Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror

Comment Plausible based upon server names. (Score 4, Informative) 302

I am working for a Relatively Large Teleco in Europe and can say from the list of server names that this is a plausible hack.

Whether or not however they have real information or just DNS entries however is yet to be seen.

What is the basis for this conclusion?

protib02 Prod IHAP TIBCO 582 Tibco 10.1.81.21 HP-UX 11.11 BOTHELL_7 582 #N/A 1 - Tibco. An application layer messaging bus used heavily in FAB (Fulfilment Assurance Billing) area of large telecos
proetl02 Prod IHAP Teradata 576 teradata 10.133.17.51 HP-UX 11.11 NEXUS #N/A #N/A 1 - Teradata.... another product I know we are using (unknown however exactly what it does)
prowac06 Prod IHAP EAI 151 EAI - Middleware 10.1.80.91 HP-UX 11.11 BOTHELL_7 151 #N/A 1 - EAI - Middleware application used also in telecos.

Similarly the SAP Naming convention used roughly translates to some deployments I have seen in the past.

What does this whole thing give away....

Looking at the naming conventions they have three "defined" network zones:
TAMPA - Management (HP OVO, DNS, Backup Servers)
BOTHELL - Application Server zone with all sorts of stuff. Big flat topology....(ugly with lots of different services using the same subnets and DB Servers not seperated from AS)
NEXUS - Another Application Server Zone with a mix of stuff within it. This appears smaller and newer than the other from the server names.

What does this show from a security perspective?

- No clear Security Architecture ... No 3 tier architecture DMZ/Application Server/DB Server split.
- No clean separation of Backup network (backup mixed with Management functions... this should be in a seperate network).
- No clean separation of Management Network (SAN/Backup/OVO located together)

In any Teleco situation with thousands of servers it is impossible to prevent a security breach. There is always going to be servers somewhere which are unpatched, legacy, forgotten etc.
What is important is a "defence in depth" principle to limit any disclosure. In this instance that appears not to have been followed. The topology is "Flat" with an emphasis on easier communications between systems rather than minimizing communications to minimum required. This essentially stopped any chance of them being able to limit a breach.

Hopefully someone will get some lessons learned out of this. I know I will be presenting some points to our management where we should be focusing based upon this. Our security is definitely better but nothing is perfect.

I'm interested in any points that anyone else could offer here, I have not discussed all points however I am interested in the perspective of others from what they can mine there.

Please more comments!

http://streetstyles.ch/ - Schweiz Band & Fashion Tshirts

Input Devices

Motion Control To Lengthen Console Hardware Cycles 160

With the recent E3 demonstrations of new motion-based control for consoles — Microsoft's Natal, Sony's Motion Controller, and Ubisoft's camera-based system for the Wii — analysts now expect the current console generation to last longer than normal. Microsoft exec Shane Kim said he expects the Xbox 360 to last until around 2015, in part due to Natal and new services available through Xbox Live. Signal Hill's Todd Greenwald thinks this cycle may not need to end at all: "Microsoft and Sony have invested so much in their current hardware line, as have third party publishers, that we don't think any party is seriously interested in throwing away these investments and starting over from scratch. For all of these reasons, we think this cycle will last longer than those in the past, and don't see new hardware coming until 2011 at the earliest, and 2012 to 2013 more likely (if at all — if new services like OnLive take off, or if Xbox Live and PlayStation Network become more and more robust, there may not be a need for another console cycle).'"

Comment Audit Responsibility - Possibly a good thing. (Score 3, Informative) 209

I am working in a large firm. Quite often new projects upon realisation require technical audits as well as "Life Cycle" audits for existing systems involved with billing etc. One point that needs to be clear. Audits are not cheap! These guys are paid between 1500-2000 per Man day. Presently this is done in essence without ANY liability as to the quality of their work. What needs to be established in this case is: 1. Technical Audits provide a snapshot of a system "at a particular point in time" - Did at the time of the Audit these holes exist, or where there changes afterwards which could have affected the audit results? 2. Audit Scope. This is really important! If the Audit scope didn't include for instance the visibility of the systems from outside of the firewall, then the perspective of the auditors were limited and therefore the audit itself is not complete. I have seen companies for instance that are ISO 27001 Certified....however.... the audit scope was only for a particular part of the company. This enables the company to suggest 27001 Certification when in fact it may not indeed be fully the case. Most likely the outcome of such a case would be an increase in costs to cover Liability (insurance or something of the like) on the part of the auditor. However it may well be also an increase in the quality and transparency (clearer scope, limitations etc.) of technical audit work. Both of these are positive outcomes! http://streetstyles.ch/ - Swiss Band & Fashion Tshirts
Classic Games (Games)

Monkey Island To Return 153

Briareos was one of several readers to write with news that TellTale Games, along with LucasArts, will be bringing new Monkey Island games later this year. Tales of Monkey Island will be a series of episodic games released for PC and WiiWare in the coming months, and The Secret of Monkey Island: Special Edition will be a remake of the original 1990 game, available on the PC and Xbox Live. A trailer is available for the former, and this is what the press release says about the latter: "The development team at LucasArts is bringing the game into the modern era with all-new HD graphics, a re-mastered musical score, full voiceover, and an in-depth hint system has been added to help players through the game's side-splitting puzzles. Purists will also delight in the ability to seamlessly switch between the updated HD graphics and the original's classic look." Grumpy Gamer has a nostalgic look back at the franchise.

Slashdot Top Deals

Live within your income, even if you have to borrow to do so. -- Josh Billings

Working...