Blog|Login|Chinese German Japanese|Follow @imperva
January 23, 2009
 Is it a bird? Is it a plane? No, it's...TJMAX all over again

By a very weird coincidence we became aware of one of the largest data breach incidents of all time on the same day of Obama's inauguration. Currently hyped conspiracy theory is that someone was hoping that we would be too distracted to notice. The incident which actually took place over the past year resulted in tens of millions of credit and debit card transactions being compromised.


Working for a Data Security vendor I should now throw my usual company line telling you to beware of SQL Injection, Google Hacking and internal threats to your database. However, it seems that this one belongs to one of the oldest tricks in the book.


Attackers managed to install a, probably very simple, Trojan on a server that collected all the transactions processed by a server before being sent to a database.What I really think this attack reinforces is that information security is a layered effort, mitigating different risks in different layers of the protocol stack. In this case these should probably have been Anti Malware, configuration change detection, and maybe some stricter outbound network access controls.


Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Past Perfect and Present Progressive | Main | Will The Real PII Stand Up? »