Friday, 27 July 2007

IBM - Idiots Buy Medicines from a hacked IBM server

Need a little blue pill? Contact Big Blue, AKA IBM...


Good old IBM! The pharmacy site they are hosting is still going strong, THREE WEEKS after it being reported to them. To quote from their website:-

Drawing on a deep understanding of today’s security threats from both within and outside the enterprise, IBM provides a unified strategy for developing enterprise security solutions, and identity and access management represents a modular entry point into IBM security solutions. A comprehensive, standards-based approach that integrates access authorization and identity management enables organizations to cost-effectively provide authorized users with access to applications and data while protecting these assets from unauthorized access.

No shit, Sherlock!

Let me translate:- What this means is that even on one of OUR OWN SERVERS, we will let an intruder hack our system, install a proxy redirector, and leave it there for weeks undisturbed while the spammers and criminals are profiting from it.


Would you buy a server from this company, and let them manage the security of it?

http://170.224.180.131

whois 170.224.180.131

OrgName: IBM
OrgID: IBM-1
Address: 3039 Cornwallis Road
City: Research Triangle Park
StateProv: NC
PostalCode: 27709-2195
Country: US

NetRange: 170.224.0.0 - 170.227.255.255
CIDR: 170.224.0.0/14
NetName: IBM-COMMERCIAL
NetHandle: NET-170-224-0-0-1
Parent: NET-170-0-0-0-0
NetType: Direct Assignment
NameServer: RTPUSSXDNSB03.RALEIGH.MEBS.IHOST.COM
NameServer: RTPUSSXDNSB04.RALEIGH.MEBS.IHOST.COM
NameServer: BLDUSWXDNSB01.BOULDER.MEBS.IHOST.COM
NameServer: BLDUSWXDNSB02.BOULDER.MEBS.IHOST.COM
Comment:
RegDate: 1995-04-21
Updated: 2007-01-31

No comments: