News
[Security]| Monday 29th September 2008 |
Andrew Mason bought the Cisco VPN 3002 Concentrator - a device on which he has written a tutorial book - on Ebay for only 99 pence, with the intention of using it at work.
However, when he plugged it in it automatically connected him directly to Kirklees Council's central servers, circumventing security with the login details which had been carelessly left on the device.
"It instantly connected me, and I had full network access," explains Mason. "I understand the law extremely well and at that point disconnected," adds the intrusion-detection professional.
Despite contacting the council about the matter, no action was taken. "They ignored me at first," says Mason, before explaining that following coverage on the BBC website, access from the device has been shut off.
He admits
ADVERTISEMENT |
|
The council says it is "deeply concerned" by the news, but is confident that "multiple layers of security have prevented access to systems and data."
"In the meantime the disposal process has been suspended until an investigation can be carried out and appropriate action taken," says a statement released by the council.
Top 5 stories on PC Pro
1. Government admits massive enrgy waste
2. GNU creator lashes out at web services
3. Third Phorm trial starts tomorrow
Submit to: Digg | Slashdot | Del.icio.us | Technorati
Find practically any item! Buy it. Sell it. Love it. eBay.co.uk






