Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
News

Acxiom Hacking Details Made Public 142

pgrote writes "As mentioned previously, the Acxiom consumer database company was compromised. More details have emerged including the background of the alleged hacker and the method used to gather access. It turns out he had access since December of 2002 and came in through an unsecured FTP server. The suspect was not a former employee of Acxiom as previously reported, but an employee of data mining company."
This discussion has been archived. No new comments can be posted.

Acxiom Hacking Details Made Public

Comments Filter:
  • details? (Score:3, Informative)

    by trmj ( 579410 ) * on Sunday August 10, 2003 @06:58PM (#6661690) Journal
    There aren't many details in this, it simply says that the hacker got in through an unsecured FTP server, was arrested, and they don't think he distributed the information.

    Where are the details again?
  • No Excuse (Score:4, Insightful)

    by TedCheshireAcad ( 311748 ) <ted@fUMLAUTc.rit.edu minus punct> on Sunday August 10, 2003 @06:58PM (#6661695) Homepage
    At first I thought maybe this guy was a DBA or Sys Admin at the company, but an outsider? This is unacceptable for a place that stores such sensitive data.
    • An ex-employee.
    • Re:No Excuse (Score:4, Insightful)

      by AstroDrabb ( 534369 ) on Sunday August 10, 2003 @08:18PM (#6661973)
      Well the article I read said he was an employee of data mining company. Which means he had some inside knowlege of the systesm. He broke in through an external FTP server and did not get through their firewall. So I think Acxiom deserves a little break. There is no such thing as a 100% secure system, especially with inside knowlegde of the systems. As a programmer for a fortune 500 company, I could literally bring that company to it's knees and cause millions (USD) lost per day. However, I don't do that because I am a professional and would not use my skills to be abusive. I hope this dude get some hard time.
      • That statement was actually coined by Ben Franklin. I think his words were a little bit different, but both syntactically, intent, and meaning it was the same.

        Just letting you know. The only reason I know is cause it was a good quote to use back in my debating days.

      • Re:No Excuse (Score:1, Offtopic)

        by Sherloqq ( 577391 )
        He broke in through an external FTP server and did not get through their firewall. So I think Acxiom deserves a little break.

        I beg to differ. Matter of fact, I think it's absurd. Completely absurd to allow someone to gain access to sensitive data outside the firewall perimeter. How could anyone be so stupid? Damn, something as simple as https or ssh/scp would've solved that problem! Acxiom does NOT deserve a break, they deserve a group spanking from their shareholders and clients!
        • Why would https have made a difference? The problem here was that sensitive data was on an FTP outside the firewall. That's the problem here.
        • My point was that the guy had inside knowledge. NO amount of security is 100%. Not that Acxiom should be let off the hook, they obviously made some DUMB mistakes, however, I wonder how successful the guy would have been without that insider knowlegde.
    • I'm not sure if the article mentioned it, but sources inside the company (I worked there a little over a year ago) are telling me that he simply got access to the the FTP server used to transmit data from Acxiom to the company this guy worked for. Also, the data that he obtained was completely encrypted, so it's likely he didn't get any actual useful data. Just a bunch of encrypted bits that aren't probably useful to him at all.
  • Do they know exactly what info was taken? If so, how were the victims notified? I know if it was my info in there, I'd be pretty pissed if they didn't tell me about it.
    • Re:Victims (Score:3, Funny)

      by Exiler ( 589908 )
      No, actually you'd be like 'oooh, something shiney!' while looking at a random techy toy, because if they didn't tell you about it you wouldn't have been informed and therefore could not have been pissed.
    • Re:Victims (Score:5, Insightful)

      by Anonymous Coward on Sunday August 10, 2003 @07:55PM (#6661870)
      I know if it was my info in there, I'd be pretty pissed if they didn't tell me about it.

      Your info was in there. And they didn't. And you are so not pissed you will never read this, never cancel your cards and start using cash, never write a congressmen, and just move on to the next slashdot story about legos and linux.

