No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

The, RSA, attack, who, else, was, hit
Juniper Networks has extended its SSL VPN security to the iPad with the release...
A recent survey by security company Sophos exposes the dilemma to business posed by...
You might think that thousands, nay millions of people will be on the Internet...
Today's release of the report "In the Crossfire: Critical Infrastructure in the Age of...
- Sponsored Editorial - AppLabs sees huge value proposition for its clients with...

The RSA attack - who else was hit?

Business IT - Security

In March this year, RSA was the victim of a relatively stealthy attack which appeared to have breached its proprietary secure token systems - the so-called key-fobs.  Unfortunately, they were not the only ones hit by the same attackers.

A few days ago, well-known security writer Brian Krebs posted a list of over 760 organisations that appear to have a close victim relationship with the RSA attack.

As Krebs makes very clear, these organisations may or not have been infiltrated by the attackers, but they are clearly showing the effects of being infiltrated.

The list shows those organisations which have made contact with one of the many command-and-control (C&C) servers associated with the attack. Readers should also be reminded that many of the listed organisations are ISPs (who may have had affected customers) or AV organisations (who clearly have an interest in testing these C&C servers).  There are approximately 20% of the Fortune-500 companies in the list.

Many commenters to both Krebs' blog and other summaries have complained that without knowing the source of the list (which Krebs claims to not be at liberty to disclose) there is doubt as to its veracity.

However in the security arena, pearls such as this are always at the flimsy end of the spectrum.  Too many people and organisations are overly protective of their security and any facts related to gaps in such security; particularly as it relates to shareholder value and public image are tightly controlled.  Alternately, knowing the source might also expose the method of obtaining the list.

So, who was behind this attack?