<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Zecurion Company Blog</title>
	
	<link>http://www.zecurion.com/server-software-blog</link>
	<description>Data Storage Security, Data Loss Prevention</description>
	<lastBuildDate>Thu, 26 Aug 2010 03:23:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/zecurion/qwAh" /><feedburner:info uri="zecurion/qwah" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Supermarket Customer Data Breached by SQL Injection Hack</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/fhqoOwCYidg/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/08/supermarket/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 03:23:39 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[customer data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=228</guid>
		<description><![CDATA[Neo Beat&#8211;an online Japanese Supermarket&#8211;reported that data on nearly 13,000 customers was compromised as a result of a SQL injection attack against its database. Credit card companies have reported that there have been fraudulent charges racked up as a result of the stolen customer data.
A report from Japan Today states &#8220;A source close to Neo [...]]]></description>
			<content:encoded><![CDATA[<p>Neo Beat&#8211;an online Japanese Supermarket&#8211;reported that data on nearly 13,000 customers was compromised as a result of a SQL injection attack against its database. Credit card companies have reported that there have been fraudulent charges racked up as a result of the stolen customer data.</p>
<p>A <a href="http://www.japantoday.com/category/crime/view/hackers-steal-customer-data-by-accessing-supermarket-database" target="_blank">report from Japan Today</a> states &#8220;A source close to Neo Beat, which also operates the websites of these online supermarkets, said it believes that the approximately 30,000 unauthorized accesses to its database server were likely ‘‘perpetrated by a group of professional hackers.&#8221; Japan Today also states &#8220;The company’s investigation has found that its database program has a security vulnerability which made it difficult to block attempts from outside to intrude into the database server.&#8221;</p>
<p>Organizations should have sufficient perimeter defenses to prevent unauthorized access to internal servers, and there should be tools in place to monitor access and detect suspicious activity, but there are two other lessons to be learned here. First, IT admins need to stay informed of vulnerabilities affecting critical systems like customer database servers and make sure they are patched in a timely manner. Second, had the data been protected with encryption&#8211;using a tool  like <a href="http://www.zecurion.com/zserver.php" target="_blank">Zecurion Zserver Storage</a>&#8211;the hackers would have retrieved nothing but useless gibberish and the customer data wouldn&#8217;t be compromised in spite of the other security weaknesses.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/fhqoOwCYidg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/08/supermarket/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/08/supermarket/</feedburner:origLink></item>
		<item>
		<title>RAID Provides Data Integrity and Availability, But Not Security</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/HIZm36BTJ90/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/08/raid-provides-data-integrity-and-availability-but-not-security/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 03:27:23 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Data Storage Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[RAID]]></category>
		<category><![CDATA[Zserver Storage]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=225</guid>
		<description><![CDATA[
In the storage realm RAID architecture continues to be very popular and is widely used by different vendors because it allows for the combination of different hard drives into one fast, reliable and
spacious storage device that satisfies nearly all enterprise data storage needs. However, along with all the well known benefits of RAID architecture a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: Calibri; font-size: small;"><span style="font-family: Calibri; font-size: small;"></p>
<p align="left">In the storage realm RAID architecture continues to be very popular and is widely used by different vendors because it allows for the combination of different hard drives into one fast, reliable and<br />
spacious storage device that satisfies nearly all enterprise data storage needs. However, along with all the well known benefits of RAID architecture a common misconception continues to exist; many IT<br />
professionals still believe that the data stored on RAID devices is secure.</p>
<p align="left">This false belief stems from the basic concept of RAID – distributing the data among many hard drives which disrupts files formats and makes the stealing of one particular hard drive from the RAID system useless for an attacker. This <a href="http://www.zecurion.com/uploads/RAID_not_Considered_Storage.pdf" target="_blank">white paper highlights the threats to data in a RAID architecture</a> and outlines why additional data protection procedures should be employed to ensure complete protection and compliance with the ever-increasing regulatory mandates for securing sensitive data.</p>
<p></span></span></p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/HIZm36BTJ90" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/08/raid-provides-data-integrity-and-availability-but-not-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/08/raid-provides-data-integrity-and-availability-but-not-security/</feedburner:origLink></item>
		<item>
		<title>Hell Pizza Needs to Add Some Encryption to the Menu</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/ytPuA8S5DSA/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/08/hell-pizza-needs-to-add-some-encryption-to-the-menu/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 03:28:44 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Hell Pizza]]></category>
		<category><![CDATA[New Zealand]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=223</guid>
		<description><![CDATA[A popular pizza chain in New Zealand&#8211;Hell Pizza&#8211;has been victimized by cyber attackers. The personal information&#8211;including name, address, email address, phone number, account password, and even past pizza orders&#8211;of over 230,000 Hell Pizza customers has been exposed in the database breach.
