NEWS Holes in company networks are being exploited by hackers and fraudulent employees to store and distribute illegal pornography, media files and pirated software. A 'honeypot' network set up purely to attract and monitor the level and type of hacking activity on the internet has found hackers are routinely scanning for misconfigured file transfer protocol (FTP) servers that allow them to upload and store material secretly on company networks for later download. The Irish Honeynet was set up by Espion, Deloitte & Touche and Data Electronics last year to mimic a typical corporate internet infrastructure but with the ability to detect and monitor all activity to and from the system. In a recent test, Espion deliberately misconfigured the FTP server – a regular occurrence for many firms - which allows for the transfer of files to and from hosts on the internet. The FTP server was configured to allow anonymous uploads and the creation of directories, while preventing anyone from downloading any files. This allows for anonymous uploads and hackers exploit these holes to use the system as a storage depository for the illegal distribution of software, music and pornography. After just two days the Honeynet FTP upload directory contained many new files and directories, including hacker tools and files to test the amount of storage space and download speed available. Espion's advice is for companies to only allow anonymous logins on an FTP server where there is a genuine business need and to limit the size of an upload and the size of the FTP directory. Mark Morris, head of forensics, intelligence and security at LogicaCMG, warned that the threat can also come from inside, with employees surreptitiously using the corporate network to run their own businesses or store illegal content. "At one firm where we investigated an outsourced IT helpdesk we found a sub-network that the company did not know about that was running an escort agency website and a counterfeit software operation," he said. The warnings echo findings from a study by PSINet and PanSec last week which monitored two mock banking sites - one with security and one without. The results showed a frightening level of hacking activity that could cripple firms who still leave security to chance.
Porn, pirated software, MP3s – do you really know what's on your network?
Hackers and employees using corporate networks to store and distribute illegal material and even run businesses...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Networks stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Magic Quadrant for WAN Optimization Controllers.
Oversight is an important step to keeping something in check- whether it's a group of kids at recess or a suite of...
-
WAN Optimization for Today and Tomorrow.
It was only a few years ago when the idea of mobile computing seemed like a distant reality. Many could see it coming,...
-
Using pay-as-you-grow model for better agility
Enterprise IT teams are being challenged to increase overall IT flexibility and business agility by incorporating...
Popular Networks stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
HR Consultant
HR Consultant- CIPD Qualified, Public Sector, Trade UnionsHigh profile public sector role based in Darlington requires...
-
1st line Support- Croydon
My client- A large consultancy based in Croydon are looking for a 1st/2nd line helpdesk support candidate on an...
-
IT Security Specialist , Big Learning + Move into Pre-Sales
IT Security Specialist , Big Learning + Move into Pre-SalesSC Cleared, UK National - Intensive training offered on...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





