- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
Hiring Manager: Emphasize Integrity, Attitude 14/12/2007 11:18:07
William Howell shares his hiring mistakes and his secrets for selecting the best job candidates, finding objective references and using LinkedIn as a recruiting tool.William Howell shares his hiring mistakes and his secrets for selecting the best job candidates, finding objective references and using LinkedIn as a recruiting tool.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
CRM your salespeople will love
Best Practice in Building an Integrated Information Management Strategy
Solve Exchange Mailbox Storage Issues Once and for All
Web Security SaaS: The Next Generation of Web Security
Revolutionising Back-up and Recovery
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Why Security SaaS Makes Sense Today
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
The theft of personal information from some 1.3 million users of the Monster.com job search service first revealed two weeks ago was not a one-time attack, the company's CEO said Wednesday.
"The Company has determined that this incident is not the first time Monster's database has been the target of criminal activity," Sal Iannuzzi, the chairman and CEO of Monster Worldwide, said in a statement. In an interview with Reuters, Iannuzzi also acknowledged that the most recent breach may have been substantially larger than the 1.3 million users the company said earlier had been affected.
"It could easily be in the millions," Iannuzzi told Reuters. He did not spell out when other attacks had taken place or even how many might have breached the company's security.
Iannuzzi was divulging the prior attacks, he said, to give all Monster.com users fair warning. "Due to the significant amount of uncertainty in determining which individual job seekers may have been impacted, Monster felt that it was in your best interest to take the precautionary steps of reaching out to all Monster job seekers regarding this issue."
A second statement released by the company Wednesday reiterated its inability to tell users whether their information had been compromised. "Despite ongoing analysis, the scope of this illegal activity is impossible to pinpoint," the company said.
On Aug. 17, Symantec security analyst Amado Hidalgo told Monster that he'd found the names, e-mail addresses, home addresses, phone numbers and resume identification numbers representing more than a million of its users on a hacker-controlled server hosted in Ukraine. Hidalgo theorized -- and several days later, Monster confirmed -- that the data had been retrieved using legitimate log-on credentials stolen from recruiters and human resource personnel with corporate Monster.com accounts.
Within days, Monster.com said it had shut down the data-storing server, which was also used by an aggressive hacker crew to spam the users whose data was stolen. Some of the spam duped those users into self-infecting their PCs with online bank account password stealers, while other junk mail campaigns tried to convince job seekers into working as "money mules," the term for people who launder the money stolen from phished bank accounts.
A week ago, evidence surfaced of Monster.com-fueled attacks beginning in early July. Some job seekers, however, claimed they had seen similar messages as far back as February. Iannuzzi's admission Wednesday supported the claims of a long-running exploit of the company's database.
"Monster has launched a series of initiatives to enhance and to protect the integrity of the information you have entrusted to us," Iannuzzi said. "Some of these steps are being immediately implemented, while others will be put into place as appropriate."
In an accompanying statement, Monster.com said that the new security measures included adding new site monitoring and surveillance capabilities, and reviewing and tightening its site access policies and controls.
As recently as Aug. 19, however, Monster.com said that the second step -- tightening access -- might be impossible. "From time to time, our legitimate customers' credentials are used to gain unauthorized access to the database, and it would be very difficult to be 100 percent certain that any given access using legitimate credentials is indeed legitimate," said spokesman Steve Sylven then.
One possible measure the site could take would be to disable automated or script-based searches; the attackers seeded Trojans that robotically searched the massive Monster.com database using the same techniques that corporate recruiters rely on. Early in the case, a Monster.com spokesman said that it was essentially impossible to tell the difference between a legitimate automated search done by a corporate account holder and one run by the hacker's Trojan.
In addition, Monster.com hired an unspecified number of "industry security experts" who specialize in helping corporations protect customer data. Ironically, in late July, Monster.com selected Cyveillance, an Arlington, Va.-based firm that specializes in protecting enterprise assets from malware attacks.
According to a statement issued July 23 by Cyveillance, the company was supposed to protect Monster.com's users from phishing and malware attacks. Cyveillance was also set to monitor various sources for any abuse of the Monster brand or logo.
The spam spewed out by the Infostealer.Monstres Trojan -- the malware that snatched the personal information from the Monster.com database -- was designed to look like legitimate e-mail from the job search site.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Wireless LANs: Is my enterprise at risk?
Achieve an overall understanding of the risks associated with wireless LANs. Discover their inherent properties, as well as what makes them different from wired networks. Read on to uncover a list of recently published articles on real-life breaches and incidents illustrating the need for proactive measures to mitigate wireless security risks.










