Risk
2/6/2011
06:52 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Nasdaq Hack. Lots of Questions. Few Answers

According to a news report this weekend, hackers breached web-based applications owned by the NASDAQ. How deep did the attacks go, and who was behind them?

According to a news report this weekend, hackers breached web-based applications owned by the NASDAQ. How deep did the attacks go, and who was behind them?A news story from The Wall Street Journal reported that attackers had penetrated, on multiple occasions, the computer networks of the company that runs the Nasdaq Stock Market. According to the story federal investigators are working to uncover the criminals. The Nasdaq trading platform was not affected, the story claimed. The story was based on unnamed sources.

It wasn't the Nasdaq stock market that the attackers were after it turns out, but information from the boards of directors of publicly traded companies. To get that, it was their Web-based collaboration platform – Directors Desk – that was the target.

This statement from Nasdaq says that the company detected suspicious files on U.S. servers and determined: that our web facing application Directors Desk was potentially affected. We immediately conducted an investigation, which included outside forensic firms and U.S. federal law enforcement. The files were immediately removed and at this point there is no evidence that any Directors Desk customer information was accessed or acquired by hackers.

The The Wall Street Journal, in a follow-up story, reported that the exchange will be run as usual for trading on Monday.

According its own Web site, Directors Desk is used by 10,000 directors at Fortune 500 sized companies. That's a trove of information, so no shocker the system was targeted.

The Nasdaq OMX was no slouch when it comes to security, either:

Operational Security

Our policies comply with the ISO27001 security standard, providing multiple levels of protection to guard our clients' confidential data against undesired access. The ISO27001 standard includes employee background screening; policies that restrict physical and logical access to classified information; management of information systems; firewalling; intrusion detection; risk assessment; and guaranteed destruction of expired data.

Application Security

Directors Desk provides multiple layers of security to protect our clients' most vital corporate records.

User authentication is tightly controlled through "strong passwords," fully encrypted transport, procedures surrounding account activation, and encryption of all service level passwords in the system.

Role-based security protocols control which content is available to each user upon logging in.

Network and host-based Intrusion Detection Systems (IDS) protect all hardware and applications in the Directors Desk server farm

Complying with security standards, having good authentication and authorization systems in place is great. So are IDS systems. But no matter how many layers of security are in place, what matters is how well it's all orchestrated together. That's why lists of standards being adhered to, as well as security technologies in place don't really tell us much about how secure an organization is.

So far, not much information about this hack. Hopefully, Nasdaq is correct, and no customer information was stolen. But we still don't know who was behind the attack, and can only assume that it was board secrets that the attackers sought.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

CVE-2014-0600
Published: 2014-08-29
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

CVE-2014-0888
Published: 2014-08-29
IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.

CVE-2014-0897
Published: 2014-08-29
The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection me...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.