funsec mailing list archives

Man bought VPN server from eBay, got access to council's internal network


From: Juha-Matti Laurio <juha-matti.laurio () netti fi>
Date: Mon, 29 Sep 2008 23:51:25 +0300 (EEST)

This is great:

"Andrew Mason from security firm Random Storm bought some network hardware from auction site eBay for 99p.

When he switched it on and plugged it in, the device automatically connected to the internal network of Kirklees 
Council in West Yorkshire.
..."

and

"Subsequent investigation found that the internet, or IP, address to which it connected was owned by Cap Gemini, in a 
range of addresses allocated to Kirklees Council.

"It is like having a long ethernet cable from the Council office to anywhere where I connected the device," said Mr 
Mason."

More at
http://news.bbc.co.uk/2/hi/technology/7635622.stm
 
Juha-Matti
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: