ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Keeping security in check

John Verry

Published: 11 Oct 2005 14:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Ethical hacking is one of the most intriguing and exciting elements of our work at Pivot Point Security. A recent engagement for an International Bank took us a bit by surprise as the level of security provided by an Application Service Provider (ASP) to protect the identities of the banks clients and hundreds of millions of dollars was notably less than one would expect. I'll show you the techniques that we used and how our efforts turned from hacking their critical application, to hacking the Application Service Provider, to hacking another bank's hosted network.

A call to arms
On a Monday morning in the not-too-distant past, we received a call from an Information Security engineer at a major international bank, who we will refer to as Bank Client (BC) from this point forward. An industry colleague that frequently worked with us in support of our projects (and vice versa) on network and security architecture referenced them to us. This was not a typical introductory call to vet our capabilities; this was a call to engage our services.

"We have a few concerns regarding the security of an application that is hosted by a third party on our behalf. How soon can you come on site and perform an ethical hack against the application?" he queried. Still surprised by the directness of the call, I offered, "I think we could get resources on site early next week."

He replied: "We were really hoping that we could get this done no later than the end of the week" reinforced the urgency of the call.

"If it's that important I think we can move some personnel around and get there on Thursday," I said quietly as I prayed that I wouldn't take too much grief from our project manager for reallocating his resources, but it's not every day that an opportunity this intriguing rears its head.

"OK, let me confirm everything with our management," he said. "We'll be in touch, shortly."

On Tuesday morning a signed purchase order...

For more, click here...

Next

Previous

1 2 3 4 5


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
257 out of 520 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Linux Systems Administrator - Linux Windows XP, Network Connectivity

You will be a Linux Redhat Systems Administrator who is happy to provide Windows user support, manage network (Cisco LAN/WAN TCP/IP VPN) as well as ...

Senior IT Auditor - Investment Bank

You will join one of the largest audit teams in the sector, working in teams of around 5 people you will report your findings into the IT Audit ...

UNIX Solaris Administrator Cheshire 40,000

The key to the role is to provide support and enhancement of live services hosted on a Unix environment, and will involve 24/7 on-call support. A ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment