Most Popular Stories
- Chrome 17's new features enhance speed, security
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
- Apple's iPad 3 will be unveiled first week of March, says report
- Microsoft: How Windows 8 on ARM will be different
- There's no escaping the app economy
Events
- MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - CIO Summit
March 18- 21 — Miami, FL
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Storage Consolidation: Best of Both Worlds
- Is Corporate Liability Robbing YOU Blind?
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Case Study: ABBYY FineReader® Engine Drives Demand for ECM Software Leader
- Penetration Testing with Metasploit Framework
Hacker infiltrates eBay admin system
Last month, you might have read about a security breach at eBay that resulted in the public disclosure of some 1,200 credit card numbers. Turns out, it was more hoax than hack: the credit card information didn't match anything that eBay had on file. This month, however, the online auction site found itself the victim of a real breach: a hacker going by the name of "Vladuz" (believed by some to be the same individual behind the earlier incident) gained access to components of an old eBay administrative system and disabled several user accounts. eBay has since removed the compromised code from its servers and assures users that it has taken the appropriate steps to ensure that a similar attack won't be successful in the future. "This fraudster found very old administrative functions that had not been deactivated several years ago when we changed the security of our internal systems," a statement from an eBay Trust and Safety representative said. "These functions were still accessible on public servers, while the rest of our functionality is now behind multiple layers of security. We immediately identified the functions that he accessed and deactivated, and we are undergoing an audit to ensure obsolete code that may still exist for other reasons is secure." The moral of the story? If you've got vestigial code on your servers, make sure it's secure.
For more on the attack:
- see this Ars Technica story
Related Stories
- New class of cyber attacks sidesteps existing defenses, says security vendor
- Silly hackers attempt to attack the Internet, fail
- University server in hackers' hands for a year
- Foundry adds Snort security to LAN switch
- Apple patches 43 flaws in OS, QuickTime
- ALSO NOTED: When servers crash and burn; Why did Microsoft join ODF group?; and much more...
- InfoPath hit with first virus, researchers say
- Microsoft patches Outlook and Exchange
- ALSO NOTED: What hackers will hit in 2006; BlackBerry users can relax;and much more...
- Oracle patches 88 holes in security update
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