  • Question (Score:5, Insightful)

    by Henry V .009 ( 518000 ) on Sunday August 10, 2003 @06:59PM (#6661701) Journal
    How is it hacking if you publish it on your FTP server? I'm sure no one would call it hacking if the protocol had simply been http instead. Now, this fellow may have used the information for nefarious purposes, and if there is any law he broke in doing so, go get him. But I don't see this as hacking.
    • Re:Question (Score:5, Informative)

      by rritterson ( 588983 ) * on Sunday August 10, 2003 @07:05PM (#6661730)
      According to one of the the articles, he broke the encryption on the passwords used to login to the FTP server. I call that cracking, which would be labeled hacking in the general lexicon.
      • Re:Question (Score:1, Redundant)

        by Alien Being ( 18488 )
        Then they must not have taken the appropriate precautions. They either used weak passwords, sent them in the clear at one time or ignored a brute force attack on the server. They were careless with their customer's data. I don't know if the kid had any malicious intent, but I'm glad he brought their problem into the light.

      • Re:Question (Score:5, Interesting)

        by rainer_d ( 115765 ) * on Sunday August 10, 2003 @07:22PM (#6661779) Homepage
        According to one of the the articles, he broke the encryption on the passwords

        When was the last time you saw a FTP-server that allowed to download its own password-file ? 1990 ?
        This is ridiculous - if I'd encounter one, I'd ask myself if it was a honeypot.

        Also, the various journalists' view (and the subsequent picture created by them for their readers) of "hacking", "cracking", "security" etc. is sometimes so distorted, so far-off from the reality of the people closer involved with the subject that reading a mainstream-press article about it is often only marginally better than just making-up the facts from slashdot-postings !

        Rainer

        • Re:Question (Score:4, Informative)

          by Vinson Massif ( 88315 ) on Sunday August 10, 2003 @08:19PM (#6661975) Homepage
          "When was the last time you saw a FTP-server that allowed to download its own password-file ? 1990 ?"

          Not an admin, eh?

          Many _default_ non-anonymous ftp services on unix|unix-like systems that I have dealt (recently) with allow the ftp user the same access rights to the entire tree as their uid:gid is allowed. So, on a system w/o shadow passwords, cd /etc; get passwd; is all that's needed to get started. (grr ./ eats spaces...)

          BTW, shadow passwording has the achilles heel of file security. I have dealt with systems where the file security of these files had been comprimised to solve some silly need.
          • Re:Question (Score:1, Funny)

            by Anonymous Coward
            So, on a system w/o shadow passwords, cd /etc; get passwd; is all that's needed to get started.

            Well if you're still running a system without shadow password support you need to get your head out of the sand and upgrade or migrate to something that isn't so obsolete. WTF are you running, SCO Unixware?

            • -1, pointless SCO reference.

              I quite like that, when I saw it, your comment was moderated 'funny'. You did read my entire comment, yes?

              In this case, I suspect there was a series of poor admin descisions, one of was allowing ftp access, that lead to the end comprimise.
      • Didn't read that. In the article I read, the FTP server was 'unsecured.'
  • So what? (Score:3, Interesting)

    by zifty ( 692892 ) on Sunday August 10, 2003 @07:00PM (#6661704)
    If this wasn't known since December of 2002, what cause do I have not to believe it's been happening everywhere? Being a victim hasn't affected ME yet, once it does, I'll fight the bill, get a new card number, and be on my way. This is relatively meaningless to us.
  • Keep going (Score:5, Interesting)

    by Pig Hogger ( 10379 ) <(moc.liamg) (ta) (reggoh.gip)> on Sunday August 10, 2003 @07:00PM (#6661705) Journal
    Keep going at it. Eventually, people are going to be SO PISSED at their personal data being spewed forth all over the place, there will be a terrible backlash that will make the European Data-Protection and Privacy laws seem tame enough...
    • by Anonymous Coward on Sunday August 10, 2003 @07:53PM (#6661861)
      when they passed the income tax in 1913 that only hit the top ten percent of people. When U. Sinclair wrote the Jungle, people said that now the food industry will be cleaned up. Do you know what I ate for lunch ? No, I don't either. That's what they said about Roosevelt's new deal. Oh, Hitler smashed all the Jewish businesses ? Surely now the people will diselect him. When the EPA started telling private landowners the land was public because it flooded once a year, they all said "that's great, surely we'll have a groudswell now." When the Brady Bill was passed, people said "ok now the people will really revolt." How long have we lived under the Patriot Act's extra-constitutional government now ?

