Engadget

The Years Biggest Security Breach

 tháng 8 23, 2009     Hacking     No comments   

At last i am back,
here, i just i get this news recent on yahoo,about this years biggest data breach,its totally cool you should check it out.

the hacker used WARDRIVIND  to for primary breach,
and then used  SQL injection 
After reading i was totaly impressed about that hacker,

you must read

"Taylor Buley, Forbes.com



The U.S. Department of Justice's indictment of Albert Gonzalez on Monday seems to have all the elements of a Hollywood crime drama: A hacker gains access to millions of credit and debit card numbers and has the power to take down a nation. Too bad for Tinseltown, the attack itself was about as sexy and a pile of routers.

According to the indictment, Gonzalez, 28, gained a foothold into the systems of credit card processors such as Heartland Payment Systems and retailers like OfficeMax, Barnes & Noble and TJX Cos. using an amateur hacking technique called "wardriving," which uses wireless access points to find vulnerable networks from which to launch attacks. Once connected to those private networks, Gonzalez used a well-known technique called "SQL injection" to trick Web applications into forking over private information that gave him deeper access into networks. Even though it sounds complicated, techies liken this kind of hack to simply turning the front doorknob to get into a house.
In the seven-layer Open System Interconnection model, a popular reference guide for securing a network software stack, the application layer is at the top. SQL injection is a Web-based attack that happens on this surface level. Securing the application layer is entry-level security stuff, which raises the question of why so many credit card handlers were vulnerable in the first place.


They certainly shouldn't have been vulnerable, says Kurt Roemer, chief security strategist of Citrix Systems. Citrix is on the board of advisers for the Payment Card Industry (PCI) security standards council, an industry effort for hardening the security systems of businesses that handle credit cards.



Roemer says businesses need to use either a Web application scanner or Web application firewall to guard against


SQL injections. A Web application scanner likely would have likely caught the SQL injection vulnerabilities Gonzalez exploited. If it didn't, an application firewall probably would have isolated the attacker from gaining access to other parts of the compromised networks.
"PCI specifically calls this out," Roemer says. "The way these guys got hacked there's no way they would have
satisfied" those standards.
The PCI rules also try to mitigate the threats of wardriving. Earlier this year, the PCI standards body called for the
phase-out of any wireless networks using WEP encryption, a digital lock that takes only a couple of minutes to break.
Though the way Gonzalez broke into systems is hardly the work of a criminal mastermind, Roemer says he's impressed by how Gonzalez and his co-conspirators were able to use relatively simple means to gain powerfully damaging access.
"The criminals would rather have something that's pretty easy and gets them the maximum amount of data," he says. "I'm just amazed at how they profiled all these companies and actually had a complete attack methodology."
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Gửi email bài đăng nàyBlogThis!Chia sẻ lên XChia sẻ lên Facebook
Bài đăng Mới hơn Bài đăng Cũ hơn Trang chủ

0 nhận xét:

Đăng nhận xét

Popular Posts

  • Proper use of English could get a virus past security
    “ Hackers evade most existing antivirus protection by hiding malicious code in texts, according to security researchers. ”
  • How to Rename Recycle Bin
    You can change the name of Recycle Bin Desktop Icon . 1-Click Start menu > Run > and type “regedit” (without quotes), to ru...
  • New BIOS Virus Which Can Make Your Anti-Virus Useless
    Hackers Have once again launched a Root kit Virus which loads directly into the BIOS memory of the computer and makes it prone . W...
  • Should You Use Hubitat to Automate Your Smarthome?
    The first step in building a smarthome is often choosing a hub, and there are many options. Hubitat is a unique cloud-independent hub. It...
  • 35+ Nokia Cheat Codes
    Nokia is a cell phone marketing company which is currently comes in world top rates mobile phones. Now its obvious that a company like No...
  • What’s the Difference Between Canon’s Regular and L-Series Lenses and Which Should You Buy
    Canon sells regular and L-series lenses (the "L" stands for luxury). While the lenses may have similar specs, you can usually exce...
  • Instructions to earn $ 10 / day to get Amazon Gift Card, Paypal
    You follow the steps below as well as for your Ref, please comment on how to make and receive money. The sponsor of this site is also Am...
  • Autodesk 3ds Max 2017 full + KeyGen - Professional 3D graphics
    Autodesk 3ds Max, formerly 3D Studio, then 3D Studio Max is a professional 3D graphics program for 3D animation, models, games and i...
  • INTRODUCTION AND GUIDANCE TO REGISTER VPS IN VULTR
    I. REGISTER VPS SERVER VULTR First we access the homepage of Vultr. Create a VPS account Here you need to enter email information to create ...
  • Download Adobe Photoshop PTS CS6 Full + Installation Guide
    As a designer, a photographer, or just a photo-editing enthusiast, no one is aware of adobe photoshop.  Adobe Photoshop CS6 was born long ag...

The Best Penlights for Pocket-Friendly Illumination

Your phone may have a built-in flashlight, but do you really feel comfortable propping your phone inside of your car's engine bay, or ag...

Được tạo bởi Blogger.

Copyright © Engadget | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates