User comments on ISPs
  >> PlusNet plc


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | [4] | 5 | 6 | (show all)   Print Thread
Standard User h0tblack
(fountain of knowledge) Tue 15-May-07 13:55:19
Print Post

Re: Reading between the lines


[re: blewit] [link to this post]
 
Definitely.
I'd agree that some problems are only known after they have been exposed, but who exposes those and how people react are key. Work can (and is) put into hardening security by those who take it seriously. This ranges from the monitoring described right through to more proactive attempts to break a system. It's better for a friend to find a flaw than a foe. I wonder if PlusNet have ever had an impartial external assessment of their policies?
Standard User phil100
(committed) Tue 15-May-07 14:14:19
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
Hi Paddy,
I don't think this is an inside job due to the nature of the announcement...

"It has come to our attention that a number of customer email addresses have been obtained illegally by a third party."

To me a third party is someone other than
1st Party - Plusnet
2nd Party - customer(s)

The 3rd Party is yet to be confirmed.



ZeN
Standard User blewit
(committed) Tue 15-May-07 14:21:42
Print Post

Re: Reading between the lines


[re: phil100] [link to this post]
 
3rd party could also be an ex-employee - which I'd pretty much class as an "Inside Job" ...

Given that it looks like it was Webmail that was compromised and that the platform runs publically-available software I'm guessing it was "just-another-hacker" who's been trying random atmail installs he could find and just "stumbled" across Plusnet ...


Register (or login) on our website and you will not see this ad.

Standard User Rastus
(committed) Tue 15-May-07 14:41:47
Print Post

Re: Reading between the lines


[re: phil100] [link to this post]
 
In reply to:

I don't think this is an inside job due to the nature of the announcement...

"It has come to our attention that a number of customer email addresses have been obtained illegally by a third party."



I think we can assume that in this case the third party being referred to is the spammer/s, therefore it could still possibly have involved an "insider".

Rob

PlusNet Premier Option 1 MaxDSL @ 8128 / 448
DrayTek Vigor2800VG (Firmware v2.7.1_E38)
Standard User deleted
(deleted) Tue 15-May-07 14:54:07
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
Copy of email to be sent http://usergroup.plus.net/forum/index.php/topic,4761.msg62039.html#msg62039

Much ado about taking security seriously, but nothing to back it up, empty words with are contradicted by the last couple of days.
Standard User deleted
(deleted) Tue 15-May-07 15:06:05
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
I shall wait and see the actual email that I receive by this does seem to be very poor and lacking in real information/help. For example:

1. The Trojan they refer to in the email seems to exploit a hole that was fixed in September last year and so anyone applying a Windows Update since then shouldn't be affected. A specific date would help people who don't update frequently.
2. Some advice on how to combat the spam would also be useful.
Standard User deleted
(deleted) Tue 15-May-07 15:06:45
Print Post

Re: Reading between the lines


[re: IanWild] [link to this post]
 
In reply to:



If I could just ask that you don't read too much into the removal of Wireless and a couple of other things for the minute - Overnight we conducted some pretty serious screw tightening across the board, but what we are aware of relates solely to the Webmail platform.




/me *sighs* not the first time this has happined has it ian? looks like your "screw tightening" the last time wasnt that tight after all!
Standard User deleted
(deleted) Tue 15-May-07 15:08:11
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
its not the first time they have had to do some 'screw tightening' overnight - had a similar situation back in 2004.

its about time plusnet sack whoever is responsible for the serious (lack of) security within their network.
Standard User h0tblack
(fountain of knowledge) Tue 15-May-07 15:22:01
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
One would assume PlusNet are currently totally blocking all e-mail from the known sources of this outbreak or all that match the patterns of the outbreak. This is why they were able to say the problem has been 'resolved'. The problem is sadly not that easy to solve though.
Standard User deleted
(deleted) Tue 15-May-07 15:23:37
Print Post

Re: Reading between the lines


[re: h0tblack] [link to this post]
 
If that is the case then it is not a fix for me because I am now tied to PN for my email unless I want to receive lots of spam as a result of their security lapse. Not good.
Pages in this thread: 1 | 2 | 3 | [4] | 5 | 6 | (show all)   Print Thread

Jump to