      Face it, if you want to protect your self there is no hope in waiting for the masses to get pissed. Just start fighting.
      • by Anonymous Coward
        What is this: anarchist capitalist neo-nazi samuray ninja rebel yapi hippy fighter?

        Fight for my protection?
        I'm not a stupid consumer, I always give as much false information as I can on the internet, and I sure as hell don't give personal data to stupid companies.

        If stupid lusers are damaged by these, I laugh. I support the hackers 100% on this one.
  • Some guy probably left a windows server sending out warez on the company's bandwidth. The last time I had to deal with Windows servers (BLECH!), I found that the sysadmin was afraid to run FTP for security reasons.

    As Microsoft would say, "You should've firewalled off that port."
    • Re:ftp server? (Score:5, Informative)

      by jericho4.0 ( 565125 ) on Sunday August 10, 2003 @07:14PM (#6661761)
      Being afraid to run FTP for security reasons is valid on any platform. The list of breaches on various FTP servers is long.

      Still, I'd much rather be running an open source FTP server than some of those weak Windows versions.

      • Re:ftp server? (Score:5, Interesting)

        by DrSkwid ( 118965 ) on Sunday August 10, 2003 @08:37PM (#6662046) Journal
        then you'd like plan9's ftp

        it doesn't even use passwords

        it uses a kind of public key encryption called NetKey

        ftp DrSkwid@plan9ftp
        Welcome DrSkwid to the plan9 ftp server
        challenge : 345345
        response :

        And you have to run netkey locally and encrypt the challenge using your password.
        The server checks to see if its encrypted version matches and if so you're in.

        You can't replay it and good luck cracking it.

        If you don't want to be broken into don't use insecure things, oh and "root" is considered harmful. If you there is nothing to escalate privileges to then what point that rootkit?

        Makes me laugh people talking security with such a single point of failure waiting for exploitation.

      • I run guildFTPd on my server and havn't had any problems with it even with free anonymous FTP. I recently changed the anonymous FTP so it was write only (there's now a PHP file browser pointed at it for downloading) to prevent people from linking directly to ftp://www.icarusindie.com rather than http://www.icarusindie.com/ftp/ but even before it wasn't really an issue. Most people read and play by the rules.

        Ben
      • by wrax ( 570032 )
        seems most of the problems can be solved by using the sftp server that comes with ssh.
  • HACKER? (Score:1, Informative)

    by Anonymous Coward
    Would you plese stop using "hacker" word when the proper word would be "cracker"!

    You should know it better, you're Slashdot!
    • Relax. (Score:5, Insightful)

      by thatguywhoiam ( 524290 ) on Sunday August 10, 2003 @08:08PM (#6661930)
      Would you plese stop using "hacker" word when the proper word would be "cracker"!

      No. See, it's like this: practically everyone in the world associates 'hacker' with 'computer expert' and a fairly large percentage of those people also think 'nefarious' when they hear 'hacker'.

      I know you really, really want your word back, but you just can't have it. The populace has kidnapped it. This is what it means now. It won't change. It's jargon anyways, so the meaning is fluid.

      Hackers are computer experts who sometimes circumvent established systems, for learning or mischief. Crackers are small biscuits you eat.

    • Oh, please. Do you really want to swap one multi-definition word (explorer, malicious attacker) for another (malicious attacker, snack food, derogative term for caucasian)? Why bother? Every time someone mentions a cracker breaking in somewhere, all I can think of is some Nabisco saltine typing away at a keyboard and laughing manically. (of course, where it got arms and fingers I'm not as clear on.)

      Look, the whole hacker/cracker thing is pointless. Lots of words, especially some of the derogatory on
    • Re:HACKER? (Score:3, Informative)

      by alangmead ( 109702 )

      The term hacker was both used and misused long before anyone came up with the term cracker to be someone who breaks into computer systems. It was essentially an attempt to deflect the popular press away from the word hacker, and allow it to regain the former meaning of respect.