Hell Pizza director Warren Powell said &#8221;We are honestly taking this very seriously. The last thing [...]]]></description>
			<content:encoded><![CDATA[<p>A popular pizza chain in New Zealand&#8211;Hell Pizza&#8211;has been <a href="http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&amp;objectid=10661073" target="_blank">victimized by cyber attackers</a>. The personal information&#8211;including name, address, email address, phone number, account password, and even past pizza orders&#8211;of over 230,000 Hell Pizza customers has been exposed in the database breach.</p>
<p>Hell Pizza director Warren Powell said &#8221;We are honestly taking this very seriously. The last thing we have wanted to do is inconvenience our customers. We take customers&#8217; personal details bloody seriously and we spend a lot of money on security.&#8221;</p>
<p>Apparently, Hell Pizza needs to learn that the quality of the security spending is more important than the quantity. Unfortunately, spending the most money is not a valid measure of the effectiveness of network security measures. Had Hell Pizza <a href="http://www.zecurion.com/zserver.php" target="_blank">invested in Zserver Storage</a>, the information on the breached database would have been encrypted and the only thing exposed to attackers would be useless gibberish.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/ytPuA8S5DSA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/08/hell-pizza-needs-to-add-some-encryption-to-the-menu/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/08/hell-pizza-needs-to-add-some-encryption-to-the-menu/</feedburner:origLink></item>
		<item>
		<title>Cooper University Reports Personal Data on Missing Thumb Drive</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/sreeU3_dJhs/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/08/cooper-university-reports-personal-data-on-missing-thumb-drive/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 03:01:33 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[Cooper University Hospital]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[USB thumb drive]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=220</guid>
		<description><![CDATA[ABC News in Philadelphia&#8211;WPVI&#8211;reports that Cooper University Hospital is missing a USB thumb drive containing sensitive personal data on medical students, residents, and fellows.
It is unknown whether the thumb drive was stolen, or simply lost. But, what is known is that the missing thumb drive contains Social Security numbers, addresses, and phone numbers of the [...]]]></description>
			<content:encoded><![CDATA[<p>ABC News in Philadelphia&#8211;WPVI&#8211;reports that Cooper University Hospital is <a href="http://abclocal.go.com/wpvi/story?section=news/local&amp;id=7578794" target="_blank">missing a USB thumb drive</a> containing sensitive personal data on medical students, residents, and fellows.</p>
<p>It is unknown whether the thumb drive was stolen, or simply lost. But, what is known is that the missing thumb drive contains Social Security numbers, addresses, and phone numbers of the affected individuals.</p>
<p>Cooper University Hospital issues a statement explaining &#8220;Cooper University Hospital is investigating the circumstances surrounding a missing thumb drive. The thumb drive contained information with personal data about graduate medical education residents and fellows for the current and prior academic years. We have advised the residents and fellows who were advised to contact their local police. No other employee information was compromised. Further, No patient information or records were compromised.&#8221;</p>
<p>There is no indication that the data on the thumb drive was a violation of policy in any way, but it is worth noting that USB thumb drives are a significant security concern for all organizations. Portable storage media capable of holding 32Gb or more of data could contain untold volumes of sensitive or confidential information. IT admins should employ <a href="http://www.zecurion.com/zlock.php" target="_blank">Zecurion&#8217;s Zlock</a> to restrict access for storing data on removable media. For additional data protection, the data on removable or portable media should also be encrypted so it can&#8217;t be compromised even if the device is lost or stolen.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/sreeU3_dJhs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/08/cooper-university-reports-personal-data-on-missing-thumb-drive/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/08/cooper-university-reports-personal-data-on-missing-thumb-drive/</feedburner:origLink></item>
		<item>
		<title>Personal Info of 93,000 Exposed in University Data Breach</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/zwdTkW0yCuA/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/07/personal-info-of-93000-exposed-in-university-data-breach/#comments</comments>
		<pubDate>Sun, 01 Aug 2010 03:03:18 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[Buena Vista University]]></category>
		<category><![CDATA[compromised]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[exposed]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=217</guid>
		<description><![CDATA[Buena Vista University announced that a database was compromised containing data such as names, Social Security numbers, and driver&#8217;s license numbers of 93,000 students, parents, current and former faculty and staff, alumni and donors dating back to 1987.
