Welcome | Sign In
ECommerceTimes.com
Network Intrusion

University of Missouri Burned in Second Hack Attack

Print Version
E-Mail Article
Reprints
University of Missouri Burned in Second Hack Attack

More than 22,000 students and former students have been exposed in the second hack attack against the University of Missouri this year. The incident highlights the particular vulnerability of institutions of higher learning, which handle the personal data of large numbers of students, faculty and staff cycling in and out of their systems.


Tips to Integrate Social Media into Your Day-to-Day Media Monitoring
Is social media part of your PR and marketing strategy? This white paper is filled with tips on how to listen to conversations about your brand in the media (social media, print, TV and internet) using the latest tools and techniques. Download Now.

For the second time this year, hackers have victimized the University of Missouri. The names and Social Security numbers of 22,396 current or former students who were employed by UM during 2004 may have been compromised, according to university officials.

The hacker or hackers reportedly gained access to the personal information via a 2004 Web page set up by the IT help desk.

The IT staff noticed unusual activity on a computer application on May 3, and confirmed the next day that an attack had taken place. Two overseas IP (Internet protocol) addresses -- one traced to China and the other to Australia -- were the likely vectors.

"The University of Missouri takes this breach very seriously and is working to alert the individuals whose information was improperly accessed," the University says in an advisory, adding that it will provide instructions about how those affected can monitor their credit reports for suspicious activity.

"The University has been and will continue to work diligently to secure confidential data held in its computer systems," the statement continues. "We are also working closely with law enforcement in our investigation of this event."

The university's computer system was also compromised in January, when hackers gained access to a Web-based application that had been poorly secured.

Easy Target

The fact that the University of Missouri has been targeted twice does not mean it is particularly careless with its data.

"More than likely, it means that somebody has found a way into the system -- perhaps a stolen password -- and now has a base set up to make repeated entries," Shane Coursen, senior technical consultant at Kaspersky Lab, told TechNewsWorld.

Universities and colleges in general tend to be targeted more than, say, banks, retailers or the government, he noted.

"They are information-rich because there are so many students," Coursen said. "Secondly, universities are not as heavily manned, security-wise, compared to large institutions."

Physical security is also more of an afterthought for many campuses' IT systems, he pointed out. "True, a lot of times the attacks come through the Internet. But just as many can occur from people having physical access to a system. I think we will be seeing upgraded physical security and processes at universities as more of these events happen."

It is true that universities are a favorite fishing pier for hackers, agreed Mark Sunner, chief security analyst at MessageLabs, who noted that the huge numbers of students and employees cycling through the institutions provide numerous opportunities to exploit the safeguards that do exist.

"There are a lot of people using a lot of equipment that hook into the network but are not necessarily dedicated to it," Sunner told TechNewsWorld.

Also, universities tend to use open source software, which provides more of a road map to a database or system, he commented.

Profit Toolkit

There may be a more insidious reason for the University of Missouri's vulnerability, suggested Sunner. It may have been targeted by hackers using a new business model: marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales toolkits specifically to launch one-off hack attacks against a certain institution or vertical, such as education.

Since December 2006, the antivirus community has been aware of commercially packaged toolkits -- some of which come with service packages and automated updates -- for sale on shady Russian and Ukrainian Web sites.

"They are scarily commercialized," Sunner said. "You can buy a one-off Trojan for (US)$200. If it becomes detectable by an AV, you can get an update for $50. For $2,000, you can get the bad guy equivalent of a service contract and receive automatic updates."

Besides education, other sectors for which Trojans have been built include the public sector, electronics, retail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse, aviation, communications, financial and the military, Sunner said.


Print Version E-Mail Article Reprints More by Erika Morphy


Talkback: Join the Discussion.
Re: University of Missouri Burned in Second Hack Attack
Daisygrower
Posted 2007-05-10
The vast majority of universities rely on large, moderately-protected networks to store data on ...

More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network