      It didn't work. The popular press hasn't let go of the word hacker to mean computer criminal. They haven't picked up on the term Cracker. Instead of trying to explain what hacker means [syndetic.org], we need to what hacker and cracker mean [ibm.com]

    • No.

      When I speak or write words mean exactly what *I* intend them to mean. No more, no less. I use them because I intend to transfer an idea in a specific way. Sometimes I make allowances for what the dictionary says, sometimes I deliberately mangle meanings to get the other person to understand. ("Press the "eject" button on the hard drive and pull out the floppy disk, then reboot.")

      If some fool mis-inteprets what I say when I did not intend to say it, it's their problem, not mine. Likewise, the confus
      • No.
        When I speak or write words mean exactly what *I* intend them to mean. No more, no less.

        When I use a word," Humpty Dumpty said, in a rather scornful tone, "it means just what I choose it to mean--neither more nor less."
        -- Lewis Carroll, Through the Looking Glass

        On the other hand:

        You keep using that word. I do not think that word means what you think it means
        -- Inigo Montoya, The Princess Bride

        Yup, pedantic, guilty as charged. Go ahead and mod me down; I can afford it.

  • by Anonymous Coward on Sunday August 10, 2003 @07:04PM (#6661728)
    get
  • Translation (Score:5, Funny)

    by Arker ( 91948 ) on Sunday August 10, 2003 @07:06PM (#6661738) Homepage

    According to law enforcement officials, the person arrested was a known sophisticated hacker.

    Translation from law enforcement language - this was a guy that knows what things like encryption, and ftp are. This was a guy that knows the difference between a megabyte and a megahertz. A real wizard. Be afraid.

    • by Danse ( 1026 ) on Sunday August 10, 2003 @07:43PM (#6661837)

      Wow. Sounds like getting busted can do wonders for your self-esteem. Here the guy was probably a basic loser and managed to "hack" into an unsecured FTP server. Then he gets busted for it. Suddenly he's no longer Joe Loser, he's a sophisticated hacker to be feared and respected for his mastery of such arcane skills as using a password cracking app and an FTP app. How can we ever feel safe with such diabolical people out there?

      • It may feel cool when the police call you a sophisticated hacker now. But as soon as you enter the courtroom, you're gonna have a hard time convincing the judge and jury that you're just some kid who stumbled across the wrong ftp:// address one evening during a pr0n r0mp.
  • What! (Score:2, Insightful)

    by Matt_Fisher ( 696201 )
    So you mean, that this company has a open FTP account that was rooted to the files of all that material! Is it just me or does that make you not want to trust anyone?
  • Disturbing (Score:5, Informative)

    by Bruha ( 412869 ) on Sunday August 10, 2003 @07:11PM (#6661753) Homepage Journal
    This more or less shows the fact that many companies have group passwords to their critical equipment instead of inplementing a choke system to allow users to login into it to show them where they can go and cant go.

    Since they probably dumped the company involved and not changed any of those passwords then this guy was allowed to basically walk around at will inside the databases.

    Such lax security in itself should also be criminal especially when it concerns consumer data and financial information of consumers.
    • by FuckMeter ( 695157 ) on Sunday August 10, 2003 @07:28PM (#6661801) Homepage
      ...is the mugshot [enquirer.com] of the guy responsible. Anyone want to start a pool on how many gallons of Bawls (and other ThinkGeek(TM) caffeinated products) this guy consumed in the 24 hours prior to his arrest??

      Rate Naked People! [fuckmeter.com] at Fuck Meter! (Not work-safe)
      • He probably hasn't had any sleep for the few days they held him in a bright ass cell with blaring Britney Spears music!
        Cruel and Inhumane? You Bet!!!

        • You're joking but depending on where he is being held that is exactly his condition.

          When I was arrested for bank robbery, I was held first for a few days in the San Francisco Country Jail - you do NOT sleep there unless you are unconscious because somebody knocked you out.

          Then I was moved to Alameda Country Jail because the Federal Detention Center at Dublin was overcrowded. There you could turn off the light and get some sleep at night IF you had a cellie who didn't want to stay up all night. During th
    • Re:Disturbing (Score:2, Interesting)

      I disagree.

      Let's say I have a single lock on the handle of my front door... with no dead bolt. Along comes someone and kicks the door open and proceeds to rob my house. While he's robbing my house he steals a cd that I borrowed from my friend. Are you saying that *I* should be arrested because I failed to install an adequate dead bolt on my front door and thus the robber stole a cd that didn't belong to me?

      What's adequate? Let's say I did install a dead bolt but the robber was sophisticated enough to pick
      • Some problems with your analagy:

        This isn't you holding a CD for your friend. This is a company that makes it's buisness the storing and compiling of this information. Say instead that you run a buisness out of your home and your buisness is the storing of CD collections. If you're broken into and those CDs stolen, you certainly would be liable - this is why people who do this sort of thing have insurance against it. The insurance company is going to be really pissed off that there was an unsecured FTP serv

      • Re:Disturbing (Score:5, Insightful)

        by FuckMeter ( 695157 ) on Sunday August 10, 2003 @07:58PM (#6661876) Homepage
        Let's say I have a single lock on the handle of my front door... with no dead bolt. Along comes someone and kicks the door open and proceeds to rob my house. While he's robbing my house he steals a cd that I borrowed from my friend. Are you saying that *I* should be arrested because I failed to install an adequate dead bolt on my front door and thus the robber stole a cd that didn't belong to me?
        You're comparing apples to oranges. In fact, you're comparing apples to... zebras, or something not even closely related.

        The first distinction is that in your example, your friend willingly loaned you the CD. I don't think anyone has intentionally "loaned" their personal information to Acxiom. Before the initial story was reported here, I'd never heard of Acxiom, though various articles proclaim them to be [one of] the biggest data-mining compan[y|ies] around. If they have any data on me, I sure as hell didn't loan it to them.

        The second problem with your analogy is that a CD is nothing like personal data. A CD is a vanity, something worth maybe $15, less now that it's used. Acxiom has been described as serving "most top credit card companies and retail banks." What do you think the credit card or bank details of a single person - much less however many people were affected by this breach - are worth? That $15 CD pales in comparison.
        What's adequate? Let's say I did install a dead bolt but the robber was sophisticated enough to pick both locks? In this case I shouldn't be arrested because I had "adequate" security and was victimized by a "skilled" robber who had the proper knowledge that surpassed my own in lock technology?
        Your analogy fails here as well. You, as a private citizen, do not have any liability for the stolen items. Your friend loaned you the CD, there was no business agreement surrounding that friendly exchange. Acxiom is a business, the rules are different.

        Suppose you rent a storage facility at one of those mini-storage places. Their property is surrounded by a chainlink fence complete with razorwire. The gate requires a keycode to enter. Each bay is padlocked. Now let's say some joker breaks into the place, gets into your bay and steals everything you have stored there. Surely a fence with razorwire, key-coded facility access, and padlocks are "adequate" security... But you're damn sure that the mini-storage company would be liable for your loss, unless that was covered in your contract with them.

        But, see, none of us have a contract with Acxiom.

        Acxiom is liable, one way or another.

        --
        Rate Naked People! [fuckmeter.com] at Fuck Meter (not work-safe)
        • FYI

          I don't think anyone has intentionally "loaned" their personal information to Acxiom. Before the initial story was reported here, I'd never heard of Acxiom, though various articles proclaim them to be [one of] the biggest data-mining compan[y|ies] around. If they have any data on me, I sure as hell didn't loan it to them.

          Acxiom collate, clean and break down client data for client companies, as far as I know they don't actually use it themselves. If you're in Acxioms db's, chances are someone you boug

      • 1. Analogies suck.

        2. If it were my CD, I'd want it back. Since the victim of the robbery is my friend, I'd be sympathetic and cut him some slack. But if he had insurance and the loss were covered, I'd expect him to fork over enough for a new CD. Obviously I'm not going to sue a friend over a lost CD in any case. But if the friend were grossly negligent -- i.e. not just having flimsy locks but, say, inviting crackheads to stay in his living room -- then I'd be pissed, and put the blame on him.

        3. You

  • This was done by an employee of a data mining company? To gather information about consumers? Hmmmm.. The RIAA been hiring some of those lately.. This could be a fun little conspiracy...
  • pathetic (Score:5, Funny)

    by Feztaa ( 633745 ) on Sunday August 10, 2003 @07:20PM (#6661778) Homepage
    From the article:

    "Acxiom is proud of its long-standing commitment to the security of our systems and our efforts toward continuous improvements in that area,"

    As far as I can tell, this guy logged into an ftp server and downloaded some publicly accessible files, perhaps after breaking some simple encryption to get a password or something. yes, that's some impressive security they have there...
  • by RenQuanta ( 3274 ) on Sunday August 10, 2003 @07:24PM (#6661789) Homepage
    ...but let's see what we can figure out from the article:

    The breach involved one FTP server outside the Acxiom firewall, the company said. No internal systems or internal databases were accessed, and there was no breach of the security firewall.

    Why did they have a server outside their firewall?!?

    The company said only a small percentage of its clients' data was involved in the incident, and the hacker, a former employee of an Acxiom client, was arrested.

    I guess they were trying to keep the article under a certain word count, because they forgot the word "alleged".

    According to law enforcement officials, the person arrested was a known sophisticated hacker. Acxiom said the person apparently gained access through the hacking of encrypted passwords.

    Okay, so this was probably little more than an attack against the /etc/shadow file if it's a UNIX box, or the SAM file if it's NT. In either case, I'm guessing they brute-forced / dictionary attacked the file with John the Ripper or the like. If that's what they did, how did they get the password file to begin with? Perhaps the FTP was a bit too willing to follow instructions? (recursion anyone? ;)

    After learning of the breach, Acxiom immediately moved to close the security gap and changed all passwords on the FTP server involved. The company is now in the process of communicating with all clients who might be potentially affected.

    Now, does that mean they had all users change their passwords, or just their passwords on that server? I wonder how many of those users have the same passwords on other machines as they had on the compromised FTP server...hmm.....

    "Acxiom is proud of its long-standing commitment to the security of our systems and our efforts toward continuous improvements in that area, so we deeply regret this breach," said Acxiom Company Leader Charles Morgan in the statement.
    Which is why their infrastructure was vulnerable to begin with? Why was their FTP server outside their firewall? Why aren't they using a Firewall proxy? How about FTP servers with jails? Without more details, it's impossible to be sure, but this smells like a successful attack due to careless configuration and insecure architecture
    • by bourne ( 539955 ) on Sunday August 10, 2003 @08:43PM (#6662068)

      Why did they have a server outside their firewall?!?

      I think that if you translate from Dumb Reporter to Technical you get "server on a service network or DMZ, available to the Internet but segregated from their internal network." That's standard practice, the thing has to be available to the Internet.

      In either case, I'm guessing they brute-forced / dictionary attacked the file with John the Ripper or the like

      Again, you need to translate here. Based on personal experience with similar organizations, I believe this translates to "He sniffed the plaintext (non-anonymous) FTP passwords off the Internet and used them to log in himself and get files."

      Now, does that mean they had all users change their passwords, or just their passwords on that server

      Translation: "We changed all the FTP passwords, so that they will be secure until the next time someone sniffs them.

      Which is why their infrastructure was vulnerable to begin with?

      Note that they also state the information he got was encrypted and not believed to have been used. It is not unusual for organizations like Acxiom to accept PGP or ZIP encrypted files via FTP. Obviously, that isn't good enough - if only because of the negative publicity that comes out of an incident like this - but that's what they do.

      The only sign of weak infrastructure here is FTP passing plaintext passwords over the Internet. I don't see any real evidence that anything else was compromised - except their PR shell.

      • I think that if you translate from Dumb Reporter to Technical you get "server on a service network or DMZ, available to the Internet but segregated from their internal network."

        Quite possibly so. Let's hope.

        That's standard practice, the thing has to be available to the Internet.

        I'm very well aware of standard practice, but I am also aware (from my own personal experience) of certain companies whom still have Internet-facing systems which are not behind a firewall. Legacy architecture has an amazing

    • smells like a successful attack due to careless configuration and insecure architecture

      Or like Acxiom pushed this data purposefully out to an insecure ftp server with a weak username and password as their security to be "hacked" by someone who wanted that info. Maybe they wanted him to have it, or carry it to some buyer, and gave them the password in some under the table deal..

      But for all I know its the government going after a known hacker with planted evidence or whatever. I mean, who can you trust t
    • I can answer part of this (I was an employee there a little over a year ago).

      The FTP server was likely one of the servers used to move data from Acxiom (who is simply a data processor) back to the client. So, the thing sits outside of the firewall. This was only done for customer data that was considered 'public record' or 'less sensitive' data. Which means that it's only the type of information that you can garner from various sources without to much trouble.

      The data was more than likely encrypted, and I
    • If that FTP server was meant to be accessible to the outside then putting it behind a firewall would have accomplished exactly nothing. The ports to it would be open anyway and he got in through the standard FTP port.

      "because they forgot the word "alleged"."

      If he admitted to the crime then "alledged" is no longer needed. He just needs to try to convince people he shouldn't be punished much.

      Ben
  • Hacking? (Score:2, Insightful)

    by Anonymous Coward
    Odd but where I come from anonymous ftp isn't hacking.. that's why it's anonymous.. if I posted confidential customer information on a website and you viewed my page did you hack me? At what point did we say anonymous web is ok, but don't try anonymous ftp even though there are plenty of anonymous ftp servers meant for public use.
  • by Anonymous Coward
    ...wow!

    That's some incredible reporting!

    When the news story first broke, we get "no personal information was released to others"

    And we get that it was an insider.

    And we get that "very, very little...information was compromised...", as compared to the amount of information that could have been stolen.

    Specifically, we get this quote:

    She says less than ten percent of the files on a single server were affected. She says Acxiom has thousands of computer servers -- and the amount of material taken is smal

  • ftp server (Score:4, Funny)

    by bucketoftruth ( 583696 ) on Sunday August 10, 2003 @07:43PM (#6661836)
    Does anyone know the address of the compromised ftp server? I'd like to check if it's still secure. Or someone else can...
  • FBI Informant (Score:1, Informative)

    by Anonymous Coward
    For those of you who didn't read it...

    There's a part about a leet haxor d00d "Krakah Jak" who attended 2600 script kid meetings etc. but was actually a paid FBI informant.

    That was nifty.
  • Acxiom? (Score:1, Funny)

    by Anonymous Coward
    Grief! Did they hack the company name too?
  • jaded (Score:5, Interesting)

    by dpletche ( 207193 ) on Sunday August 10, 2003 @07:58PM (#6661880)
    My first inclination was to deplore this latest breach in the handling of our most sensitive personal data by its self-appointed custodians at Acxiom. But after reflecting for a couple hours, I realize that this makes no difference at all. Is this guy in trouble just because he took the data without paying for it? I'm sure that Acxiom could have accomodated him if he had just created his own marketing firm and forked over some $$$.

    "But Acxiom would never sell your most sensitive personal data! They only use for internal modeling, aggregated statistical profiling, {cancer|AIDS} research, finding loving homes for stray kitties and puppies, etc." Or for sharing with affliliated partners, i.e. anyone who is willing to pay for it.

    If Acxiom wasn't selling the information, you could still count on the DMV to sell your information to all comers.
    • Re:jaded (Score:2, Interesting)

      by Anonymous Coward

      If Acxiom wasn't selling the information, you could still count on the DMV to sell your information to all comers.

      I don't know about other states, but here in Tennessee, when you fill out a drivers license application/renewal, there is an option to opt out of datasharing by initialing a few boxes on the form. The same option is present on the license plate renewal form they send each year.

      Granted, most people probably skip over it, but if you read the fine print and initial in the right places, the DMV is

    • I think a little more research would do some good before raining the fire down on Acxiom.

      I have to deal with Acxiom occasionally where I work, and while I don't necessarily get along real well with them, they're not the avatars of evil that most people envision when they think 'data miners'.

