Chercher :
Newsletter :  


Revues :
- Presse
- Presse FR
- Vidéos
- Twitter
- Secuobs





Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- USBsploit
- Commentaires


Revue Presse:
- Tous
- Francophone
- Par mot clé
- Par site
- Le tagwall


Top bi-hebdo:
- Ensemble
- Articles
- Revue
- Videos
- Twitter
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Twitter :
- Tous
- Par mot clé
- Par compte
- Le tagwall


Commentaires :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS/XML :
- Articles
- Commentaires
- Revue
- Revue FR
- Videos
- Twitter


RSS SecuObs :
- sécurité
- exploit
- windows
- attaque
- outil
- réseau


RSS Revue :
- security
- microsoft
- windows
- hacker
- attack
- network


RSS Videos :
- curit
- security
- biomet
- metasploit
- biometric
- cking


RSS Twitter :
- security
- linux
- botnet
- attack
- metasploit
- cisco


RSS Comments :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS OPML :
- Français
- International











Revue de presse francophone :
- OVH, premier registrar à proposer les nouvelles extensions dans le respect de la loi sur la conservation des données
- Les Salons Cloud Computing World Expo et Solutions Data Center Management L'édition 2014, toujours plus...
- Etude 2014 Olfeo sur l'utilisation d'internet au bureau
- Appel à mobilisation nationale contre les écrans publicitaires numériques
- Riverbed présente SteelFusion
- Vigilance - OpenSSL injection de données via OPENSSL_NO_BUF_FREELIST, analysé le 14 04 2014
- Highlights from the SyScan 2014 Conference
- Vigilance - Noyau Linux déréférencement de pointeur NULL via mac80211, analysé le 02 04 2014
- Stéphane Janichewski est nommé Directeur du marché Défense Aerospace et Directeur de la Sécurité du Groupe Bull
- Lookout une application de sécurité qui protège contre le vol
- Expect Beautifully Packaged Spam along with Your Easter Gifts
- Comment Kroll Ontrack a récupéré des données sensibles de l'OTAN dans un abri antinucléaire
- BearingPoint reçoit le prix de l'innovation décerné par Lünendonk
- Les entreprises fuient les avantages gratuits
- Heartbleed risques et recommandations face à une potentielle exploitation

Dernier articles de SecuObs :
- Le ministère de l'intérieur censure une conférence au Canada
- Saut d'air gap, audit de firmware et (in)sécurité mobile au programme de Cansecwest 2014
- GCHQ: Le JTRIG torpille Anonymous qui torpille le JTRIG (ou pas)
- #FIC2014: Entrée en territoire inconnu
- Le Sénat investit dans les monnaies virtuelles
- #LPM2013: Un nouvel espoir ?
- L'ANSSI durcit le ton
- Assises 2013: Nouvel élan de jeunesse
- OWASP Framework Security Project, répertorier et fixer les contrôles de sécurité manquants
- Le bracelet Nimy, une solution d'authentification à 3 facteurs utilisant un capteur d'ECG

Revue de presse internationale :
- Student arrested for Heartbleed-exploiting tax agency breach
- Zeus rootkit combo delivered via Starbucks-themed emails
- Ca RCMP charge 19-year-old man in Heartbleed privacy breach at Canada Revenue Agency
- U.S. Agent Lures Romanian Hackers in Subway Data Heist
- Think tank challenges Heartbleed handwringing
- Kimberly Clark names new CISO
- 9 Things You Need to Know Before You Store Data in the Cloud
- How a cyber cob patrols the underworld of e-commerce
- Teen arrested in Heartbleed attack against Canadian tax site
- Windows XPs retirement turns into major security project for Chinese firm
- Microsoft extends Windows 8.1 Update migration deadline for business
- Suntory Whisky 3D on the Rocks VIDEO 3DThursday
- Charlie and The 3D Egg VIDEO 3DxArt 3DThursday 3DPrinting
- Police make Heartbleed arrest Taxing times in Canada
- Phishing boom in China bucks global trends

Annuaire des videos
- FUZZING ON LINE PART THREE
- Official Maltego tutorial 5 Writing your own transforms
- Official Maltego tutorial 6 Integrating with SQL DBs
- Official Maltego tutorial 3 Importing CSVs spreadsheets
- install zeus botnet
- Eloy Magalhaes
- Official Maltego tutorial 1 Google s websites
- Official Maltego tutorial 4 Social Networks
- Blind String SQL Injection
- backdoor linux root from r57 php shell VPS khg crew redc00de
- How To Attaque Pc With Back Track 5 In Arabique
- RSA Todd Schomburg talks about Roundup Ready lines available in 2013
- Nessus Diagnostics Troubleshooting
- Panda Security Vidcast Panda GateDefender Performa Parte 2 de 2
- MultiPyInjector Shellcode Injection

Revue Twitter
- RT @fpalumbo: Cisco consistently leading the way ? buys vCider to boost its distributed cloud vision #CiscoONE
- @mckeay Looks odd... not much to go on (prob some slideshow/vid app under Linux)
- [SuggestedReading] Using the HTML5 Fullscreen API for Phishing Attacks
- RT @BrianHonan: Our problems are not technical but cultural. OWASP top 10 has not changed over the years @joshcorman #RSAC
- RT @mikko: Wow. Apple kernels actually have a function called PE_i_can_has_debugger:
- [Blog Spam] Metasploit and PowerShell payloads
- PinkiePie Strikes Again, Compromises Google Chrome in Pwnium Contest at Hack in the Box: For the second time thi...
- @mikko @fslabs y'all wldn't happen to have lat/long data sets for other botnets, wld you? Doing some research (free/open info rls when done)
- RT @nickhacks: Want to crash a remote host running Snow Leopard? Just use: nmap -P0 -6 --script=targets-ipv6-multicast-mld #wishiwaskidding
- An inexpensive proxy service called is actually a front for #malware distribution -

Mini-Tagwall
Revue de presse : security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone

+ de mots clés pour la revue de presse

Annuaires des videos : curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit

+ de mots clés pour les videos

Revue Twitter : security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall

+ de mots clés pour la revue Twitter

Top bi-hebdo des articles de SecuObs
- #FIC2014: Entrée en territoire inconnu
- [IDS Snort Windows – Partie 2] Installation et configuration
- [Ettercap – Partie 2] Ettercap par l'exemple - Man In the Middle et SSL sniffing
- [Trames et paquets de données avec Scapy – Partie 5] Traceroute et visualisation 2D/3D
- Le ministère de l'intérieur censure une conférence au Canada
- USBDumper 2 nouvelle version nouvelles fonctions !
- [IDS Snort Windows – Partie 4] Conclusion et webographie
- EFIPW récupère automatiquement le mot de passe BIOS EFI des Macbook Pro avec processeurs Intel
- [Ettercap – Partie 1] Introduction et rappels
- Powerpreter, un nouveau module Powershell de post-exploitation pour Nishang 0.3

Top bi-hebdo de la revue de presse
- Introducing the rsyslog config builder tool
- 1,103 Megaupload Servers Gather Dust at Virginia Warehouse
- Windows Zero-Day Vulnerability Researched by Microsoft
- Using masscan to scan for heartbleed vulnerability
- Du bitcoin à  l auroracoin, les cryptomonnaies en plein essor
- OpenSSL bug CVE-2014-0160
- XP end of life message
- cartographie en France et au Luxembourg des Data Center - édition 2014
- Move Active Directory users to a group with PowerShell
- Rockwell Automation soutient le Cybersecurity Framework destiné aux industriels

Top bi-hebdo de l'annuaire des videos
- Backtrack 5r3 Armitage Metasploit
- Mikrotik All in one hotspot pppoe client with radius
- Tutorial 14 Pfsense OpenVpn RoadWarrior VPN
- Tutorial 15 pfSense Squid Squidguard Content filtering
- Comment Pirater Un Ordinateur Avec Ubuntu Metasploit
- How to OpenVPN gui PrivatVPN
- crypt server njrat darkcomet bifrost xtremrat spynet zeus botnet
- Comment creer un server botnet!!!!(Réseau de pc zombies)
- Bbkeyswin WPA d une Bbox en 2 min sous Windows
- Metasploit msrpc exploit

Top bi-hebdo de la revue Twitter
- Zombies are attacking America – researchers: Banking sector DDoSers 'used botnets', say security boffins. Hackers re…
- @mikko @fslabs y'all wldn't happen to have lat/long data sets for other botnets, wld you? Doing some research (free/open info rls when done)
- [SuggestedReading] Using the HTML5 Fullscreen API for Phishing Attacks
- [Blog Spam] Metasploit and PowerShell payloads
- RT @helpnetsecurity: Proxy service users download malware, unknowingly join botnet //How ironic.
- PinkiePie Strikes Again, Compromises Google Chrome in Pwnium Contest at Hack in the Box: For the second time thi...
- Zombies are attacking America – researchers - Banking sector DDoSers 'used botnets', say security boffins Hackers re...
- #networksecurity #cloud Expert QA: Cloud computing, HIE will be the 'new normal' - Ken Ong: The National Institute ...
- RT @BrianHonan: Our problems are not technical but cultural. OWASP top 10 has not changed over the years @joshcorman #RSAC
- An inexpensive proxy service called is actually a front for #malware distribution -

Top des articles les plus commentés
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Microsoft !Exploitable un nouvel outil gratuit pour aider les développeurs à évaluer automatiquement les risques
- Webshag, un outil d'audit de serveur web
- Les navigateurs internet, des mini-systèmes d’exploitation hors de contrôle ?
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- CAINE un Live[CD|USB] pour faciliter la recherche légale de preuves numériques de compromission
- Nessus 4.0 placé sous le signe de la performance, de l'unification et de la personnalisation
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- [IDS Snort Windows – Partie 1] Introduction aux IDS et à SNORT
- Origami pour forger, analyser et manipuler des fichiers PDF malicieux

Unauthorized Access to Millions of Cards at Global Payments

Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]

S'abonner au fil RSS global de la revue de presse



Unauthorized Access to Millions of Cards at Global Payments

Par Technicalinfo.net Blog
Le [2012-04-01] à 18:29:25



Présentation : Global Payments, an Atlanta-based payment card processing firm, announced yesterday that they had suffered unauthorized access into a portion of its processing system . Sometime in early March they uncovered the attack, and there are some indications that the breach occurred between January 21st and February 25th of this year. At the moment there is very little public information relating to the nature of the breach, merely that the details of an estimated 10,000,000 cards track 1 and track 2 effectively what s needed to clone physical cards have been slurped by the attacker s . Global Payments will be holding a conference call Monday, April 2, 2012 at 8 00 AM EDT. Personally, I m not expecting much in the way of additional information concerning the method and vectors of the breach to be discussed but would expect a lot about what they ve done to reduce fraudulent use of the stolen card details. There are a number of unverified reports that a New York City street gang with Central American ties took control of an administrative account that was not protected sufficiently . Hopefully a little more light will be shed over the following days as to the nature of the breach less so for closing the case at Global Payments, but more for others to learn from and to not repeat these kinds of mistakes. When it comes to breaches like this as in attacks that appear to target large organizations that hold large volumes of easily sellable data in the digital underground the three most common vectors from my experience are the following 1. Insider threat An insider with detailed knowledge of the businesses operations is able to install tools or access administrative accounts that enable large volumes of confidential information to be copied and transported out of the organization past existing data inspection technologies. Often the transport mechanism is a USB device or a password-protected file that is uploaded to an external Internet server. 2. Crimeware installation A system within the organization is breached through standard drive-by-download or phishing email vectors and a full-featured crimeware agent is installed. The malicious agent registers itself with a criminal s remote command and control C C server and drops a bunch of stolen data relating to that single compromised host. The criminals inspect the small amount of stolen data and realize that they have access to a host within an interesting organization and turn on some additional functions of the crimeware agent to better enumerate the devices and accounts within the breached organization. Armed with a better understanding of the organization and a number of captured accounts and their passwords, the criminals may begin to remotely access other systems within the breached organization or, more likely, sell access to the device to someone that is more capable and better prepared to hack the victim s network. 3. Remote account access - Somewhere along the line the organization has enabled a number of remote access portals or VPN s to enable staff and business partners to access key servers or update data records. Some of these services have been poorly secured or, most likely, particular accounts have been uncovered and fully enumerated by the attackers. Armed with the accounts user ID and password, the attacker s can simply log in remotely and slurp down the data they want. For organizations likely to suffer from such targeted breaches whether or not the initial breach was due to an opportunistic or non-targeted infection vector , there are obviously a myriad of technologies and tactics that can be implemented any typically are to timely identify and limit the loss from a breach. Some of the most successful approaches I ve seen in recent years are the following Canary accounts Dropping in a number of records that appear to be real in to key databases and record repositories, and carefully monitoring access to these particular accounts. For example, these may be credit cards that exist only within the card processing organization and if any external merchant tries to process a transaction against such a card it would be clear that data has been leaked. These canary accounts can also be used to track data propagation within the network from a data-leakage perspective. Administrative accounts that aren t By including a number of accounts within internal corporate email address books and servers that appear to be administrative or high privilege accounts , monitoring systems can be set to alert if anyone attempts to email them, or use the accounts to access any server. This will alert the organization to many internal breaches earlier than watching for externally used canary accounts. Destination monitoring - By tracking all egress traffic and identifying both anomaly traffic patterns to standard business entities and to unexpected destinations, it is possible to gain early warning of a breach in progress. Cybercriminal C C monitoring - The most likely breach vector that the victim organization is going to be able to proactively detect and protect against is going to be against remotely controllable crimeware. By knowing which Internet infrastructure is related to what criminal operators it becomes an automated process of identifying crimeware infected computers operating within their organization and prioritizing their remediation over standard malware infections. Hopefully most organizations are aware that modern crimeware rarely comes through the front door in an easily inspectable form. Even insider threats have found it increasingly advantageous to use their own crimeware as a method of remotely accessing devices within the targeted organization and transporting the stolen data out. As such there is a need to identify egress traffic associated with crimeware and to instrument the organization to detect canary data records and administrative accounts. With a bit of luck we ll get more insight to the Global Payments breach over the coming weeks. However, I suspect that it s going to be the same old story again. The cybercriminals have better tools than their victims and are more agile in their deployment and use.




AddThis Social Bookmark Widget



Les derniers articles du site "Technicalinfo.net Blog" :

- Consumer Antivirus Blogs
- Divvy Up the Data Breach Fines
- The CISSP Badge of Security Competency
- Tales of SQLi
- How much is a zero-day exploit worth
- Now at IOActive
- Point of Sale POS and Card Reader Tampering
- Persistent Threat Detection on a Budget
- Exploit Development for Fun Profit
- NItol and 3322.org Action by Microsoft




S'abonner au fil RSS global de la revue de presse

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]



Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail




SecuToolBox :

Mini-Tagwall des articles publiés sur SecuObs :

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :

Mini-Tagwall des Tweets de la revue Twitter :