blank.gif (43 bytes)

Church Of The
Swimming Elephant

Search:

Earthlink cracked!


Earthlink is currently battling a recent compromise of their internal network. Many of their internal Unix boxes have been cracked and have had a backdoor installed, according to unnamed Earthlink admins. Earthlink is currently working this in stealth, with the entire affair being kept very quiet.

Administrators have been working frantically to determine the depth of the breach. Among tasks facing administrators is the combing of files using the strings command in an apparent attempt to determine exactly which machines have been back doored. They have currently restricted access to their billing database and a "jump" box named "chie". They have also locked down what they call their "yellow" and "green" networks.

Restricting access to their billing database means that they have it temporarily locked down. We have heard that finance employees and billing are currently unable to access this database unless it is urgent. Urgent requests are temporarily required to be sent off instead of direct access. It is unknown at this time if the billing databases were compromised.

The compromise was apparently due to a recent SSH vulnerability that caught them off guard. It appears that they did not react fast enough in patching their servers and the result was a wide spread compromise. Granted, rapidly patching many servers is a task and a half and will not happen fast, but close monitoring of the affected service can drastically limit damage. We hope that Earthlink managed to detect it fast enough.

This should underscore the need for corporations with a net presence to follow the security lists closely and address root exploits immediately. Unfortunately most corporations still place network security as low priority. Frequently they completely ignore it or take weeks to respond to announced vulnerabilities. The recent Microsoft, Intel, and now Earthlink compromises have shown that even waiting a few days is to long.

Companies with a strong net presence should be employing a security administrator who's sole job is to keep up with the vulnerabilities and coordinate patching in a timely manner. Root vulnerabilities cannot wait to wade through the mountains of internal red tape before being addressed.

/steve
2-15-2001

Cotse.Net

Protect yourself from cyberstalkers, identity thieves, and those who would snoop on you.
Stop spam from invading your inbox without losing the mail you want. We give you more control over your e-mail than any other service.
Block popups, ads, and malicious scripts while you surf the net through our anonymous proxies.
Participate in Usenet, host your web files, easily send anonymous messages, and more, much more.
All private, all encrypted, all secure, all in an easy to use service, and all for only $5.95 a month!

Service Details

 
.
www.cotse.com
Have you gone to church today?
.
All pages ©1999, 2000, 2001, 2002, 2003 Church of the Swimming Elephant unless otherwise stated
Church of the Swimming Elephant©1999, 2000, 2001, 2002, 2003 Cotse.com.
Cotse.com is a wholly owned subsidiary of Packetderm, LLC.

Packetderm, LLC
210 Park Ave #308
Worcester, MA 01609