      They specialise ( at least in my part of the world ) in cleaning up customer data, addresses, name casing, etc - checking it against national do-not-mail lists and providing a GUI marketing tool to independant companie

  • by PSaltyDS ( 467134 ) on Sunday August 10, 2003 @08:29PM (#6662004) Journal
    If a company that handles sensitive information can't use ssh and scp, or some other secure mechanism, aren't they liable for legal action? Isn't financial data required to be protected by something equivelent to HIPPA [hep-c-alert.org]?
    • by bourne ( 539955 )

      Isn't financial data required to be protected by something equivelent to HIPPA?

      HIPAA (Health Insurance Portability and Accountability Act) [hhs.gov] mostly revolves around (suprise) health related personal information. Financial organizations need to pay attention to it for their own employee's information, and for any health-related organizations they provide services for, but it's not the biggest IT driver for financial companies.

      The Gramm-Leach-Bliley Act of 1999 [senate.gov] is more closely targeted on financial organ

      • You can't buy this kind of publicity. To paraphrase an earlier poster...'I didn't know who Acxiom was until this attack...' pretty much sums it up.

        A vast audience now knows who Acxiom is, and what they do, and how they respond to a "crisis".

    • The article didn't seem to indicate the nature of the data. I know that as a general rule any data exposed outside of Acxioms firewall is encrypted as a matter of policy. The data he obtained may have been nothing but encrypted bits that he couldn't DO anything with (unless he stole the key from his former employer).
  • Does anyone know if he tried to hide his trail or that he just logged in from his home puter to their ftp server? Given the speed with which they found him, seems like he did the latter.

    As a former employee of one of Axciom's customers maybe he had access to this FTP server for his work using an account that wasn't then removed. Or maybe he put a trace on FTP traffic so that he could glean the passwords of other people accessing that server. I find the use of the term "FTP" in the article confusing becaus

    • I find the use of the term "FTP" in the article confusing because it implies Acxiom has plain password access there.

      If they are using FTP, then they deserve a rap in the mouth. SSH is easy and available for just about anything.

  • by /dev/trash ( 182850 ) on Sunday August 10, 2003 @08:35PM (#6662041) Homepage Journal
    The IT I am referring to is of course the obligatory: Free Daniel J. Baas websites.
  • holy moly (Score:5, Funny)

    by Beowulf_Boy ( 239340 ) on Sunday August 10, 2003 @08:41PM (#6662061)
    I found out today that this guy is my dads fiance's nephew.

    I've never met him, and apparently he has prior marijuana charges (just look at his pic), but from what I heard from his family, he's absolutely fucked, and is looking at spending the rest of his life in a "federal pound you in the ass prison"
  • by Synithium ( 515777 ) on Sunday August 10, 2003 @08:45PM (#6662080)
    The guy they arrested, Dan Baas, is my cousin. This is super funny and not the first time he's been involved in stuff like this.

  • Prosecutor Mike Allen said...

    "Businesses have to feel secure that their information stays confidential. You just can't have someone hacking into a business's confidential information," he said. "It's really no different than someone breaking into an office and stealing files."

    Somebody should tell Prosecutor Mike Allen that...

    Businesses have to make their information secure so that it stays confidential. You just can't leave your business' confidential information. It's really no different than someo
  • THe real hacker is onel de guzman of philippines.
  • He was charged with the same crime against an unnamed company on June 3, also for another April 10 offense, records show. In that case, Baas is accused of hacking into the computer database of an unnamed company and providing "personal information regarding a subject's name and home address and telephone number without the consent or permission of the owner," records show.

    If a business provides (sells) this information, its legal and considered "good business".

    If an individual does the same thing, he's
  • by upt1me ( 537466 )
    How did the police find out about the hacking before the company? He must have been bragging about it to some government informant.
    • > How did the police find out about the hacking before the company?

      It was insinuated that the idiot turned himself in. He must have been smoking some extra-good pot that day.
  • Cryptonomicon.Net has this story [cryptonomicon.net] that proposes a mode of attack...

"If it ain't broke, don't fix it." - Bert Lantz

Working...