FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
ChannelWeb's Top 25 Execs of 2008 know that reading is fundamental. Here are their picks for books to feed your brain.
There were plenty of high-powered movers and shakers that made a big impact on the channel in 2008. Here's a look at who made our list of the 25 most influential.
It's time again to agonize over what to get the techie in your life. With the holidays closing in fast, here are 25 gift ideas sure to wow any techie.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Regional Desktop Coordinator
BP seeking Regional Desktop Coordinator in Houston, TX
spacer

SECURITY BREACH

Monster.com Hit By Trojan Infostealer.Monstres


CRN logo By Shelley Solheim, ChannelWeb
12:00 AM EDT Mon. Sep. 03, 2007
From the September 03, 2007 issue of CRN
The breach of online jobs site Monster.com, which comprised 1.3 million job seekers' personal information, holds an important lesson for businesses banking on the Web to conduct business, say security solution providers.

The stolen data, which was foundon a remote server and shut down by Monster.com, included users' names, addresses, phone numbers and e-mail addresses. Symantec security researchers were the first to report the incident.

The data was collected by the Trojan Infostealer.Monstres, which likely used stolen login credentials of legitimate employment recruiters to gain access to the site's resume database, according to a posting by Symantec researcher Amado Hidalgo on Symantec's Web site. The unsuspecting job seekers whose information was stolen then became the victims of various phishing e-mail scams attempting to empty their bank accounts.

"This is not only going to damage Monster.com's brand reputation but is also going to cost them a lot of money," said Shiv Kumar, executive vice president of ZSL, a security solution provider in Edison, N.J. "This is a good lesson for any business completely relying on Web infrastructure to provide their services to consumers, and this is also a good opportunity for a lot of solution providers specializing in security to take this to your customers and tell your customers how proactive security management can benefit them."

Service providers say the breach highlights the need for a multilayered approach to security.

"That involves a lot of different components, including end-point protection, complex passwords, password policies, intrusion prevention detection and some mechanism to correlate that information, and security monitoring," said Brian Okun, director of Prevalent Networks, a security solution provider in New York.

"This is a very common form of attack we have these days, and in general how we address this is with a defense-in-depth approach. We make our users have security controls in place at the network and application level and make sure that they are monitoring the applications they provide on the Internet for any misusage. The other thing is that they are making sure they are educating their users using their site on what information will officially come from them as a site provider," said John McNeely, CTO of Sword & Shield Enterprise Security, an information security consulting firm in Knoxville, Tenn.

Security solution providers said incidents like this also bolster the argument for services that include continual monitoring and point to the fact that Monster.com was not the first to know its site had been compromised.

"If you look at the evolution of security over the past several years you see a proliferation of point products, so you're talking about four to eight distinct areas within security. If you have to have someone watching over every one of those all the time that's a lot of blinking lights out there. Even if you were to invest in a security management platform, it's still nice to have some experts keep an eye on your security infrastructure because the bad guys don't work normal business hours," Okun said.


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
90% OFF Aladdin SafeWord Starter Pack - Act Now!!
Make more money with SafeWord and Aladdin now that we've joined teams. Order a SafeWord Two-Factor Authentication Starter P...
Get More in Q4 from Kaspersky Lab
Sell Kaspersky products and earn dollars for every sale of 10 or more nodes. That’s right! Every sale you make will put extra...
LATEST NEWS >>
December 01, 2008 06:50 PM
December 01, 2008 04:19 PM
December 01, 2008 03:40 PM
December 01, 2008 11:55 AM
December 01, 2008 10:39 AM
RELATED BLOG >>
Photo
The Test Center's most recent threat watch.
ADVERTISEMENT




CHANNEL SERVICES >>