Auctioned server becomes security nightmare

Share this article:

A VPN server that was bought for less than a dollar on eBay proved to be a security nightmare as the new user found that it automatically connected itself to private networks.

Andrew Mason from Random Storm, a UK-based vulnerability management firm, picked up the Cisco Virtual Private Network from eBay in August. When he plugged the device in, it connected itself to an English metropolitan borough's servers.

A spokesperson for the borough, Kirklees, said it was a reason for concern, but remained confident that “multiple layers of security” prevented access to data. The spokesperson said, “In the meantime the disposal process has been suspended until an investigation can be carried out and appropriate action taken.”

Richard Farnworth, general manager, Enterprise Solutions, NEC (UK), said: “Protecting networking equipment and network topology is just as important in preventing security breaches as the recent spate of laptop, CD and memory stick losses we have seen. This latest announcement should not only act as a wake-up call to others, but demonstrated the growth in utility and appliance-style computing where the data and the intelligence is as much inherently ‘in' the network as those devices that connect to the network."

He added: “As so much dependence is placed upon connectivity in the ‘networked society' we belong to, it is imperative that both public sector organizations and commercial businesses take special care when disposing of any IT products. It will not come as a surprise that many ‘black box' devices hold configuration information within them and even consumers have cottoned on to the importance of securing their wireless networks at home, wiping hard disk drives before disposing of PCs and clearing memory banks in mobile telephones before sending them off for recycling.”

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

Reported breaches involving zero-day bug at JPMorgan Chase, other banks

Reported breaches involving zero-day bug at JPMorgan Chase, ...

Hackers exploited a zero-day vulnerability and gained access to sensitive information from JPMorgan Chase and at least four other financial institutions, reports indicate.

Data on 97K Bugzilla users posted online for about three months

During a migration of the testing server for test builds of Bugzilla software, data on about 97,000 Bugzilla users was inadvertently posted publicly online.

Chinese national had access to data on 5M Arizona drivers, possible breach ...

Although Lizhong Fan left the U.S. in 2007, the agencies responsible for giving him access to Americans' personal information have yet to disclose the details of the case to the public.