<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; t-mobile</title> <atom:link href="http://m32consulting.com/tag/t-mobile/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>T-Mobile USA confirms massive data breach</title><link>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=t-mobile-usa-confirms-massive-data-breach</link> <comments>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/#comments</comments> <pubDate>Thu, 11 Jun 2009 02:02:57 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Corporate]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Firewalls]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[black hat]]></category> <category><![CDATA[breach]]></category> <category><![CDATA[check point]]></category> <category><![CDATA[check point firewall]]></category> <category><![CDATA[checkpoint]]></category> <category><![CDATA[corporate document]]></category> <category><![CDATA[cybersecurity]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[GSM]]></category> <category><![CDATA[high visibility]]></category> <category><![CDATA[internal ip addresses]]></category> <category><![CDATA[massive data]]></category> <category><![CDATA[mobile hack]]></category> <category><![CDATA[network]]></category> <category><![CDATA[network security]]></category> <category><![CDATA[partial descriptions]]></category> <category><![CDATA[Pwnmobile]]></category> <category><![CDATA[t-mobile]]></category> <category><![CDATA[usa today]]></category> <category><![CDATA[user data]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=20</guid> <description><![CDATA[The network security guys at T-Mobile USA probably breached their underpants after some black hat or group of black hats named &#8220;Pwnmobile&#8221; posted on seclists.org a sizeable list of internal hostnames, OSes,  partial descriptions, internal IP addresses, and facilities relating to the back-end of T-Mobile&#8217;s customer management and services network. At first, T-Mobile tried to [...]]]></description> <content:encoded><![CDATA[<p>The network security guys at T-Mobile USA probably breached their underpants after some black hat or group of black hats named &#8220;Pwnmobile&#8221; posted on <a
title="insecure.org's mailing list" href="http://seclists.org/fulldisclosure/2009/Jun/62" target="_blank">seclists.org</a> a sizeable list of internal hostnames, OSes,  partial descriptions, internal IP addresses, and facilities relating to the back-end of T-Mobile&#8217;s customer management and services network.</p><p>At first, T-Mobile tried to say it was just a list pulled from a corporate document; but now the company is admitting that it was, in fact a major security breach <a
title="T-Mobile confirms company records taken" href="http://content.usatoday.com/communities/technologylive/post/2009/06/67913035/1" target="_blank">according to a USA Today Blog</a> and are not disclosing how much data was taken. Odds are, if whoever managed to get this far, a very sizeable amount of data was captured. The person who made the posting mentioned that they had tried to sell the information to competitors, but they were not taken seriously.</p><p>On a slightly related note, the posting related the T-Mobile hack with Check Point. Does this mean a perimeter Check Point firewall was either hacked or exploited to gain access to this network? Only further elaboration from Pwnmobile, T-Mobile, or an insider can say. There have been several recently published high-visibility Check Point exploits and perhaps they were used in the hack.</p>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/black-hat/" title="black hat" rel="tag">black hat</a>, <a
href="http://m32consulting.com/tag/breach/" title="breach" rel="tag">breach</a>, <a
href="http://m32consulting.com/tag/check-point/" title="check point" rel="tag">check point</a>, <a
href="http://m32consulting.com/tag/check-point-firewall/" title="check point firewall" rel="tag">check point firewall</a>, <a
href="http://m32consulting.com/tag/checkpoint/" title="checkpoint" rel="tag">checkpoint</a>, <a
href="http://m32consulting.com/tag/corporate-document/" title="corporate document" rel="tag">corporate document</a>, <a
href="http://m32consulting.com/tag/cybersecurity/" title="cybersecurity" rel="tag">cybersecurity</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/gsm/" title="GSM" rel="tag">GSM</a>, <a
href="http://m32consulting.com/tag/high-visibility/" title="high visibility" rel="tag">high visibility</a>, <a
href="http://m32consulting.com/tag/internal-ip-addresses/" title="internal ip addresses" rel="tag">internal ip addresses</a>, <a
href="http://m32consulting.com/tag/massive-data/" title="massive data" rel="tag">massive data</a>, <a
href="http://m32consulting.com/tag/mobile-hack/" title="mobile hack" rel="tag">mobile hack</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/network-security/" title="network security" rel="tag">network security</a>, <a
href="http://m32consulting.com/tag/partial-descriptions/" title="partial descriptions" rel="tag">partial descriptions</a>, <a
href="http://m32consulting.com/tag/pwnmobile/" title="Pwnmobile" rel="tag">Pwnmobile</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/t-mobile/" title="t-mobile" rel="tag">t-mobile</a>, <a
href="http://m32consulting.com/tag/usa-today/" title="usa today" rel="tag">usa today</a>, <a
href="http://m32consulting.com/tag/user-data/" title="user data" rel="tag">user data</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/06/t-mobile-usa-confirms-massive-data-breach/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 4/16 queries in 0.071 seconds using disk: basic
Object Caching 1114/1144 objects using disk: basic

Served from: m32consulting.com @ 2012-02-11 14:50:39 -->
