<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; data-loss</title>
	<atom:link href="http://www.darknet.org.uk/tag/data-loss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>IT Managers Under-Estimate Impact Of Data Loss</title>
		<link>http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/</link>
		<comments>http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 10:52:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[data loss survey]]></category>
		<category><![CDATA[data-loss]]></category>
		<category><![CDATA[data-security]]></category>
		<category><![CDATA[data-theft]]></category>
		<category><![CDATA[impact of data loss]]></category>
		<category><![CDATA[information loss]]></category>
		<category><![CDATA[information theft]]></category>
		<category><![CDATA[Information-Security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1877</guid>
		<description><![CDATA[I find it a little surprising in this day and age that such a low percentage of IT managers believe data loss is a low impact issue. Don&#8217;t they read the news? Don&#8217;t they understand how losing customer trust can really effect your bottom-line? I would have thought 30% of respondents thinking data loss was [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I find it a little surprising in this day and age that such a low percentage of IT managers believe data loss is a low impact issue.</p>
<p>Don&#8217;t they read the news? Don&#8217;t they understand how losing customer trust can really effect your bottom-line?</p>
<p>I would have thought 30% of respondents thinking data loss was high impact as a low figure, but 7%? That&#8217;s just insane.</p>
<blockquote><p>A mere seven per cent of respondents to a survey on data management believed data loss has a &#8220;high&#8221; impact on a business.</p>
<p>This is one of the key findings of a survey launched in Hong Kong yesterday by Kroll Ontrack, a US-based provider of data recovery solutions. The survey was conducted earlier this year by StollzNow Research. It asked IT managers from 945 small, medium and large companies in Hong Kong, Singapore and Australia about their views and experiences related to data management.</p>
<p>The survey found that just less than half (49 per cent) of all IT managers have reported a data loss situation in the last two years. </p></blockquote>
<p>Even more shocking is that half of the small business surveyed don&#8217;t even run back-ups! It&#8217;s so cheap and simple now with mass storage devices available off the shelf with Terabytes of storage.</p>
<p>There&#8217;s really no excuse for not backing up any more, I even had a 2TB RAID mirrored storage unit at home to back up my personal stuff. All my websites are backed up nightly and the backups sent to multiple physical servers and DB backups sent via e-mail.</p>
<blockquote><p>While larger companies may not fully appreciate the risks they face with data loss, it is the small business sector that appears to be most at risk. An alarming 49 per cent of small companies stated that they fail to back up their data on a daily basis.</p>
<p>This is despite the fact that nearly half of all participants had experienced data loss in their workplace in the past two years, and 36 per cent felt that data loss could have a significant impact on their business.</p>
<p>Small businesses were also less likely to test their backup systems on a regular basis, or to have implemented a policy for the preservation of data. While 61 per cent of overall respondents reported that their company had a formalised data retention policy, this figure fell to just 45 per cent for companies with 50 or fewer employees. </p></blockquote>
<p>I&#8217;d be interested to see a similar survey for the US and Europe to see if the figures are in the same kind of range.</p>
<p>It&#8217;s very common though for policies and backups to be implemented and never updated or tested. So when a failure actually occurs the company finds out their system isn&#8217;t even working.</p>
<p>Computers and backup systems don&#8217;t just keep magically working, especially when you&#8217;re changing configurations, server setups and software all the time.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/061909-it-managers-under-estimate-the-impact.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IT+Managers+Under-Estimate+Impact+Of+Data+Loss+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1877+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;t=IT+Managers+Under-Estimate+Impact+Of+Data+Loss" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;title=IT+Managers+Under-Estimate+Impact+Of+Data+Loss" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;title=IT+Managers+Under-Estimate+Impact+Of+Data+Loss" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;title=IT+Managers+Under-Estimate+Impact+Of+Data+Loss" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/&amp;title=IT+Managers+Under-Estimate+Impact+Of+Data+Loss" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fit-managers-under-estimate-impact-of-data-loss%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/it-managers-under-estimate-impact-of-data-loss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TJX (T.J. Maxx and Marshall’s) Largest Breach of Customer Data in U.S. History</title>
		<link>http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/</link>
		<comments>http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/#comments</comments>
		<pubDate>Fri, 28 Sep 2007 20:18:58 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[customer data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data-loss]]></category>
		<category><![CDATA[data-security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-databases]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[marshalls]]></category>
		<category><![CDATA[tj maxx]]></category>
		<category><![CDATA[tjx]]></category>
		<category><![CDATA[web sites]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/</guid>
		<description><![CDATA[This case has been going on for a while but obviously hush hush, being that it is the largest breach of customer data in U.S. History. The details of the case have only started emerging in the last couple of months. Information Week published a good article covering what has been going on recently. Amazing [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>This case has been going on for a while but obviously hush hush, being that it is the largest breach of customer data in U.S. History. The details of the case have only started emerging in the last couple of months.</p>
