Windows Server 2012 Resource Centre
[ad] Windows Server 2012 redefines the server category, delivering hundreds of new features and enhancements spanning virtualization, networking, storage, user experience, cloud computing, automation, and more. Click here to visit our Windows Server 2012 Resource Centre with case studies, white papers and articles about Windows Server 2012.
Nokia Lumia Smartphones: Innovation's calling
[ad] Nokia Lumia with Windows Phone comes with unique camera technology, wireless charging and turn-by-turn navigation. Make every image picture perfect. See your city differently. Charge without wires. Click here to learn more.
Save up to $199 on Dell XPS 12 Ultrabooks: Power for your projects and passions.
[ad] This convertible Ultrabook™ delivers the speed and performance you expect from the XPS family in a sleek new design that's ready for work and play. Don't get two pieces of technology when one will do it all. The Dell XPS 12 is a tablet and Ultrabook combined to produce the perfect laptop.
Great articles on other sites
- Galaxy S 4 “Google Edition” to be available in Australia via MobiCity
- When does mission creep become censorship?
- First NBN fibre extension completed
- Proof the internet filter lives on by other means
- Budget 2013: Heavy on 'showcasing', light on strategy
- CGU to replace core insurance system
- Google Australia calls for mandatory comp sci until year 10
- Spectrum fail could help Libs fight Labor's regional NBN
- Offended By Fraudband? Maybe You Shouldn’t Have Said It First
- Brisbane Grammar School prepares for Lync
Managing virtualised environments: Free whitepaper
[ad] Virtualisation is one of the single most important technologies for efficiently operating servers. This free whitepaper presents information about current trends in virtualisation adoption, risks associated with single vendor virtualisation, and the benefits of open source virtualisation. Click here to download the whitepaper.
One More Thing - iOS App Maker Conference - 24th May
[ad] If you make iOS apps, come listen to the best in the industry share their tip & tricks for App Store success. Melbourne, 24th May, 2013 - use the coupon code "delimiter" for 5% off.
News, Telecommunications - Written by Renai LeMay on Wednesday, October 3, 2012 20:02 - 17 Comments
iiNet hid game forum hack from customers
news Following several months of rumors, national broadband provider iiNet has admitted a now-defunct forum associated with its 3FL gaming network was recently hacked and that it concealed the break-in from affected customers whose login details may have been compromised.
Rumours about the apparent hack have been swirling in Australia’s technology community for several months, with Delimiter receiving an unverified tip in July about the break-in, and iiNet customers on broadband forum Whirlpool complaining about receiving spam email to accounts which they had not publicly used for any purpose.
iiNet has made no public comment to the media regarding the issue and has not communicated regarding it to customers. However, in response to speculation on broadband forum Whirlpool about a break-in, the ISP’s network services manager Roger Yerramsetti posted last week that iiNet had done “a lot of digging” but could not find any evidence of a security breach or inappropriate access of customer information.
“Our teams have looked outward from iiNet and we’ve had expert people looking inward from outside as well,” he wrote. “There were some settings we were not happy with, which have now been modified, but for obvious reasons we cannot state what we have done. At this point we are happy to offer to change any affected account holder’s authoritative email address to stop any further unwanted emails.”
However, this week Delimiter received a second unverified tip regarding the issue. The tip contained what appeared to be an internal email from iiNet operations centre supervisor Paul Guidera sent on 7 June this year to iiNet’s executive team. In it, Guidera wrote that iiNet’s security team had informed his team that the 3FL website — the public face of a long-running iiNet gaming network used by both iiNet customers and non-iiNet customers, had been “compromised and defaced”. In response, the server had been taken offline temporarily.
“On instructions from security there is a comms blackout on this event (no publics, WP, staff communication etc),” wrote Guidera in the unverified email, referring to the desire to stop iiNet staff communicating about the issue to the public or through the Whirlpool forum. At that stage, iiNet was investigating the issue internally, but it had already announced in May that it was planning to merge 3FL with Internode’s games.on.net platform following iiNet’s acquisition of Internode late in 2011, and it appears as though iiNet progressed the process, in part due to the 3FL break-in.
This morning Delimiter requested comment on the issue from Guidera, iiNet chief executive Michael Malone, and later on, iiNet’s public relations representative, however no official company response was received. The company has not confirmed that Guidera’s email was genuine. However, following the requests for comment, tonight iiNet chief technology officer John Lindsay posted a comment on a previous Delimiter article confirming the break-in.
“The 3FL forum was a standalone system with its own user database and was not connected to iiNet’s secure networks,” he wrote. “In June we found that the system was hacked via an unpatched hole in PHP. Upon finding this, we shut down the forum immediately. No financial information was stored on this database. We didn’t handle the external communications well after this incident and have made changes to our internal policies. We subsequently retired the old 3FL forum after merging with games.on.net.”
Lindsay wrote that iiNet had investigated the spam issue raised by Whirlpool and had found no evidence linking the spam to the 3FL break-in. “Accounts created since the 3FL server was shut down have received this spam so it is very unlikely there is any connection,” he wrote.
