Melbourne IT takes heat for Cold Fusion breach

Powered by SC Magazine
 

How one hole delivered AAPT data and Qld Govt sites.

Melbourne IT has admitted to hosting and operating both the Queensland Government and AAPT servers that suffered breaches this week at the hands of hackers purporting to be from a Anonymous splinter group.

The group Ops Australia took credit for defacing nine Queensland Government websites related to tourism, science and economic development and stealing a 40 GB trove of customer data from corporate ISP AAPT.

The text-based defacements on Queensland sites were removed shortly after news broke of the attacks. The group is yet to publicly release the AAPT customer data, despite confirmation from the telco that it had been compromised.

The high-profile hacks came in apparent protest to the Federal Government's proposed data retention regime, which would require telcos and internet service providers to collect and store transmission data from users for up to two years.

Attackers exploited an existing vulnerability in the Adobe Cold Fusion application server used to run both live versions of the affected Queensland sites and an old version of AAPT's business website that the company claimed had not been used for more than 12 months.

AAPT claimed that two "historic" data files had been breached with "limited personal customer information" compromised.

Tony Smith, corporate communications general manager at Melbourne IT, told iTnews that the company had first become aware of the vulnerability after the site defacements late on Tuesday and had patched the issue "within the hour".

But the vulnerability had not been closed before "data had been uploaded from that server to the internet".

"The server contained AAPT data that appears to match the data Anonymous is claiming to possess," Smith said.

"At the moment we can't confirm whether it is [Anonymous]; at the moment it's based on suspicion. We're still conducting forensic investigations into the incident and we're continuing to keep the customer informed."

Smith said the vulnerability was cleared from the "handful of servers" it was found on.

Data for the Queensland Government and AAPT were kept on separate, dedicated servers.

Though the Anonymous-linked hackers first threatened to release ISP data as early as 2pm on Tuesday, Smith said it had not approached AAPT until Wednesday afternoon.

The compromised server was later shut down at 9.30pm on Wednesday night.

"It was closed well before [AAPT was notified of the breach]," he said.

He said the company's engineers were still investigating the issue and scanning the hosting provider's remaining servers for the potential Cold Fusion vulnerability.

Smith would not confirm whether the Australian Federal Police had become involved in the issue, but a source in the industry told iTnews it was likely the authorities would investigate.

The AFP referred questions to the federal Attorney-General's department, which said it was "inappropriate to comment" on the issue.

A spokeswoman for the Australian Privacy Commissioner told iTnews it had not been informed of the breach but would be seeking information on the issue.

Copyright © iTnews.com.au . All rights reserved.


Melbourne IT takes heat for Cold Fusion breach
 
 
 
Top Stories
Australian Govt to rethink cyber security strategy
Six-year old policy to be refreshed.
 
The failure of the antivirus industry
[Blog post] Insights from AVAR 2014.
 
At the top of her game
A decision to bring digital operations back in-house three years ago has paid big dividends for Tabcorp.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 1002

Vote