User comments on ISPs
  >> PlusNet plc


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | (show all)   Print Thread
Standard User soundsystem
(knowledge is power) Thu 24-May-07 00:40:42
Print Post

Web mail Incident Report (FULL Not link)


[link to this post]
 
Our customers will be aware of a recent serious security issue affecting our Webmail service. This document contains the results of our investigation and what actions we are now taking to minimise the resulting impact for our customers.

We are extremely sorry for the inconvenience and upset this may have caused our customers. We hope this report will provide some reassurance to our customers about how seriously we are taking these events.

Contents
1. Incident Summary

2. Breakdown of events

3. Our response and plans going forward


Incident Summary

Further details, explanations and answers to questions we have been asked are below the summary section.

What happened?

A malicious attack was performed against vulnerability in our implementation of our Webmail software which allowed the attackers to:


- Take a copy of our webmail database, which contained the email addresses of customers who have used Webmail. This also included email addresses contained in customers

Edited by soundsystem (Thu 24-May-07 00:50:58)

Standard User rsharma
(knowledge is power) Thu 24-May-07 00:59:37
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: soundsystem] [link to this post]
 
Honesty is always a good thing and should be congratulated. The dates have been confirmed and an acknowledgement that they missed the issue when first raised. I would love to put more thoughts down in words but am too tired to do this tonight. Will pick up on this at lunch time tomorrow if I get a chance. The thread will probably be 10 pages long by then...

-------------------------------------------------------
Plusnet: The Truth (Blog)
Formal Complaints Process
Testing Connection Speeds
Plusnet LLU and Your Rights
Standard User linux
(newbie) Thu 24-May-07 02:10:29
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: soundsystem] [link to this post]
 
> Only customers without up-to-date Windows software and inadequate anti-virus software would have the Trojan affect their PCs.

That is simply not true. My PC has neither up-to-date Windows software nor any anti-virus software. Yet it was still not at risk because it doesn't have Windows at all. My PC is a Microsoft-free zone.

I do wish people would stop assuming that "Windows" and "PC" are synonymous.

Edited by linux (Thu 24-May-07 02:13:01)


Register (or login) on our website and you will not see this ad.

Standard User h0tblack
(knowledge is power) Thu 24-May-07 02:24:46
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: rsharma] [link to this post]
 
Indeed, overall a very positive report. Obviously there will be more questions and discussion, but as you say it's late. And for now I think everyone involved in making the report and getting it out should be given the chance to take a moment and pat themselves on the back. And accept my (and I'm sure others) thanks. It's the sort of humble, clear and informative thing it's good to see. Well done

It's also great to see many of the changes that have been asked for for years finally being put into place and what looks like a very clear and honest change in attitude and company ethic. Having a dedicated security team is possibly overdue but again at least it's now happening. Once the practicalities of getting customers immediate problems is dealt with I'm sure there is plenty that individuals and the company as a whole have learnt that can be used to make things better for everyone.
Standard User Nick_Russell
(committed) Thu 24-May-07 07:41:42
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: soundsystem] [link to this post]
 
Great respopnse from PlusNet. Full marks to them.

Nick

PlusNet Broadband Your Way Option 2 DSLMax Netgear DG834G router
Standard User camieabz
(legend) Thu 24-May-07 07:52:25
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: soundsystem] [link to this post]
 
This is really for the attention of the PN Support, but worth having out in the open.

In reply to:

1) The ability to change your username

2) Get a free .uk domain name

3) SSL encrypted connections for POP3 and IMAP email and FTP

4) Improvements to the

Standard User deleted
(deleted) Thu 24-May-07 08:24:14
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: linux] [link to this post]
 
It was also worth noting that the compromised Servers were:- "Each of these machines was a Linux server".

Just proves that, when it comes to the crunch, Linux appears to be vulnerable to hacking & vulnerabilities as well!
Standard User deleted
(deleted) Thu 24-May-07 08:27:09
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: soundsystem] [link to this post]
 
Under the circumstances, appears to be a very good posting by PN!!

Hopefully, this is an indication of PN returning to their "culture", of a few years back, when they were ALWAYS fully open & honest with their customers!
Standard User deleted
(deleted) Thu 24-May-07 09:17:13
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: deleted] [link to this post]
 
I didn't see anything about vulnerabilities in Linux. I only read about server configuration issues and Perl/PHP issues - neither of which point to a Linux vulnerability.
Standard User deleted
(deleted) Thu 24-May-07 09:39:46
Print Post

Re: Web mail Incident Report (FULL Not link)


[re: deleted] [link to this post]
 
It was the atmail application that was vulnerable, not the underlying OS, hence why it was reported to the application developers.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | (show all)   Print Thread

Jump to