One possible reason for the spam is the possibility of a loophole in the PHP framework that might have allowed attackers to source customer usernames from iiNet’s customer web server. “We suspect this is the likely origin of the mailing list. Many php installations allow this access but we should have closed it off when the system was installed and we have now,” wrote Lindsay.
In general, the iiNet CTO wrote that the company takes its customers’ privacy “very seriously”. “We do not store complete credit card data on our servers and are audited for PCI compliance regularly,” he wrote. “We run penetration tests against public facing servers and against our firewalls regularly. I am confident that we are using reasonable and prudent techniques to protect our systems and our customers.”
The news comes several months after another major Australian telecommunications company, AAPT, had some of its data compromised, with the loose knit group of Internet activists known as ‘Anonymous’ publishing some 3.5 gigabytes of data from the company, in protest against a wide-ranging package of surveillance and data retention reforms currently proposed by the Federal Government.
Privacy advocates have consistently warned over the past several months that the data retention scheme — which would see ISPs such as iiNet forced to keep extensive records on their customers’ online activities, ranging from records about who and when they email and place telephone calls to and from — would be at risk of being broken into, and highly sensitive data stolen.
There’s several concerning things about this situation.
Firstly, to my mind iiNet came very close to lying to its customers about the hack of the 3FL network. When Whirlpool users raised the spam issue with iiNet, the company’s network services manager Roger Yerramsetti flatly said the company had conducted an internal security audit and hadn’t found anything. This is probably technically true — the company had conducted an investigation into where the spam emails were coming from, and found no evidence that its actual customer database had been broken into.
However, I would be very interested to know whether Yerramsetti was aware of the simultaneous issue swirling around the hack of the 3FL forum. If so, then this omission of information comes very close to a deliberate attempt to mislead customers, in my opinion. Personally, I don’t believe Yerramsetti did know, given the ‘blackout’ which was imposed on the knowledge. However, it is clear that the top executives at iiNet — such as chief executive Michael Malone and CTO John Lindsay — would have been aware of both, and didn’t tell customers about the 3FL issue.
How serious is the 3FL issue? Probably not that serious. As Lindsay said today, it was the 3FL forum which was hacked, not iiNet’s customer database, and no financial information was lost. To be honest, these kinds of forums (typically based on phpBB or vBulletin) get hacked all the time, and my own personal experience tells me that it is very hard to secure these forum installations, due to the arcane software which runs them. There are very many undisclosed hacked forums online of which the admins are not aware. It’s a fact of life on the Internet, and anyone using these forums would be a fool to keep sensitive information there, or to use the same password for these kinds of forums that they use for other, more sensitive sites such as Internet banking.
But nevertheless, there does remain the possibility that someone could have used the hack of the 3FL forum as a launching pad into the rest of the iiNet network. It’s standard practice for Internet bad guys — find a vulnerable web server somewhere, hack it, and then look around for new admin details which will let you into other areas of the network. Hell, I used to be a Unix/Linux systems administrator for an ISP, and I have seen precisely these kinds of hacks in action in the past, and cleaned them up. Sometimes there’s not even an active human intelligence behind them — often it can be little more than a bot.
To my mind, what this demonstrates is somewhat of a lack of integrity on the part of iiNet. Clearly, the company has had several chances to come clean about this issue over the past few months, and just as clearly, it avoided doing so. As an iiNet customer and someone who uses its gaming network from time to time, I’m disappointed in the company.
On a wider note, AAPT has recently been hacked, Telstra has recently been hacked (in a very similar breach to the 3FL attack), and now we know iiNet has recently been hacked. Most of these hacks have been fairly trivial. But does anyone really believe at this point that these ISPs would absolutely, 100 percent, be able to guarantee the security of the massive stores of Australians’ telecommunications records which the Federal Attorney-General’s Department wants them to start holding? I certainly don’t. And that’s the bigger issue here.
Leave a Comment
Enterprise IT, Featured, News - May 22, 2013 16:02 - 0 Comments
More In Enterprise IT
- Australia gets two Windows Azure datacentres
- Oracle reveals swathe of Aussie rollouts
- Australia’s universities hacked on a regular basis
- 32 years later, CGU replaces insurance IT platform
- Guzman y Gomez likes the taste of NetSuite
News, Telecommunications - May 22, 2013 15:27 - 17 Comments
More In Telecommunications
- At death’s door:
Vodafone loses 216k more customers
- 4G race: Telstra turns on 1500th tower
- Optus launches TD-LTE 4G trial in Canberra
- Is FTTN vectoring just a pipe dream?
- Turnbull rejects Labor’s NBN subsidy claims
Blog, Gadgets - May 13, 2013 15:52 - 0 Comments
More In Gadgets
- HP Slate 7 to land in Australia shortly
- Why touchscreens matter for laptops
(Or, review of the ThinkPad X1 Carbon Touch)
- Amazon Appstore challenging Google Play as Australian launch looms
- Consoles to suffer as tablets triple mobile games downloads by 2017
- Despite Aussie windfall, does Apple profit slide suggest hard times ahead?