<p>Information Week published a good article covering what has been going on recently.</p>
<p>Amazing the amount of data we are talking about here, 45 million customer records!</p>
<blockquote><p>    TJX will be glad when this year is over. The $17 billion-a-year parent company of T.J. Maxx, Marshall’s, and several other discount retail chains has spent the past eight months dealing with the largest breach of customer data in U.S. history, the details of which are starting to come to light.</p>
<p>    Last December, TJX says it alerted law enforcement that data thieves had made off with more than 45 million customer records. Since that time, at least one business, Wal-Mart, has lost millions of dollars as a result of the theft, while TJX has spent more than $20 million investigating the breach, notifying customers, and hiring lawyers to handle dozens of lawsuits from customers and financial institutions. Should TJX lose in the courts, it could be on the hook for millions more in damages.</p>
<p>    But there’s an even broader TJX Effect: The data breach, which actually took place over a period of years, has put the entire retail industry on the defensive and stirred up demands for all businesses that handle payment card information to do a better job of protecting it. Legislators are invoking TJX’s name to fast-track data-security bills.</p></blockquote>
<p>Years? That’s scary, how can something like this happen? I can’t blame the retail industry for being shaken up. Credit card information does need to be safeguarded.</p>
<p>I hope legislation is approved to hold companies that leak data like water in a sieve, they should be fined some big cash and made to compensate every consumer that was negatively effected by fraudulent use of their credit cards.</p>
<blockquote><p>    Poorly secured in-store computer kiosks are at least partly to blame for acting as gateways to the company’s IT systems, InformationWeek has learned. According to a source familiar with the investigation who requested anonymity, the kiosks, located in many of TJX’s retail stores, let people apply for jobs electronically but also allowed direct access to the company’s network, as they weren’t protected by firewalls. “The people who started the breach opened up the back of those terminals and used USB drives to load software onto those terminals,” says the source. In a March filing with the Securities and Exchange Commission,TJX acknowledged finding “suspicious software” on its computer systems.</p>
<p>    The USB drives contained a utility program that let the intruder or intruders take control of these computer kiosks and turn them into remote terminals that connected into TJX’s networks, according to the source. The firewalls on TJX’s main network weren’t set to defend against malicious traffic coming from the kiosks, the source says. Typically, the USB drives in the computer kiosks are used to plug in mice or printers. The kiosks “shouldn’t have been on the corporate LAN, and the USB ports should have been disabled,” the source says.</p></blockquote>
<p>A pretty basic attack eh? Can you believe they were so negligent in setting up the kiosks? They virtually allowed full access to their corporate network!</p>
<p>Public resources should never have access to the same segments critical data are stored on…this is basic stuff!</p>
<p>They also owned via open Wifi networks in Marshall’s stores…sad eh?</p>
<p></p>
<p>Source: <a href="http://www.informationweek.com/shared/printableArticle.jhtml?articleID=201400171">Information Week</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D698+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;t=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;title=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;title=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;title=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/&amp;title=TJX+%28T.J.+Maxx+and+Marshall%E2%80%99s%29+Largest+Breach+of+Customer+Data+in+U.S.+History" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F09%2Ftjx-tj-maxx-and-marshall%25e2%2580%2599s-largest-breach-of-customer-data-in-us-history%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Massive Data Theft Operation Uncovered</title>
		<link>http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/</link>
		<comments>http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/#comments</comments>
		<pubDate>Mon, 11 Dec 2006 05:10:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[data-loss]]></category>
		<category><![CDATA[data-theft]]></category>
		<category><![CDATA[haxdoor]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/</guid>
		<description><![CDATA[UK Police have uncovered a fairly massive data theft operation with a total close to 8,500 victims. It&#8217;s quite worrying when things like this are uncovered as if 1 is uncovered or discovered&#8230;imagine how many aren&#8217;t found out about, just like exploits. British electronic-crime detectives are investigating a massive data theft operation that stole sensitive [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>UK Police have uncovered a fairly massive data theft operation with a total close to 8,500 victims.</p>
<p>It&#8217;s quite worrying when things like this are uncovered as if 1 is uncovered or discovered&#8230;imagine how many aren&#8217;t found out about, just like exploits.</p>
<blockquote><p>British electronic-crime detectives are investigating a massive data theft operation that stole sensitive information from 8,500 people in the U.K. and others in some 60 countries, officials said Tuesday.</p>
<p>In total, cybercriminals targeted 600 financial companies and banks, according to U.K. authorities, who have worked over the past week to identify and notify victims.</p>
<p>Through intelligence sources, U.K. police were given several gigabytes of data &#8212; around 130,00 files &#8212; that came from a server in the U.S., said Charlie McMurdie, detective chief inspector for the Specialist Crime Directorate e-Crime Unit of the London Metropolitan Police. Most of the data related to financial information, she said. </p></blockquote>
<p>Several GIG of data, that&#8217;s a hell of a lot of text.</p>
<p>They were using a pretty basic program though, haxdoor.</p>
<blockquote><p>The data was collected by a malicious software program nicknamed Haxdoor that infected victims&#8217; computers. Some 2,300 machines were located in the U.K. McMurdie said.</p>
<p>Haxdoor is a powerful program that can collect passwords and send them to another e-mail address plus disable a computer&#8217;s firewall, among other functions, according to a description posted on security vendor F-Secure Corp.&#8217;s Web site. Symantec Corp., another security company, wrote it first detected Haxdoor in November 2003.</p>
<p>Computers can get infected with Haxdoor if they don&#8217;t have security patches or up-to-date antivirus software. London police said it&#8217;s believed many victims were infected through instant message programs. </p></blockquote>
<p>Nice to see the good guys also using technology to parse the data and locate victims.</p>
<blockquote><p>Metropolitan police experts built a special program to search through the data and identify victims, she said. The data contained information such as logins and passwords for major Web sites such as eBay Inc., Amazon.com, BT Group PLC and Pipex Internet Ltd., a U.K. Internet service provider.</p>
<p>In some instances, Haxdoor employed a screen-capture function to obtain information, McMurdie said.</p></blockquote>
<p></p>
<p>Source: <a href="http://www.infoworld.com/article/06/10/24/HNukdatatheft_1.html">Infoworld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Massive+Data+Theft+Operation+Uncovered+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D383+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;t=Massive+Data+Theft+Operation+Uncovered" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;title=Massive+Data+Theft+Operation+Uncovered" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;title=Massive+Data+Theft+Operation+Uncovered" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;title=Massive+Data+Theft+Operation+Uncovered" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/&amp;title=Massive+Data+Theft+Operation+Uncovered" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F12%2Fmassive-data-theft-operation-uncovered%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/12/massive-data-theft-operation-uncovered/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Top 5 Causes of Data Loss</title>
		<link>http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/</link>
		<comments>http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/#comments</comments>
		<pubDate>Mon, 23 Oct 2006 19:05:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[chamber-of-commerce]]></category>
		<category><![CDATA[data-loss]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[magnetic-stripe-data]]></category>
		<category><![CDATA[security-patches]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[top-5]]></category>
		<category><![CDATA[weak-passwords]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/</guid>
		<description><![CDATA[An interesting enough article, but if you work in infosec you could probably guess the topics anyway. In a key step to help businesses better understand and protect themselves against the risks of fraud, Visa USA and the U.S. Chamber of Commerce announced the five leading causes of data breaches and offered immediate, specific prevention [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting enough article, but if you work in infosec you could probably guess the topics anyway.</p>
<p>In a key step to help businesses better understand and protect themselves against the risks of fraud, Visa USA and the U.S. Chamber of Commerce announced the five leading causes of data breaches and offered immediate, specific prevention strategies for each.</p>
<p>&#8220;The single, most effective weapon in the battle against today&#8217;s data theft is education,&#8221; said Sean Heather, executive director, U.S. Chamber of Commerce.</p>
<ol>
<li>Storage of Magnetic Stripe Data &#8211; The most common cause of data breaches occurs when a merchant or service provider stores sensitive information encoded on the card&#8217;s magnetic stripe in violation of the PCI Data Security Standard. This can occur because a number of point-of-sale systems improperly store this data, and the merchant may not be aware of it.</li>
<li>Missing or Outdated Security Patches &#8211; In this scenario, hackers are able penetrate a merchant or service provider&#8217;s systems because they have not installed up-to-date security patches, leaving their systems vulnerable to intrusion.</li>
<li>
Use of Vendor Supplied Default Settings and Passwords &#8211; In many cases, merchants receive POS hardware or software from outside vendors who install them using default settings and passwords that are often widely known to hackers and easy to guess.</li>
<li>SQL Injection &#8211; Criminals use this technique to exploit Web-based applications for coding vulnerabilities and to attack a merchant&#8217;s Internet applications (e.g. shopping carts).</li>
<li>
Unnecessary and Vulnerable Services on Servers &#8211; Servers are often shipped by vendors with unnecessary services and applications that are enabled, although the user may not be aware of it. Because the services may not be required, security patches and upgrades may be ignored and the merchant system exposed to attack.</li>
</ol>
<p>Did you get them right?</p>
<p></p>
<p>Source: <a href="http://www.aviransplace.com/2006/09/15/top-five-causes-of-data-compromises/">Aviransplace</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Top+5+Causes+of+Data+Loss+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D344+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;t=The+Top+5+Causes+of+Data+Loss" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;title=The+Top+5+Causes+of+Data+Loss" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;title=The+Top+5+Causes+of+Data+Loss" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;title=The+Top+5+Causes+of+Data+Loss" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/&amp;title=The+Top+5+Causes+of+Data+Loss" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fthe-top-5-causes-of-data-loss%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/the-top-5-causes-of-data-loss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

