This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Crimeserver discovered w/1.4GB stolen data

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.finjan.com/Pressrelease.aspx?id…=1819&lan=3
May 6, 2008 - "Finjan… today announced its discovery of a server controlled by hackers (Crimeserver) containing more than 1.4 Gigabyte of business and personal data stolen from infected PCs. The data consisted of 5,388 unique log files. Both email communications and web-related data were among them. The compromised data came from all around the world and contained information from individuals, businesses, as well as renowned organizations, including healthcare providers. To illustrate the scope; the server contained among others 571 log files from the US, 621 from Germany (DE), 322 from France (FR), 308 from India (IN), 232 from Great Britain (GB), 150 from Spain (ES), 86 from Canada (CA), 58 from Italy (IT), 46 from the Netherlands (NL), and 1,037 from Turkey (TR). Due to the sheer impact, Finjan followed its company guidelines and promptly notified over 40 major international financial institutions located in the US, Europe and India whose customers were compromised as well as various law enforcements around the world.
The report contains examples of compromised data that Finjan found on the Crimeserver, such as:
* Compromised patient data
* Compromised bank customer data
* Business-related email communications
* Captured Outlook accounts containing email communication
Finjan’s Malicious Code Research Center (MCRC) detected a Crimeserver which was used as a command and control for the Crimeware that was executed on infected PCs. This Crimeserver was also used as the “drop site” for private information being harvested by that Crimeware. The Command & Control applications on this Crimeserver enabled the hacker to manage the actions and performance of his Crimeware, giving him control over the uses of the Crimeware as well as its victims. Since the stolen data was left unprotected on the Crimeserver, without any access restrictions or encryption, the data were freely available for anyone on the web, including criminal elements…"
- http://www.finjan.com/Content.aspx?id=1367

:smack: :oops: :ph34r:
FYI…

- http://www.finjan.com/MCRCblog.aspx?EntryId=1957
May 18, 2008 - "In our recent MPOM report, we reported on a Crimeserver hosting 1.4G of unprotected stolen data, including passwords, medical data, emails etc. Many people asked us how we found the data. Was the data secure or not? Although we cannot disclose all information to the public (for obvious reasons), I can say that the data on that Crimeserver was unprotected, meaning anyone could access it. Today we came across another Crimeserver - it seems that we are finding one every other day… malicious code is hosted on caching servers of leading Search Engine Providers. This time we reported in our recent MPOM that stolen end-user data is also stored on these caching servers. Yes, your passwords, Social Security numbers, Online banking information… no data is safe… Here we go again, all is available on the cache server… Please note that when we report on stolen data hosted on an unprotected Crimeserver, that’s what we really mean to do. It’s not a hoax as some people wrote; it’s 100% harsh reality. We share our experience and findings with you to increase public awareness of the growing cybercrime problem. But please, don’t blame Google - they just indexed the unprotected Log files found on the Crimeserver as they do with any other public file their crawlers find on the Web…"

(Screenshots available at the Finjan URL above.)

:angry: :ph34r: