home contact keylogger.org add keylogger.org to favorites set keylogger.org as homepage Anti-Keylogger.org
Keylogger testing and reviews

Keylogger testing policy

Press-releases

Keylogger developers

Links
Monitoring Software Keylogger articles

Get Free Software

Keylogger chat

Keylogger forum

Sponsorship & services
Advertising
Your Ad Here
Site News
Current section

September 24, 2008

New version of PC Activity Monitor Pro (PC Acme Pro) added!

World news

October 10, 2008

Parity provides free online identity management

High-tech bank robbers phone it in

Spread security risks with diversity

Corporate data loss not down to hackers

First quantum encrypted network goes live

Apple Posts Security Update 2008-007

NT hacker blames 'segregation'

ASIC counter-spy to be a tough search

Scotland tightens security for mobile health-data

Home Office publishes data-sharing guidance

EDS loses unencrypted armed-forces data

Data-center security tools to not overlook

Microsoft promises huge patch day next week

Firefox add-on blocks 'clickjacking' attacks

Newsletter
E-mail: 
Subscribe
Send to friend
E-mail: 
Send
Voting

We are planning to redesign our site. We would like You to express your opinion in this respect. Would you like to leave the site as it is? What changes would you like to suggest?

Yes, I like the site as it is.
It's ok, but some changes are necessary.
It should be changed completely.
VotingView results
DISCLAIMER: Logging other people's keystrokes or breaking into other people's computer without their permission can be considered illegal by the courts of many countries. The monitoring software reviewed here is ONLY for authorized system administrators and/or owners of computers. We assume no liability and are not responsible for any misuse or damage caused by the keylogging software. The end user of this software is obliged to obey all applicable local, state, federal and other laws in his country of residence.

May 16, 2008

Oklahoma State breach points to ongoing higher-ed security challenges

A seemingly neverending string of data breaches at various colleges around the U.S. highlights precisely why university systems and networks continue to have a reputation for being notoriously insecure.

The latest academic institution to disclose a data compromise was Oklahoma State University (OSU), which yesterday began notifying about 70,000 individuals that their names, addresses, Social Security numbers and other personal data may have been compromised.

The warning followed the discovery in late March of an intrusion into a server belonging to the university's parking and transit services department, according to OSU spokesman Gary Shutt. The server contained information on people who had purchased parking permits from the university dating back to July 2002, according to an advisory posted on OSU's Web site.

Shutt said that the intrusion appears to have been carried out by a hacker in Germany who was looking for a server on which to host movies, TV shows, songs and pornographic content. Thus far, there is no evidence that the attack was perpetrated for the purposes of stealing the data stored on the server. "It appears that the person who came in was just looking for server space," Shutt said. "But because we couldn't be 100% sure, we went ahead and started sending notices."

According to Shutt, the university was alerted to the intrusion after another organization complained that its servers were being probed by the compromised system at OSU. On Wednesday, the university sent out e-mail notices to about 40,000 individuals for whom it had working addresses. The school is sending notices to another 26,000 people via postal mail, Shutt said, adding that it doesn't have contact information for the rest of the people whose data was stored on the server.

The OSU breach is one of eight data compromises at colleges and universities to be listed thus far this month on a Web site called Educational Security Incidents. Since January, a total of 86 data breaches have been reported at educational institutions, according to the ESI site. Most of the incidents involve U.S. schools, although a handful were reported by universities in other countries.

The breaches that have recently come to light at universities include the following:

* Earlier this month, Dominican University disclosed that two student employees had used their passwords to improperly access an Excel file that contained the records of 5,215 students. The file was stored "in an unsecure location," according to an advisory posted on Dominican's Web site.
* Late last month, Southern Connecticut State University notified 11,000 current and former students that their names, addresses and Social Security numbers may have been accessed by intruders who were using the school's Web server to host an illicit site, allegedly as part of a spamming operation.
* In March, Antioch University in Yellow Springs, Ohio, disclosed that unknown cybercrooks had broken into its main ERP server on multiple occasions last year and stolen the personal data of about 60,000 individuals.
* That same month, Lasell College in Newton, Mass., disclosed that one of its employees had illegally accessed a database containing the Social Security numbers and other personal data of about 20,000 people.
* Ther personal information of about 10,000 graduate students at Harvard University was exposed by a server intrusion that was discovered in February and publicly disclosed the following month.

