Attacks/Breaches

Target Breach: HVAC Contractor Systems Investigated

Hackers may have used access credentials stolen from refrigeration and HVAC system contractor Fazio Mechanical Services to gain remote access to Target's network.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
johnson54
100%
0%
johnson54,
User Rank: Apprentice
10/29/2014 | 1:28:39 PM
Installation Contractor
A potential contractor must have the necessary credentials and experience to do the job perfectly. A good way to choose a contractor is to interview them. This will assure you of good customer service. So, think twice before you choose a siding installation contractor.
awinter015
50%
50%
awinter015,
User Rank: Apprentice
3/11/2014 | 10:26:01 AM
Anyone ever hear about VLANs?
The idea that a contractor was on a shared network with other systems is mind-boggling.  The technology to segement networks and limit access of users has been around for years.  Even in small environments we segment customers from one another, accounting systems from general systems, etc.  So if we can do it as a small IT Service provider - why cant the big guys do it?

 

 
mak63
50%
50%
mak63,
User Rank: Apprentice
2/9/2014 | 10:10:52 PM
Re: answers
I couldn't agree with Mr Gezelter and you more.

As someone on the informationweek staff recently told me: "live and learn" Too bad the customers will suffer the most for something that could've been avoided.
Michael Endler
100%
0%
Michael Endler,
User Rank: Apprentice
2/8/2014 | 5:01:22 PM
Re: answers
"As isolated as a driver in Los Angeles in the rush hour. Again, because we know about the breach, the answer is that the HVAC appliances were not iisolated as they should have been."


This seems like the big failing. Bob Gezelter alluded to it in his post too:

"There is simply no reason why the network access granted to an HVAC contractor for monitoring HVAC equipment should have included access to the production transactional data network. Being somewhat speculative, the POS terminals and supporting systems should have been in a separate network compartment, with an encrypted tunnel connecting the store-located systems to the transactional back end systems serving the corporation."


I can't see why the HVAC techs were connected to a network that included Target's customer data.
mak63
50%
50%
mak63,
User Rank: Apprentice
2/8/2014 | 12:28:31 AM
answers
Did Target secure Fazio's access to its network using two-factor authentication?

Probably I'm wrong for saying this, but if the credentials were stolen, what difference would have made how many level of authentication you had in place?

What level of network access did Target grant to Fazio?

There was a breach, so the answer is clear to me. Pretty much all what the hackers needed.

Were Target's HVAC appliances located on an isolated network segment that should have prevented attackers from accessing other network-connected systems?

As isolated as a driver in Los Angeles in the rush hour. Again, because we know about the breach, the answer is that the HVAC appliances were not iisolated as they should have been.

 
mak63
100%
0%
mak63,
User Rank: Apprentice
2/8/2014 | 12:09:09 AM
Re: The Internet of...
@Somedude8

If the antivirus fails to detect a malware in the microwave, we're doom, dooom and we'll also get sick for eating uncooked food. Luckyly the TV will know this and will recommend Alka-Seltzer or something like that.
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
2/7/2014 | 10:13:52 AM
Re: The Internet of...
How many hops from an HVAC system to a cash register? The Internet of Things is going to be a hoot.
Bob Gezelter
100%
0%
Bob Gezelter,
User Rank: Apprentice
2/7/2014 | 8:39:51 AM
Compartmented Networks are important; Access should require "Need to Know"
Sadly, the reported pathology is a represents a long-solved problem. Since the mid-1990's, it has been well-understood that protecting devices connected to a network requires more than a single level of protection. The access limitations to different groups of systems cannot be implemented by a single set of firewall rules. This was noted in my Security on the Internet chapter in the 1995 Computer Security Handbook, 3rd Edition (Hutt, Bosworth, and Hoyt; Wiley). My 2008 presentation on Compartmented Networks from the 11th New York State Cybersecurity Conference described how to implement and use such networks.

There is simply no reason why the network access granted to an HVAC contractor for monitoring HVAC equipment should have included access to the production transactional data network. Being somewhat speculative, the POS terminals and supporting systems should have been in a separate network compartment, with an encrypted tunnel connecting the store-located systems to the transactional back end systems serving the corporation.


Such a network topology greatly limits the ways in which a critical system can be compromised.


- Bob Gezelter, http://www.rlgsc.com; Contributing Editor, Computer Security Handbook (3rd, 4th, 4th, and 6th Editions)
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Moderator
2/6/2014 | 5:48:36 PM
Breach of outside consultant opened up Pacific NW National Labs
It was an outside, off-premises researcher whose computer workstation was compromised that gave hackers access to the Pacific Northwest National Labs in its July 2011 security breach. It's very hard for a good IT organization to know what all of its contractors are doing.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/6/2014 | 3:58:48 PM
Re: The Internet of...
This really demonstrates that the convergence of physical security with IT security has defintely arrived... Be warned!
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8551
Published: 2014-11-26
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

CVE-2014-8552
Published: 2014-11-26
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.

CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?