Had the information stored in the database been encrypted, the breach of the database would not have exposed [...]]]></description>
			<content:encoded><![CDATA[<p>Buena Vista University announced that a <a href="http://www.securityweek.com/buena-vista-university-data-breach-%E2%80%93-93k-individuals-potentially-exposed" target="_blank">database was compromised </a>containing data such as names, Social Security numbers, and driver&#8217;s license numbers of 93,000 students, parents, current and former faculty and staff, alumni and donors dating back to 1987.</p>
<p>Had the information stored in the <a href="http://www.zecurion.com/zserver.php" target="_blank">database been encrypted</a>, the breach of the database would not have exposed the sensitive data.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/zwdTkW0yCuA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/07/personal-info-of-93000-exposed-in-university-data-breach/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/07/personal-info-of-93000-exposed-in-university-data-breach/</feedburner:origLink></item>
		<item>
		<title>Zeus Compromises Student Data at University of Oklahoma</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/LapBaNANsLs/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 21:40:14 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[exposed]]></category>
		<category><![CDATA[OU]]></category>
		<category><![CDATA[Social Security numbers]]></category>
		<category><![CDATA[University of Oklahoma]]></category>
		<category><![CDATA[Zeus botnet]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=214</guid>
		<description><![CDATA[The University of Oklahoma has revealed that a laptop compromised by a variant of the Zeus botnet may have exposed or compromised sensitive information on OU students&#8211;including Social Security numbers. There are no further details yet available regarding the scope of the potential compromise. According to this blurb from KOCO.com, though, &#8220;OU officials said they [...]]]></description>
			<content:encoded><![CDATA[<p>The University of Oklahoma has revealed that a laptop compromised by a variant of the Zeus botnet may have exposed or compromised sensitive information on OU students&#8211;including Social Security numbers. There are no further details yet available regarding the scope of the potential compromise. According to this <a href="http://www.koco.com/mostpopular/24031441/detail.html" target="_blank">blurb from KOCO.com</a>, though, &#8220;OU officials said they are not aware of any instances of identity theft or similar problems as a result of the breach, but they said they can&#8217;t be certain that student information was not compromised.</p>
<p>One way that OU would be able to be certain that student information was not compromised is if the data stored on the laptop, or on servers the laptop has access to was encrypted. I am not sure why these incidents seem to occur almost exclusively at medical establishments and educational institutions, but simply <a href="http://www.zecurion.com/zserver.php" target="_blank">investing in the proper security controls</a> up front can save time, money, and embarrassment for the organization, as well as protecting the personal and sensitive information the organization has been entrusted with.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/LapBaNANsLs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/07/zeus-compromises-student-data-at-university-of-oklahoma/</feedburner:origLink></item>
		<item>
		<title>Zserver Protects Data in the Cloud</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/F165dvHAIs4/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 03:27:01 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Data Storage Security]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[ComputerWorld]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Flushing Bank]]></category>
		<category><![CDATA[Zecurion]]></category>
		<category><![CDATA[Zserver Storage]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=211</guid>
		<description><![CDATA[A ComputerWorld article title Cloud Security in the Real World: 4 Examples cites Zecurion&#8217;s Zserver as a cloud-based storage encryption solution. 