Such incidents show that many of the security issues plaguing university IT networks are still a long way from being addressed, said Charlie Moran, principal at Moran Technology Consulting, a Naperville, Ill.-based firm that does IT consulting work within the education market.

The continuing security problems don't result from a lack of effort, according to Moran. "Nobody is saying, 'Let's be stupid and leave ourselves wide open,'" he said. "It has to do with the [academic] culture."

The highly decentralized nature of educational IT environments, and their relatively open data-access policies, continue to pose data security challenges, agreed Ted Julian, vice president of marketing at Application Security Inc., a New York-based vendor of database monitoring tools. The openness "fosters a highly collaborative environment," Julian said. But, he added, it makes university networks hard to secure.

Some IT departments are trying to exercise a level of centralized control over the technology assets at their schools, but many remain far from achieving that goal, Moran said. He added that while security threats have become much more complex, the IT operations at most universities — especially at state-run schools — are understaffed and can barely keep up with information security needs.

Not all the news is bad, though. For instance, many universities have stopped using Social Security numbers as personal identifiers. One example is OSU, according to Shutt. Moran said that other schools have made considerable progress in securing potential intrusion channels, such as their student-residence networks and remote access setups.

There also appears to be a growing acknowledgment within colleges and universities of the need to do something about IT security. A survey of 589 university representatives conducted late last year by Educause, a nonprofit group promoting the use of IT in higher education, identified data security as the top priority for IT organizations this year. It's the fifth straight year that security has been one of the top three priorities, a fact that the report attributed to concerns about data breaches and the need to meet security compliance requirements.


Source: ComputerWorld




All news for October 10, 2008:
13:57Parity provides free online identity management
13:56High-tech bank robbers phone it in
13:56Spread security risks with diversity
13:54Corporate data loss not down to hackers
13:53First quantum encrypted network goes live
13:51Apple Posts Security Update 2008-007
13:50NT hacker blames 'segregation'
13:49ASIC counter-spy to be a tough search
13:48Scotland tightens security for mobile health-data
13:47Home Office publishes data-sharing guidance
13:47EDS loses unencrypted armed-forces data
13:45Data-center security tools to not overlook
13:44Microsoft promises huge patch day next week
13:43Firefox add-on blocks 'clickjacking' attacks

All news for October 09, 2008:
13:44Job losses on the way for IT security staff
13:43FSA threatens executives with fines
13:39Anatomy of a SQL Injection Attack
13:37Why Security Pros Hate SharePoint
13:36Remote Workers Care About IT Security -- Really
13:35US gov't report: Data mining is ineffective
13:34Shell warns employees of suspected data loss
13:32'Fast-flux' domains help botnets evade capture
12:46Mozilla locks in Firefox 3.1 feature list
12:45Colorado state Web site dishes out SSNs of CEOs, other top execs
12:43Kernell pleads innocent to Palin hack charge
12:42Symantec to buy e-mail security vendor MessageLabs
12:41Privacy groups praise bill curbing warrantless laptop searches
12:40Tenn. student indicted for hacking Palin's e-mail



All news for October, 2008
All news for 2008 year
All news for 2007 year
All news for 2006 year
All news for 2005 year
All news for 2004 year


DONATION: Keylogger.org is an independent research project supported by a team of enthusiasts. If you find this project useful or would like to help foster its continued development please consider making a donation using PayPal`s online secure payment service.

A PayPal account is not required. All major credit cards are accepted (MasterCard/Eurocard, Visa/Delta/Electron, American Express, Switch/Maestro, Solo). Simply click the button below.

Any amount would be useful and appreciated!

Thanks in advance for your support!

Advertising
Your Ad Here
| home | testing and reviews | testing policy | press_releases | developers |

| articles | contest | chat | forum | sponsorship & services | contacts | links |
Copyright © 2003-2008, Keylogger.Org Team. All Rights Reserved.
Use of any information from this website is permitted only with hypertext link to www.keylogger.org.