Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom EspaƱol


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Training:


Offensive Countermeasures: Defensive Techniques That Actually Work:


SANSFIRE 2012 (July 7-8)


Blackhat 2012 (July 21-22 & 23-24)


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


Visit PaulDotCom Insider


A bad day in IT...

| | Comments (3)

A bad day in IT is when you discover that one of your servers has been compromised. A really bad day is when you realize:

"...the compromised machine was one of the state government's smaller servers. But it was used by the Division of Motor Vehicles for processing payments by credit or debit card. And by the state Liquor Commission as a backup system for processing sales at state-owned liquor stores. And for collecting donations to support the New Hampshire Veterans Home."

It gets worse when you realize that:

"They knew they were stretched too thin on security, which is why they were testing an automated intrusion-detection tool. That's how the Cain & Abel program, which can capture credit card numbers, was discovered."

Yes, a bad day is when you find Cain & Abel installed on a server that houses credit card data for three different organizations. And I thought my week was rough :)

.com

Full Story

3 Comments

jeez..and i thought i was having a bad day as well..

chasing out attackers and scanners all day...but i know it, my week will get worse, thank god for next week!

Hey, I am enjoying your Podcast. Kudos to all. Is the answer to the episode 16 question:

no ip directed-broadcast

Why would someone wants to install Cain & Abel to keep a hand on a compromised system? There are so much better options to accomplish this.. what do you think?

But still.. it would be a disaster finding this! :)

Keep on the good work with your podcast. I enjoy it a lot!