<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Service Sells Access to Fortune 500 Firms</title>
	<atom:link href="http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 19 Jun 2013 07:11:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: derp</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-126000</link>
		<dc:creator>derp</dc:creator>
		<pubDate>Fri, 09 Nov 2012 07:52:05 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-126000</guid>
		<description><![CDATA[they are selling RDP, which they are using for geo proximity to wherever they are credit or bank frauding from, they are most likely not interested in what&#039;s on the system only to use it&#039;s browser fingerprint to steal from somewhere else undetected]]></description>
		<content:encoded><![CDATA[<p>they are selling RDP, which they are using for geo proximity to wherever they are credit or bank frauding from, they are most likely not interested in what&#8217;s on the system only to use it&#8217;s browser fingerprint to steal from somewhere else undetected</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Locksmith Melbourne</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-125406</link>
		<dc:creator>Locksmith Melbourne</dc:creator>
		<pubDate>Wed, 07 Nov 2012 04:41:04 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-125406</guid>
		<description><![CDATA[Really mental that there are so many computers for hire although Tadas P&#039;s comment is interesting reading. We&#039;re doing more and more security audits and risk assessments for smaller companies and this caught my eye while reading another article, I&#039;m pretty shocked.]]></description>
		<content:encoded><![CDATA[<p>Really mental that there are so many computers for hire although Tadas P&#8217;s comment is interesting reading. We&#8217;re doing more and more security audits and risk assessments for smaller companies and this caught my eye while reading another article, I&#8217;m pretty shocked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-124774</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Sun, 04 Nov 2012 14:20:08 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-124774</guid>
		<description><![CDATA[Hi Tadas. Thanks for reading and for your comment. I&#039;m assuming you&#039;re giving us a hunch as opposed to stating this as fact, unless you know something I don&#039;t about this service (which appears to have vanished for the time being).

As to the iframeservice, I wrote about it a few months back .

http://krebsonsecurity.com/2012/05/service-automates-boobytrapping-of-hacked-sites/]]></description>
		<content:encoded><![CDATA[<p>Hi Tadas. Thanks for reading and for your comment. I&#8217;m assuming you&#8217;re giving us a hunch as opposed to stating this as fact, unless you know something I don&#8217;t about this service (which appears to have vanished for the time being).</p>
<p>As to the iframeservice, I wrote about it a few months back .</p>
<p><a href="http://krebsonsecurity.com/2012/05/service-automates-boobytrapping-of-hacked-sites/" rel="nofollow">http://krebsonsecurity.com/2012/05/service-automates-boobytrapping-of-hacked-sites/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tadas P.</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-124762</link>
		<dc:creator>Tadas P.</dc:creator>
		<pubDate>Sun, 04 Nov 2012 12:54:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-124762</guid>
		<description><![CDATA[Brain, Your blog post were always entertaining, fun to real, and educational!

Most of the &quot;fortune 500&quot; servers that were sold at that shop are simply testing servers, honeypots, or servers that people simply have no use of and just play with it - also, they probably have been sold/scanned/obtained by dozen other people.

All servers that are being sold at that store are obtained by scanning IP ranges, and trying default passwords for specific ip that runs windows, and remote desktop. Such as admin/admin, admin/password, sysadmin/secret...cisco/cisco.. etc.

&quot;Fortune 500&quot; Systems are being hacked everyday, but not necessary it means, that it can do any damage, to the corporation, or infrasture itself.

Most of the systems sold there are already compromised multiple times, and multiple people have access to it, runs various malicious software, torrents, scams on it.

As article mentioned &quot;I ran a check on the Cisco box and found that it had already been blacklisted by 10 out of 15 popular services that track malicious activity online, such as spam and malware hosting.&quot; -- This just simply means, that box is compromised by multiple people, some are using server for bad things, other guys are selling it.

Brain, Here is something that should be interesting - https://srvc.iframeservice.net:666/]]></description>
		<content:encoded><![CDATA[<p>Brain, Your blog post were always entertaining, fun to real, and educational!</p>
<p>Most of the &#8220;fortune 500&#8243; servers that were sold at that shop are simply testing servers, honeypots, or servers that people simply have no use of and just play with it &#8211; also, they probably have been sold/scanned/obtained by dozen other people.</p>
<p>All servers that are being sold at that store are obtained by scanning IP ranges, and trying default passwords for specific ip that runs windows, and remote desktop. Such as admin/admin, admin/password, sysadmin/secret&#8230;cisco/cisco.. etc.</p>
<p>&#8220;Fortune 500&#8243; Systems are being hacked everyday, but not necessary it means, that it can do any damage, to the corporation, or infrasture itself.</p>
<p>Most of the systems sold there are already compromised multiple times, and multiple people have access to it, runs various malicious software, torrents, scams on it.</p>
<p>As article mentioned &#8220;I ran a check on the Cisco box and found that it had already been blacklisted by 10 out of 15 popular services that track malicious activity online, such as spam and malware hosting.&#8221; &#8212; This just simply means, that box is compromised by multiple people, some are using server for bad things, other guys are selling it.</p>
<p>Brain, Here is something that should be interesting &#8211; <a href="https://srvc.iframeservice.net:666/" rel="nofollow">https://srvc.iframeservice.net:666/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C Doom</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-124306</link>
		<dc:creator>C Doom</dc:creator>
		<pubDate>Fri, 02 Nov 2012 14:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-124306</guid>
		<description><![CDATA[1) the compromised server was in a lab, which means it might not have been under IT policy.  Engineers might have fought for the right to be excluded from firewalling policies reserved for corporate LANS.  The ever popular &quot;they&#039;re engineers and they need access without policies to do their jobs&quot; thing.

