Bye-Bye Bank Account

| | Comments (1) | TrackBacks (0)

It looks like bank account and retirement account theft are going to be this years "stolen laptop." By that I mean it will be the story that is reported with increasing frequency.

Today's story is found in Techworld. It seems that some participants in the Governments Thrift Savings Plan had a keystroke logger installed on their computers. The bad guy used the login and account information to electronically transfer cash to other accounts.

"External penetration testing has demonstrated that our system has not been breached," the TSP said. "There is no evidence of any successful attacks against the system to identify a PIN and thus obtain access."

This is kind of a strange quote. The failure of an external pen test to identify any holes does not demonstrate that the system hasn't been breached. To determine if the system has been breached, you would need to examine the system logs, IDS logs, etc. To trust those logs it would be necessary to have used a third party log server to preserve the integrity of the logs. A forensic examination of the systems may be needed.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Bye-Bye Bank Account.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/436

1 Comments

Max Penn said:

Yes...

a las it seems often times people prefer to protect their jobs, themselves, and keep things quiet, rather than trying to fix things.

Security matters and concerns are often swept under the rug.

Max

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on January 22, 2007 6:30 PM.

More Stormwatch was the previous entry in this blog.

JAVA install/uninstall is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.23-en