Auctioned server becomes security nightmare

A VPN server that was bought for less than a dollar on eBay proved to be a security nightmare as the new user found that it automatically connected itself to private networks.

Andrew Mason from Random Storm, a UK-based vulnerability management firm, picked up the Cisco Virtual Private Network from eBay in August. When he plugged the device in, it connected itself to an English metropolitan borough's servers.

A spokesperson for the borough, Kirklees, said it was a reason for concern, but remained confident that “multiple layers of security” prevented access to data. The spokesperson said, “In the meantime the disposal process has been suspended until an investigation can be carried out and appropriate action taken.”

Richard Farnworth, general manager, Enterprise Solutions, NEC (UK), said: “Protecting networking equipment and network topology is just as important in preventing security breaches as the recent spate of laptop, CD and memory stick losses we have seen. This latest announcement should not only act as a wake-up call to others, but demonstrated the growth in utility and appliance-style computing where the data and the intelligence is as much inherently ‘in' the network as those devices that connect to the network."

He added: “As so much dependence is placed upon connectivity in the ‘networked society' we belong to, it is imperative that both public sector organizations and commercial businesses take special care when disposing of any IT products. It will not come as a surprise that many ‘black box' devices hold configuration information within them and even consumers have cottoned on to the importance of securing their wireless networks at home, wiping hard disk drives before disposing of PCs and clearing memory banks in mobile telephones before sending them off for recycling.”

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.