ADP Experiences Security Breach
wiredmikey writes "HR and Payroll outsourcing giant Automatic Data Processing, Inc. (ADP) experienced a system intrusion, the company announced Wednesday. ADP said it was investigating and taking measures to address the impact of a system intrusion that occurred with a client at Workscape, a benefits administration provider that ADP acquired in August 2010. ADP has also been actively cooperating with law enforcement to determine the cause of this incident and to assist authorities in identifying and apprehending those responsible. ADP added the following in a statement: 'Because this incident is the subject of an ongoing law enforcement investigation, ADP cannot disclose any additional details at this time. ADP will provide further updates once information that can be made public becomes available, and we will continue to communicate with all affected parties as appropriate.'"
It almost seems like it would be easier to maintain a list of which major payment systems haven't been breached (that we know of). Seriously, if this was as wide open as Citibank and Sony, then we have to assume that just about everybody will be this easy to pwn.
I am officially gone from
The article makes grand mention of ADP, but the the affected systems are far less significant than if it were ADP itself. I don't know what ADP's services are like now, but I recall a time when my accounting people required MSIE and ActiveX controls to access ADP's services. That alone made me worry extensively about ADP's notion of security. But reading the article, I see that it's something else entirely.
The compromise was at Workscape which I imagine had not integrated its network with ADPs larger network. The organization appears not to have much to do with payroll or money services at all.
It was clearly 'Anonymous'. Or has Sony trademarked that excuse?
Still feeling like its a good idea?
Somebody must be really wanting to roll out a killswitch, protect all that wide open US electrical grid, rod go up/down via modem at the nuclear plant, telephone exchange and your brand new networked power meter. ... or .. was it the aggressor nation?
How many millions will be handed over to contractors and any foreign entity with a security clearance to fix a secret wireless communications channel with remote secure control to any device that speaks "internet"?
Some 'admin' having a bad script kiddies day with Microsoft again, triggers a state/tri state net security disconnect for a few hours
Domestic spying is now "Benign Information Gathering"
My take on this subject is that Anonymous and Seclulz like to piss all over their own work, thereby letting everyone know who dunnit. This really stinks of some 3 letter acronym organization wanting to destabilize the infrastructure. CIA, NSA, PRC, PLA, NWO?
Thh truth is out there
I live 1/2 mile away from headquarters
ahahaha, ADP no way.............
Just add a couple extra non-zero digits to the left side of the dollar column in my paycheck this week. I'll split it with you.
Properly and on time, instead of being hidden, to defend share price?
Ever think of that??
E.G.-> SONY took a 4% drop in stock when they were hacked/cracked for example.
That said? It's NO SECRET that many companies try to "hide it" (while their boards of directors ditch shares like mad before the news hits and people lose faith in them due to security breaches).
However, lately??
It seems that trend has reversed itself and we're seeing what is occuring in a timely fashion.
(That's a good thing for end users of these companies' services online, because they will most likely do something about it from a network security perspective once they're aware of any deficiencies there due to these hacks/cracks.)
In fact - Since you're "speculating" (though it may be possible, ala "problem/reaction/solution" type manipulations of the public often done by those in power) and, the way you talk?
Hey - I could say you're a member of "anonymous" or "lulzsec" or some other malware maker or hacker/cracker for pete's sake, trying to "sway public opinion" yourself, so that protective measures are NOT taken!
Anyone can speculate, problem is? NONE OF US HAS ENOUGH INFORMATION, & solid undeniable information, to make any type of judgements here.
We have to wait to see how it all plays out, as far as that is concerned... period!
APK
P.S.=> Oh, It's not just Microsoft stuff either, in regards to this little tidbit from you:
"Some 'admin' having a bad script kiddies day with Microsoft again" - by AHuxley (892839) on Thursday June 16, @09:00AM (#36461582) Homepage
This is happening on ALL platforms... case-in-point/example? Ok:
E.G. #1 (very recent): What about MacDefender malware appearing on MacOS X? The OS that was allegedly implied by Apple to be "more secure than Microsoft's" for years?
E.G. #2 (very recent): Also, and as far as "LAMP" (Linux, Apache, MySQL, PHP for those "not in the know" on that account) goes?