Examining the issue of data encryption in the cloud, the article states &#8220;Several providers of cloud-based backup storage install appliances at the customer site to accommodate encryption, but Flushing was not interested in that setup.&#8221;
It also explains &#8220;At [...]]]></description>
			<content:encoded><![CDATA[<p>A ComputerWorld article title <a href="http://news.idg.no/cw/art.cfm?id=3C6AFD79-1A64-67EA-E45767CFAC0C9C06" target="_blank">Cloud Security in the Real World: 4 Examples </a>cites Zecurion&#8217;s Zserver as a cloud-based storage encryption solution. </p>
<p>Examining the issue of data encryption in the cloud, the article states &#8220;Several providers of cloud-based backup storage install appliances at the customer site to accommodate encryption, but Flushing was not interested in that setup.&#8221;</p>
<p>It also explains &#8220;At Flushing Bank in New York, CIO Allen Brewer turned to the cloud for data backup after getting fed up with on-site tape backup. Using <a href="http://www.zecurion.com/zserver.php" target="_blank">Zserver</a> from Zecurion, Flushing is now sending files over the Internet to be stored for backup.&#8221;</p>
<p> Read the white paper <a href="http://www.zecurion.com/uploads/Protect%20Your%20Customer%20Data%20in%20the%20Cloud.pdf" target="_blank">Protecting Data in the Cloud</a> to learn more about encrypting and protecting data in the cloud with Zecurion&#8217;s Zserver.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/F165dvHAIs4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/zserver-protects-data-in-the-cloud/</feedburner:origLink></item>
		<item>
		<title>Tufts University Alumni Data Exposed by Malware</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/i7JxJEAjh3I/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 02:56:40 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Social Security numbers]]></category>
		<category><![CDATA[Tufts University]]></category>
		<category><![CDATA[Zserver Storage]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=209</guid>
		<description><![CDATA[What is it about networks and data at universities and medical establishments? It seems like almost every breach of sensitive or personal data is related to these two types of institutions. Are they targeted more often than other types of networks, or do they just have weaker security and poorer data protection mechanisms in place?
Following [...]]]></description>
			<content:encoded><![CDATA[<p>What is it about networks and data at universities and medical establishments? It seems like almost every breach of sensitive or personal data is related to these two types of institutions. Are they targeted more often than other types of networks, or do they just have weaker security and poorer data protection mechanisms in place?</p>
<p>Following on the heels of the recent <a href="http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/" target="_blank">botnet compromise</a> at Penn State University, <a href="http://www.boston.com/news/education/higher/articles/2010/06/09/letters_to_tufts_alumni_warn_of_security_breach/" target="_blank">Tufts University has discovered</a> that &#8220;several computers were recently exposed to an unknown virus or malicious software program.&#8221; As a result, roughly 7000 alumnus may have had their student ID numbers exposed&#8211;and like Penn State University the breached data is legacy data from a time when the university used the student&#8217;s Social Security number as their student ID number.</p>
<p>Universities, including both Penn State University and Tufts University, have abandoned that practice, but apparently have not found the time to go back through archive data and old databases to purge legacy information from the servers. While that is still a good idea, and a project that these universities should be pursuing, having <a href="http://www.zecurion.com/zserver.php" target="_blank">sufficient data protection controls</a> in place, such as encrypting the stored data, would ensure that it would not be exposed even in the event of a malware compromise or breach of the server itself.</p>
<p>A small investment in proactive security measures goes a long way and saves the organization from the lost reputation, time, and money involved in responding to a data breach incident.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/i7JxJEAjh3I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/tufts-university-alumni-data-exposed-by-malware/</feedburner:origLink></item>
		<item>
		<title>Penn State Server Compromised by Botnet</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/XL_goowSpmA/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 03:28:32 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Penn State]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=206</guid>
		<description><![CDATA[Penn State University has sent out data breach notification letters to nearly 16,000 individuals to let them know that a computer in its Outreach Market Research and Data office was found to be actively communicating with a malicious botnet and that personal information including Social Security numbers may have been compromised.
