevel/2010/07/siemens-scada/" target="_blank">Wired Article on password&#8217;s public exposure</a></p><p><a
href="http://blog.eset.com/2010/07/22/new-malicious-lnks-here-we-go" target="_blank">ESET Blog on new Zero-day exploit in the wild</a></p>Tags: <a
href="http://m32consulting.com/tag/2wsxcder/" title="2WSXcder" rel="tag">2WSXcder</a>, <a
href="http://m32consulting.com/tag/chymine/" title="Chymine" rel="tag">Chymine</a>, <a
href="http://m32consulting.com/tag/ivanlef/" title="Ivanlef" rel="tag">Ivanlef</a>, <a
href="http://m32consulting.com/tag/july-14/" title="july 14" rel="tag">july 14</a>, <a
href="http://m32consulting.com/tag/lnk/" title="LNK" rel="tag">LNK</a>, <a
href="http://m32consulting.com/tag/scada/" title="SCADA" rel="tag">SCADA</a>, <a
href="http://m32consulting.com/tag/siemens/" title="Siemens" rel="tag">Siemens</a>, <a
href="http://m32consulting.com/tag/siemens-wincc/" title="siemens wincc" rel="tag">siemens wincc</a>, <a
href="http://m32consulting.com/tag/wincc/" title="WinCC" rel="tag">WinCC</a>, <a
href="http://m32consulting.com/tag/zero-day/" title="zero day" rel="tag">zero day</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Critical Microsoft Vista/2008/Windows 7 Zero-day Remote BSOD Found</title><link>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found</link> <comments>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/#comments</comments> <pubDate>Wed, 09 Sep 2009 00:24:06 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[ampersand]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[blue screen of death]]></category> <category><![CDATA[BSOD]]></category> <category><![CDATA[Laurent Gaffié]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft vista]]></category> <category><![CDATA[microsoft windows vista]]></category> <category><![CDATA[OOB]]></category> <category><![CDATA[process id]]></category> <category><![CDATA[proof of concept]]></category> <category><![CDATA[SMB]]></category> <category><![CDATA[throwback]]></category> <category><![CDATA[versions of windows vista]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[zero day]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=41</guid> <description><![CDATA[Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down [...]]]></description> <content:encoded><![CDATA[<p>Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down with a simple ampersand. Leave it up to Microsoft to do it all again more than a decade later.</p><p>The SMB 2.0 driver in x86 and x64 versions of Windows Vista, Server 2008, and Windows 7 are all one in the same. When sent the &#8220;&amp;&#8221; character in the &#8220;Process ID High&#8221; SMB header, the process pagefaults and brings us the beloved Blue Screen of Death we&#8217;ve all come to know and love.</p><p><a
href="http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html" target="_blank">Credit goes to Laurent Gaffié and you can find the Proof-of-Concept on his blog.</a></p>Tags: <a
href="http://m32consulting.com/tag/ampersand/" title="ampersand" rel="tag">ampersand</a>, <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a
href="http://m32consulting.com/tag/blue-screen-of-death/" title="blue screen of death" rel="tag">blue screen of death</a>, <a
href="http://m32consulting.com/tag/bsod/" title="BSOD" rel="tag">BSOD</a>, <a
href="http://m32consulting.com/tag/laurent-gaffie/" title="Laurent Gaffié" rel="tag">Laurent Gaffié</a>, <a
href="http://m32consulting.com/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a
href="http://m32consulting.com/tag/microsoft-vista/" title="microsoft vista" rel="tag">microsoft vista</a>, <a
href="http://m32consulting.com/tag/microsoft-windows-vista/" title="microsoft windows vista" rel="tag">microsoft windows vista</a>, <a
href="http://m32consulting.com/tag/oob/" title="OOB" rel="tag">OOB</a>, <a
href="http://m32consulting.com/tag/process-id/" title="process id" rel="tag">process id</a>, <a
href="http://m32consulting.com/tag/proof-of-concept/" title="proof of concept" rel="tag">proof of concept</a>, <a
href="http://m32consulting.com/tag/smb/" title="SMB" rel="tag">SMB</a>, <a
href="http://m32consulting.com/tag/throwback/" title="throwback" rel="tag">throwback</a>, <a
href="http://m32consulting.com/tag/versions-of-windows-vista/" title="versions of windows vista" rel="tag">versions of windows vista</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a
href="http://m32consulting.com/tag/zero-day/" title="zero day" rel="tag">zero day</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>T-Mobile USA confirms massive data breach</title><link>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=t-mobile-usa-confirms-massive-data-breach</link> <comments>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/#comments</comments> <pubDate>Thu, 11 Jun 2009 02:02:57 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Corporate]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Firewalls]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[black hat]]></category> <category><![CDATA[breach]]></category> <category><![CDATA[check point]]></category> <category><![CDATA[check point firewall]]></category> <category><![CDATA[checkpoint]]></category> <category><![CDATA[corporate document]]></category> <category><![CDATA[cybersecurity]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[GSM]]></category> <category><![CDATA[high visibility]]></category> <category><![CDATA[internal ip addresses]]></category> <category><![CDATA[massive data]]></category> <category><![CDATA[mobile hack]]></category> <category><![CDATA[network]]></category> <category><![CDATA[network security]]></category> <category><![CDATA[partial descriptions]]></category> <category><![CDATA[Pwnmobile]]></category> <category><![CDATA[t-mobile]]></category> <category><![CDATA[usa today]]></category> <category><![CDATA[user data]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=20</guid> <description><![CDATA[The network security guys at T-Mobile USA probably breached their underpants after some black hat or group of black hats named &#8220;Pwnmobile&#8221; posted on seclists.org a sizeable list of internal hostnames, OSes,  partial descriptions, internal IP addresses, and facilities relating to the back-end of T-Mobile&#8217;s customer management and services network. At first, T-Mobile tried to [...]]]></description> <content:encoded><![CDATA[<p>The network security guys at T-Mobile USA probably breached their underpants after some black hat or group of black hats named &#8220;Pwnmobile&#8221; posted on <a
title="insecure.org's mailing list" href="http://seclists.org/fulldisclosure/2009/Jun/62" target="_blank">seclists.org</a> a sizeable list of internal hostnames, OSes,  partial descriptions, internal IP addresses, and facilities relating to the back-end of T-Mobile&#8217;s customer management and services network.</p><p>At first, T-Mobile tried to say it was just a list pulled from a corporate document; but now the company is admitting that it was, in fact a major security breach <a
title="T-Mobile confirms company records taken" href="http://content.usatoday.com/communities/technologylive/post/2009/06/67913035/1" target="_blank">according to a USA Today Blog</a> and are not disclosing how much data was taken. Odds are, if whoever managed to get this far, a very sizeable amount of data was captured. The person who made the posting mentioned that they had tried to sell the information to competitors, but they were not taken seriously.</p><p>On a slightly related note, the posting related the T-Mobile hack with Check Point. Does this mean a perimeter Check Point firewall was either hacked or exploited to gain access to this network? Only further elaboration from Pwnmobile, T-Mobile, or an insider can say. There have been several recently published high-visibility Check Point exploits and perhaps they were used in the hack.</p>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/black-hat/" title="black hat" rel="tag">black hat</a>, <a
href="http://m32consulting.com/tag/breach/" title="breach" rel="tag">breach</a>, <a
href="http://m32consulting.com/tag/check-point/" title="check point" rel="tag">check point</a>, <a
href="http://m32consulting.com/tag/check-point-firewall/" title="check point firewall" rel="tag">check point firewall</a>, <a
href="http://m32consulting.com/tag/checkpoint/" title="checkpoint" rel="tag">checkpoint</a>, <a
href="http://m32consulting.com/tag/corporate-document/" title="corporate document" rel="tag">corporate document</a>, <a
href="http://m32consulting.com/tag/cybersecurity/" title="cybersecurity" rel="tag">cybersecurity</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/gsm/" title="GSM" rel="tag">GSM</a>, <a
href="http://m32consulting.com/tag/high-visibility/" title="high visibility" rel="tag">high visibility</a>, <a
href="http://m32consulting.com/tag/internal-ip-addresses/" title="internal ip addresses" rel="tag">internal ip addresses</a>, <a
href="http://m32consulting.com/tag/massive-data/" title="massive data" rel="tag">massive data</a>, <a
href="http://m32consulting.com/tag/mobile-hack/" title="mobile hack" rel="tag">mobile hack</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/network-security/" title="network security" rel="tag">network security</a>, <a
href="http://m32consulting.com/tag/partial-descriptions/" title="partial descriptions" rel="tag">partial descriptions</a>, <a
href="http://m32consulting.com/tag/pwnmobile/" title="Pwnmobile" rel="tag">Pwnmobile</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/t-mobile/" title="t-mobile" rel="tag">t-mobile</a>, <a
href="http://m32consulting.com/tag/usa-today/" title="usa today" rel="tag">usa today</a>, <a
href="http://m32consulting.com/tag/user-data/" title="user data" rel="tag">user data</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 23/27 queries in 0.033 seconds using disk: basic
Object Caching 3251/3252 objects using disk: basic

Served from: m32consulting.com @ 2012-05-20 22:46:18 -->