I'll let this article from the Register speak on that account here, for me:
http://www.theregister.co.uk/2011/06/10/domains_lamped/
---
PERTINENT QUOTE:
"Phishers compromise LAMP-based websites for days at a time and hit the same victims over and over again, according to an Anti-Phishing Working Group survey. Sites built on Linux, Apache, MySQL and PHP are the favoured targets of phishing attackers"
---
Now - For comparison's sake, Apples-To-Apples, in the MS Stack for business online? Here we go:
---
Vulnerability Report: Microsoft SQL Server 2008:(06/16/2011)
http://secunia.com/advisories/product/21744/
Unpatched 0% (0 of 0 Secunia advisories)
---
Vulnerability Report: Microsoft Internet Information Services (IIS) 7.x: (06/16/2011)
http://secunia.com/advisories/product/17543/
Unpatched 0% (0 of 6 Secunia advisories)
---
Vulnerability Report: Microsoft Exchange Server 2010: (06/16/2011)
http://secunia.com/advisories/product/28234/
Unpatched 0% (0 of 0 Secunia advisories)
---
Vulnerability Report: Microsoft Internet Explorer 9.x: (06/16/2011)
http://secunia.com/advisories/product/34591/ [secunia.com]
Unpatched 0% (0 of 1 Secunia advisories)
---
Vulnerability Report: Microsoft Visual Studio 2010: (06/16/2011)
http://secunia.com/advisories/product/30853/?task=advisories
Unpatched 0% (0 of 1 Secunia advisories)
---
And?
Well, We already KNOW that Windows 7:
I was complaining to the HR person at my previous company that the password policy of ADP is so terrible that it encourages extremely bad behaviour with password management (really really draconian password requirements that you basically end-up having to use a random password generator). I said that it's not great security wise & the response was that "This is a huge company that a lot of people use & I'm sure they know what they're doing better than you". At that point I gave up on continuing that thread of the conversation. They also tend to use your SSN all over the place, cause... you know.... employment....
After all - It's not the 1st time you've tried to troll me on HOSTS files either...
In fact, here are 2 of your "classic technical blunders" in fact, Mr. AC troll, in regards to HOSTS files usage:
---
E.G. #1 - LARGE HOSTS FILES BEING CACHED BY THE LOCAL KERNEL-MODE DISKCACHING SUBSYSTEM (recently here no less, you screwed up THERE, hugely):
http://it.slashdot.org/comments.pl?sid=2220314&cid=36379004
E.G. #2 - HOSTS ON ANDROID PHONES (yes, they work there):
http://apple.slashdot.org/comments.pl?sid=2204000&cid=36318508
---
Proof's in the pudding, Mr. AC troll...
APK
P.S.=> Face it - On your best day, You couldn't touch me on technical issues if you're LIFE depended on it, and you know it...
However, since I am of an open mind & I can only get STRONGER VIA VALID CRITIQUE?
Well - What's "computer-science oriented technically wrong" (for lack of a better expression here) with my points on HOSTS files then?
(Especially since I even shown that I had an MS mgt., SENIOR VP mind you, of the "Windows Client Performance Division" for years & at that time, agree that I was correct on my points on HOSTS files, ala -> http://slashdot.org/comments.pl?sid=1467692&cid=30384918 )?
I can cite many posts where my points on HOSTS files were modded up also, ala:
---
HOSTS MOD UP -> http://yro.slashdot.org/comments.pl?sid=1907266&cid=34529608
HOSTS MOD UP -> http://tech.slashdot.org/comments.pl?sid=1490078&cid=30555632
HOSTS MOD UP -> http://it.slashdot.org/comments.pl?sid=1869638&cid=34237268
HOSTS MOD UP -> http://tech.slashdot.org/comments.pl?sid=1461288&threshold=-1&commentsort=0&mode=thread&cid=30272074
HOSTS MOD UP -> http://tech.slashdot.org/comments.pl?sid=1255487&cid=28197285
HOSTS MOD UP -> http://tech.slashdot.org/comments.pl?sid=1206409&cid=27661983
HOSTS MOD UP -> http://apple.slashdot.org/comments.pl?sid=1725068&cid=32960808
HOSTS MOD UP -> http://it.slashdot.org/comments.pl?sid=1743902&cid=33147274
HOSTS MOD UP -> http://news.slashdot.org/comments.pl?sid=1913212&cid=34576182
HOSTS MOD UP -> http://it.slashdot.org/comments.pl?sid=1530066&cid=30965192
HOSTS MOD UP with facebook known bad sites blocked -> http://tech.slashdot.org/comments.pl?sid=1924892&cid=34670128
HOSTS FILE MOD UP FOR ANDROID MALWARE -> http://mobile.slashdot.org/comments.pl?sid=1930156&cid=34713952
HOSTS FILE MOD UP vs ANDROID MALWARE -> http://mobile.slashdot.org/c
Hacking is only becoming such big news now because the US congress is trying to push more crap legislation through to screw up the internet. Hacking will become the new "TERRORISM" excuse for violating civil rights.
But...as the dumb sheep they are, most citizens will just lay there and take it like everything else we get hosed with.
Listen, you know it was prescribed to us. We don't want to go back THERE.
- JL
here http://it.slashdot.org/comments.pl?sid=2243006&cid=36463826 or here http://it.slashdot.org/comments.pl?sid=2243006&cid=36464356 the poor troll can't even write correctly. School that troll please. I can't handle his hieroglyphic style of illiterate trollspeak. Must be those meds he mentioned he obviously takes. Thank JL.
ADP is the company that protected its 401K accounts by having people type in their Social Security Number and a 4-digit Pin. To protect against a brute force attack on the 4-digit pin, they had a browser cookie count the number of tries, and if the browser cookie reached 3, then some javascript would say that you had to wait until some time elapsed on the client's clock.
When contacted about this, they insisted that it was secure because of the enforced delay. When I sent them a demonstration of how to hack my own PIN with program that just kept the cookie login count set to 1 and a request that they disable all network access to my account, they refused, saying that they had no means to disable it. ADP is garbage.
I had a representative of ADP come in to our office to begin the process of signing our company up. I saw my SSN plastered all over everything -- the forms, my login name, etc. I told them I would not authorize myself to be part of their system when my personal data was so easily visible. She said she would get it all obscured/changed. She never did, never returned my calls, and all paperwork I received from them had personal data all over it.
If ADP was penetrated via an SQL Injection hack (or even a MASS MESH attack, much Much worse)?
The use of a HOSTS file is a good layered security measure!
(Simply because once you get the names of the servers they are talking back to via the malware those can direct you to?? HOSTS files truly ARE an excellent extra layer of defense for blocking communication w/ them!)
* However , ADP's not talking yet on details, afaik!
APK
P.S.=> You're pitifully inadequate on technical details anyhow, as evidenced in your FAIL list vs. myself here, Mr. AC Troll:
http://it.slashdot.org/comments.pl?sid=2243006&cid=36464032
Which shows you've tried this before & screwed up on the fact that HOSTS files (even larger ones where you must turn off the local DNS client cache service in Windows for) get CACHED BY THE LOCAL KERNELMODE DISKCACHING SUBSYSTEM, & THE FACT THAT HOSTS FILES WORK ON ANDROID MOBILE PHONES ALSO... lol, man: You? You are STOO-PID, no questions asked, & a noob in the art & science of computing!
... apk
Impersonating me... to wit/e.g., quoted from YOU:
"Cause certainly nobody would want to impersonate you" - by Anonymous Coward on Thursday June 16, @11:46AM (#36463826)
Ahem, bullshit: Your saying that telegraphs that You've tried that very thing here before, obviously, & I have evidences of that from this week alone here:
http://it.slashdot.org/comments.pl?sid=2227792&cid=36400620
and here in the past also:
http://it.slashdot.org/comments.pl?sid=2227792&cid=36400620
You really are a piece of garbage!
Plus, your "FAIL LIST" vs. myself, everytime you've tried to troll me on HOSTS files also:
http://it.slashdot.org/comments.pl?sid=2243006&cid=36464032
Illustrates you are truly a noob in the computer sciences arena, and stupid also... period! I can't put it any more lightly than that...
... apk