Attacks/Breaches

Target Breach: HVAC Contractor Systems Investigated

Hackers may have used access credentials stolen from refrigeration and HVAC system contractor Fazio Mechanical Services to gain remote access to Target's network.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
johnson54
100%
0%
johnson54,
User Rank: Apprentice
10/29/2014 | 1:28:39 PM
Installation Contractor
A potential contractor must have the necessary credentials and experience to do the job perfectly. A good way to choose a contractor is to interview them. This will assure you of good customer service. So, think twice before you choose a siding installation contractor.
awinter015
50%
50%
awinter015,
User Rank: Apprentice
3/11/2014 | 10:26:01 AM
Anyone ever hear about VLANs?
The idea that a contractor was on a shared network with other systems is mind-boggling.  The technology to segement networks and limit access of users has been around for years.  Even in small environments we segment customers from one another, accounting systems from general systems, etc.  So if we can do it as a small IT Service provider - why cant the big guys do it?

 

 
mak63
50%
50%
mak63,
User Rank: Apprentice
2/9/2014 | 10:10:52 PM
Re: answers
I couldn't agree with Mr Gezelter and you more.

As someone on the informationweek staff recently told me: "live and learn" Too bad the customers will suffer the most for something that could've been avoided.
Michael Endler
100%
0%
Michael Endler,
User Rank: Apprentice
2/8/2014 | 5:01:22 PM
Re: answers
"As isolated as a driver in Los Angeles in the rush hour. Again, because we know about the breach, the answer is that the HVAC appliances were not iisolated as they should have been."


This seems like the big failing. Bob Gezelter alluded to it in his post too:

"There is simply no reason why the network access granted to an HVAC contractor for monitoring HVAC equipment should have included access to the production transactional data network. Being somewhat speculative, the POS terminals and supporting systems should have been in a separate network compartment, with an encrypted tunnel connecting the store-located systems to the transactional back end systems serving the corporation."


I can't see why the HVAC techs were connected to a network that included Target's customer data.
mak63
50%
50%
mak63,
User Rank: Apprentice
2/8/2014 | 12:28:31 AM
answers
Did Target secure Fazio's access to its network using two-factor authentication?

Probably I'm wrong for saying this, but if the credentials were stolen, what difference would have made how many level of authentication you had in place?

What level of network access did Target grant to Fazio?

There was a breach, so the answer is clear to me. Pretty much all what the hackers needed.

Were Target's HVAC appliances located on an isolated network segment that should have prevented attackers from accessing other network-connected systems?

As isolated as a driver in Los Angeles in the rush hour. Again, because we know about the breach, the answer is that the HVAC appliances were not iisolated as they should have been.

 
mak63
100%
0%
mak63,
User Rank: Apprentice
2/8/2014 | 12:09:09 AM
Re: The Internet of...
@Somedude8

If the antivirus fails to detect a malware in the microwave, we're doom, dooom and we'll also get sick for eating uncooked food. Luckyly the TV will know this and will recommend Alka-Seltzer or something like that.
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
2/7/2014 | 10:13:52 AM
Re: The Internet of...
How many hops from an HVAC system to a cash register? The Internet of Things is going to be a hoot.
Bob Gezelter
100%
0%
Bob Gezelter,
User Rank: Apprentice
2/7/2014 | 8:39:51 AM
Compartmented Networks are important; Access should require "Need to Know"
Sadly, the reported pathology is a represents a long-solved problem. Since the mid-1990's, it has been well-understood that protecting devices connected to a network requires more than a single level of protection. The access limitations to different groups of systems cannot be implemented by a single set of firewall rules. This was noted in my Security on the Internet chapter in the 1995 Computer Security Handbook, 3rd Edition (Hutt, Bosworth, and Hoyt; Wiley). My 2008 presentation on Compartmented Networks from the 11th New York State Cybersecurity Conference described how to implement and use such networks.

There is simply no reason why the network access granted to an HVAC contractor for monitoring HVAC equipment should have included access to the production transactional data network. Being somewhat speculative, the POS terminals and supporting systems should have been in a separate network compartment, with an encrypted tunnel connecting the store-located systems to the transactional back end systems serving the corporation.


Such a network topology greatly limits the ways in which a critical system can be compromised.


- Bob Gezelter, http://www.rlgsc.com; Contributing Editor, Computer Security Handbook (3rd, 4th, 4th, and 6th Editions)
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Moderator
2/6/2014 | 5:48:36 PM
Breach of outside consultant opened up Pacific NW National Labs
It was an outside, off-premises researcher whose computer workstation was compromised that gave hackers access to the Pacific Northwest National Labs in its July 2011 security breach. It's very hard for a good IT organization to know what all of its contractors are doing.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/6/2014 | 3:58:48 PM
Re: The Internet of...
This really demonstrates that the convergence of physical security with IT security has defintely arrived... Be warned!
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4497
Published: 2015-08-29
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token...

CVE-2015-4498
Published: 2015-08-29
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point i...

CVE-2014-9651
Published: 2015-08-28
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."

CVE-2015-1171
Published: 2015-08-28
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.

CVE-2015-2987
Published: 2015-08-28
Type74 ED before 4.0 misuses 128-bit ECB encryption for small files, which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smaller than 128 bits.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.