Penn State has not used SSNs [...]]]></description>
			<content:encoded><![CDATA[<p>Penn State University has <a href="http://www.infosecurity-us.com/view/9976/penn-state-data-may-have-been-exposed/" target="_blank">sent out data breach notification letters</a> to nearly 16,000 individuals to let them know that a computer in its Outreach Market Research and Data office was found to be actively communicating with a malicious botnet and that personal information including Social Security numbers may have been compromised.</p>
<p>Penn State has not used SSNs as a student identifier for 5 years, however an archived copy of a legacy database apparently still existed on the compromised server.</p>
<p>A Penn State spokesperson explained that “We have, of course, standard defenses: site-licensed antivirus, unit firewalls, patching, vulnerability scanning, web application scanning, intrusion detection and blocking of confirmed hostile sites or frequently probed ports. When a machine is compromised, it must be re-installed from known ‘good’ media before it&#8217;s allowed back on the network, since it&#8217;s not possible to truly clean a machine that&#8217;s been fully compromised.&#8221;</p>
<p>All of those are excellent security controls and fit nicely with established security best practices. However, the data itself <a href="http://www.zecurion.com/zserver.php" target="_blank">should be encrypted</a> so that if and when an attacker figures out how to circumvent those defenses the data itself will still be impervious to unauthorized access.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/XL_goowSpmA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/penn-state-server-compromised-by-botnet/</feedburner:origLink></item>
		<item>
		<title>An Unenforced Policy is the Same as No Policy at All</title>
		<link>http://feedproxy.google.com/~r/zecurion/qwAh/~3/rRTUVssjZrk/</link>
		<comments>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 04:53:29 +0000</pubDate>
		<dc:creator>tbradley</dc:creator>
				<category><![CDATA[Security Breaches & Data Loss Incidents]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[sensitive data]]></category>
		<category><![CDATA[USB memory stick]]></category>
		<category><![CDATA[Zlock]]></category>

		<guid isPermaLink="false">http://www.zecurion.com/server-software-blog/?p=204</guid>
		<description><![CDATA[The West Berkshire Council has just learned this lesson the hard way. According to a recent report of lost data &#8220;West Berkshire introduced encrypted memory sticks in 2006. But following an investigation by the Information Commissioner&#8217;s Office (ICO), it was also discovered that council employees were still using unencrypted memory sticks.&#8221;
In a perfect world, simply [...]]]></description>
			<content:encoded><![CDATA[<p>The West Berkshire Council has just learned this lesson the hard way. According to a <a href="http://www.publicservice.co.uk/news_story.asp?id=13126" target="_blank">recent report of lost data</a> &#8220;West Berkshire introduced encrypted memory sticks in 2006. But following an investigation by the Information Commissioner&#8217;s Office (ICO), it was also discovered that council employees were still using unencrypted memory sticks.&#8221;</p>
<p>In a perfect world, simply stating that data should only be stored on approved USB devices, and that all data on portable storage media must be encrypted would be good enough. In the real world, though, simply stating it is not good enough. Stating a policy&#8211;without any means of monitoring or enforcing compliance with it&#8211;is simply paying lip service to data protection and gambling that a data breach incident will never occur.</p>
<p>West Berkshire Council lost that gamble when an unencrypted USB memory stick containing sensitive information relating to the ethnicity, and mental and physical health of children was lost. The report also contains this quote &#8220;It is essential that organisations ensure the correct safeguards are in place when storing and transferring personal information, especially when it concerns sensitive information relating to children.&#8221;</p>
<p>The best option to ensure correct safeguards are in place is <a href="http://www.zecurion.com/zlock.php" target="_blank">Zlock</a>. Zlock allows IT administrators to restrict users from writing to data to unapproved portable storage media. Access can be locked down to devices from a particular manufacturer, or of a particular type. A specific USB memory stick can be associated with each individual user, and all other memory sticks can be blocked.</p>
<p>In the case of West Berkshire Council, Zlock would have been instrumental in ensuring  that users relied on the encrypted USB memory sticks they were issued four years ago, rather than storing data on the now lost unencrypted USB memory stick.</p>
<img src="http://feeds.feedburner.com/~r/zecurion/qwAh/~4/rRTUVssjZrk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.zecurion.com/server-software-blog/2010/06/an-unenforced-policy-is-the-same-as-no-policy-at-all/</feedburner:origLink></item>
	</channel>
</rss>