2) Engineers / Telco noc flunkies at my former employer were fairly infamous for stupid moves such as these.  One engineer got his lab linux server rooted in 26 tries by the remote russian malware bot.  His excuse: &quot;I thought the lab was firewalled!&quot;  No.  It.  Wasnt.  engineers argued for it to be open.  Then he got Pwned.  So we called him my lil pwny from that point on.

3) Cisco/Cisco is used in lots of default contexts.  Entirely believable on that front.

Its always possible its a honeynet.  But in a testing lab, I&#039;d easily believe security unconscious employees or security hubris on the part of technical employees is also in play.]]></description>
		<content:encoded><![CDATA[<p>1) the compromised server was in a lab, which means it might not have been under IT policy.  Engineers might have fought for the right to be excluded from firewalling policies reserved for corporate LANS.  The ever popular &#8220;they&#8217;re engineers and they need access without policies to do their jobs&#8221; thing.</p>
<p>2) Engineers / Telco noc flunkies at my former employer were fairly infamous for stupid moves such as these.  One engineer got his lab linux server rooted in 26 tries by the remote russian malware bot.  His excuse: &#8220;I thought the lab was firewalled!&#8221;  No.  It.  Wasnt.  engineers argued for it to be open.  Then he got Pwned.  So we called him my lil pwny from that point on.</p>
<p>3) Cisco/Cisco is used in lots of default contexts.  Entirely believable on that front.</p>
<p>Its always possible its a honeynet.  But in a testing lab, I&#8217;d easily believe security unconscious employees or security hubris on the part of technical employees is also in play.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 67GTV</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-122906</link>
		<dc:creator>67GTV</dc:creator>
		<pubDate>Fri, 26 Oct 2012 15:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-122906</guid>
		<description><![CDATA[Hmmm...  Something about petting other people&#039;s cat??  :D]]></description>
		<content:encoded><![CDATA[<p>Hmmm&#8230;  Something about petting other people&#8217;s cat??  <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AJ</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-122880</link>
		<dc:creator>AJ</dc:creator>
		<pubDate>Fri, 26 Oct 2012 13:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-122880</guid>
		<description><![CDATA[Andrey, that is an option that might come in handy. But as I understand, you should also be able to search using the name of your company.  If you really want to use numbers you can check the block of IP that is assigned to your company.]]></description>
		<content:encoded><![CDATA[<p>Andrey, that is an option that might come in handy. But as I understand, you should also be able to search using the name of your company.  If you really want to use numbers you can check the block of IP that is assigned to your company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Drutar</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-122740</link>
		<dc:creator>Drutar</dc:creator>
		<pubDate>Fri, 26 Oct 2012 01:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-122740</guid>
		<description><![CDATA[Check out seculert]]></description>
		<content:encoded><![CDATA[<p>Check out seculert</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FRAUD</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-122736</link>
		<dc:creator>FRAUD</dc:creator>
		<pubDate>Fri, 26 Oct 2012 01:34:10 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-122736</guid>
		<description><![CDATA[Да сам он черт ебливый маниторит вериф, давно пора найти и пизды дать]]></description>
		<content:encoded><![CDATA[<p>Да сам он черт ебливый маниторит вериф, давно пора найти и пизды дать</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Austin</title>
		<link>http://krebsonsecurity.com/2012/10/service-sells-access-to-fortune-500-firms/comment-page-1/#comment-122604</link>
		<dc:creator>Austin</dc:creator>
		<pubDate>Thu, 25 Oct 2012 14:53:22 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17221#comment-122604</guid>
		<description><![CDATA[Hey, if you are on microsoft, use Microsoft Security Baseline Analyzer and it will list out all the admin accounts on your system.

If you want to pay, use LanGuard from GFI or Nessus if you want to get really deep]]></description>
		<content:encoded><![CDATA[<p>Hey, if you are on microsoft, use Microsoft Security Baseline Analyzer and it will list out all the admin accounts on your system.</p>
<p>If you want to pay, use LanGuard from GFI or Nessus if you want to get really deep</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 17/18 queries in 0.002 seconds using memcached
Object Caching 379/387 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-19 03:15:44 by W3 Total Cache -->