Home Repair (alt.home.repair) For all homeowners and DIYers with many experienced tradesmen. Solve your toughest home fix-it problems.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1   Report Post  
Posted to alt.home.repair
external usenet poster
 
Posts: 445
Default Target Hack Blamed on HVAC company

Target Hackers Broke in Via HVAC Company

Last week, Target told reporters at The Wall Street Journal and
Reuters that the initial intrusion into its systems was traced back to
network credentials that were stolen from a third party vendor.
Sources now tell KrebsOnSecurity that the vendor in question was a
refrigeration, heating and air conditioning subcontractor that has
worked at a number of locations at Target and other top retailers.

Sources close to the investigation said the attackers first broke into
the retailer’s network on Nov. 15, 2013 using network credentials
stolen from Fazio Mechanical Services, a Sharpsburg, Penn.-based
provider of refrigeration and HVAC systems.

It’s not immediately clear why Target would have given an HVAC company
external network access, or why that access would not be cordoned off
from Target’s payment system network. But according to a cybersecurity
expert at a large retailer who asked not to be named because he did
not have permission to speak on the record, it is common for large
retail operations to have a team that routinely monitors energy
consumption and temperatures in stores to save on costs (particularly
at night) and to alert store managers if temperatures in the stores
fluctuate outside of an acceptable range that could prevent customers
from shopping at the store.

“To support this solution, vendors need to be able to remote into the
system in order to do maintenance (updates, patches, etc.) or to
troubleshoot glitches and connectivity issues with the software,” the
source said. “This feeds into the topic of cost savings, with so many
solutions in a given organization. And to save on head count, it is
sometimes beneficial to allow a vendor to support versus train or hire
extra people.”

Full story at
http://krebsonsecurity.com/2014/02/t...-hvac-company/
  #2   Report Post  
Posted to alt.home.repair
external usenet poster
 
Posts: 1,377
Default Target Hack Blamed on HVAC company

On 02/06/2014 06:58 AM, Moe DeLoughan wrote:
Target Hackers Broke in Via HVAC Company
X
“To support this solution, vendors need to be able to remote into the
system in order to do maintenance (updates, patches, etc.) or to
troubleshoot glitches and connectivity issues with the software,” the
source said. “This feeds into the topic of cost savings, with so many
solutions in a given organization. And to save on head count, it is
sometimes beneficial to allow a vendor to support versus train or hire
extra people.”

Full story at
http://krebsonsecurity.com/2014/02/t...-hvac-company/




Speaking of security, here is one for you


https://www.youtube.com/watch?v=TCKr...&app=deskt op
  #3   Report Post  
Posted to alt.home.repair
external usenet poster
 
Posts: 3,515
Default Target Hack Blamed on HVAC company

Moe DeLoughan posted for all of us...

And I know how to SNIP


Target Hackers Broke in Via HVAC Company

Last week, Target told reporters at The Wall Street Journal and
Reuters that the initial intrusion into its systems was traced back to
network credentials that were stolen from a third party vendor.
Sources now tell KrebsOnSecurity that the vendor in question was a
refrigeration, heating and air conditioning subcontractor that has
worked at a number of locations at Target and other top retailers.

Sources close to the investigation said the attackers first broke into
the retailer?s network on Nov. 15, 2013 using network credentials
stolen from Fazio Mechanical Services, a Sharpsburg, Penn.-based
provider of refrigeration and HVAC systems.

It?s not immediately clear why Target would have given an HVAC company
external network access, or why that access would not be cordoned off
from Target?s payment system network. But according to a cybersecurity
expert at a large retailer who asked not to be named because he did
not have permission to speak on the record, it is common for large
retail operations to have a team that routinely monitors energy
consumption and temperatures in stores to save on costs (particularly
at night) and to alert store managers if temperatures in the stores
fluctuate outside of an acceptable range that could prevent customers
from shopping at the store.

?To support this solution, vendors need to be able to remote into the
system in order to do maintenance (updates, patches, etc.) or to
troubleshoot glitches and connectivity issues with the software,? the
source said. ?This feeds into the topic of cost savings, with so many
solutions in a given organization. And to save on head count, it is
sometimes beneficial to allow a vendor to support versus train or hire
extra people.?

Full story at
http://krebsonsecurity.com/2014/02/t...-hvac-company/


This reminds me of SCADA (sp) hacking that supposedly happened 4-5 years ago; which proved false.
The HVAC co probably had access but Target should have firewalled them from the other segments.

--
Tekkie
  #4   Report Post  
Posted to alt.home.repair
external usenet poster
 
Posts: 22,192
Default Target Hack Blamed on HVAC company

On Thu, 06 Feb 2014 06:58:25 -0600, Moe DeLoughan
wrote:

Last week, Target told reporters at The Wall Street Journal and
Reuters that the initial intrusion into its systems was traced back to
network credentials that were stolen from a third party vendor.


{Home use} Download, install, and update definitions of Belarc
Advisor (free). I recently fixed a laptop for a friend of the wife.
It had a fake "credential" installed.

To fix the bad credential, it requires a valid MSFT product. BA will
provide the link and information in the BA report. Once the product is
validated MSFT allows a valid ( fix ) credential to be installed.

http://belarc.com/

The bad credential was causing her firewall to shutdown. Best I could
tell. But it is fixed now.
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules

Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
I blamed the effing goats... Grimly Curmudgeon[_3_] UK diy 22 May 16th 13 06:52 PM
HVAC System - Hack Job? Cynthia[_2_] Home Repair 18 August 26th 11 06:17 AM
SP Trading Company Stanislav Proskurovsky Stanp2323 SCAMMERS Don't buy electronics from this company refurbished JUNK Billy Bob Woodworking 2 July 17th 07 10:55 AM
HVAC questions welcomed at alt.hvac Larry F Home Repair 20 December 30th 05 04:40 AM
dave, HVAC hack and fundy idiot is now posting as U will be assimilated Home Repair 0 February 7th 05 05:01 PM


All times are GMT +1. The time now is 01:49 PM.

Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 DIYbanter.
The comments are property of their posters.
 

About Us

"It's about DIY & home improvement"