iTnews
  • Home
  • News
  • Technology
  • Security

AAPT hack exploited 'very old' Cold Fusion hole

By Darren Pauli
Jul 27 2012 1:01PM
Follow google news

Stolen data held on dedicated server.

The vulnerability used by Anonymous hackers to breach and obtain data from AAPT and Queensland Government websites was "very old", sources have told iTnews' sister site SC Magazine.

AAPT hack exploited 'very old' Cold Fusion hole

AAPT yesterday confirmed a 12-month-old backup of its business website had been compromised with hackers retrieving two "historic" data files with "limited personal customer information" compromised. The data, which is yet to be released, could amount to 600,000 records kept in a 40 GB file.

The hackers involved in the attacks told SC they broke into the dedicated server, hosted by Melbourne IT, through an unpatched Adobe Cold Fusion vulnerability.

But an industry security expert close to the incident, and speaking on the condition of anonymity, said the flaw was "very old".

"We know that the version of Cold Fusion was very old at Melbourne IT, which from an incidence response point-of-view creates a series of challenges," they said.

"Something like Cold Fusion requires Java underneath it, and other packages — so responding to a threat means you have to scope the threat."

His report corroborates claims from some involved in the attack that the vulnerability has been publicly known since 2008.

Though it is expected the patching, upgrading and updating would have been a complex process, a spokesman for Melbourne IT said the issue was fixed "within the hour" on late Tuesday night.

The same Cold Fusion vulnerability was used in a twin attack on another dedicated server hosted by Melbourne IT in which hundreds of megabytes of seemingly benign databases owned by Queensland Government tourism sites were stolen and posted online.

The source said Melbourne IT was "flat out working with AAPT and law enforcement" and "providing some assistance to other customers".

The hosting provider did not respond to questions about whether it had contacted police. Questions to the Australian Federal Police about its involvement were deferred on without response to the Attorney-General's Department.

The Department's information security response agency, CERT Australia, condemned the attacks but would not confirm its involvement in incident response.

Victoria Police referred matters of its involvement to Melbourne IT.

Melbourne IT become aware of the vulnerability after hacked Queensland Government sites were defaced on Tuesday but AAPT data was stolen by the time the patch was applied.

"The server contained AAPT data that appears to match the data Anonymous is claiming to possess," spokesman Tony Smith told iTnews on Thursday

Though the Anonymous-linked hackers first threatened to release ISP data as early as 2pm on Tuesday, Smith said it had not approached AAPT until Wednesday afternoon.

The compromised server was later shut down at 9.30pm on Wednesday night.

"It was closed well before [AAPT was notified of the breach]," he said.

He said the company's engineers were still investigating the issue and scanning the hosting provider's remaining servers for the potential Cold Fusion vulnerability.

Security boffins at rival telcos were understood to have lent a hand to AAPT, but Melbourne IT refused to comment on details on its incident response handling.

A former electronic crimes police officer told SC that Melbourne IT, following best practice, would have moved to preserve data through a specialist third party forensic firm before calling police.

The high-profile hacks came in apparent protest to the Federal Government's proposed data retention regime, which would mandate telcos and internet service providers to collect and keep transmission data from users for up to two years.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
aaptadobeanonymousdata breachhackingincident responsemelbourne itsecuritytelco/isptelecommunicationsvulnerabilities

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Superloop self-serve AI resolutions top 330,000 cases Superloop self-serve AI resolutions top 330,000 cases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
Join our WhatsApp Channel

Partner Content

Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.