All the latest UK technology news, reviews and analysis

WorldCom leaves multinationals exposed

by John Geralds in Silicon Valley

07 Dec 2001

Be the first to comment

  • Tweet this

Telecoms giant MCI WorldCom has confirmed that a security hole left internal networks at Bank of America, Sun Microsystems, British Airways, JP Morgan and Fox News among others, vulnerable to intruders.

Security researcher Adrian Lamo, who discovered the vulnerability and worked with WorldCom to fix the problem, said there was no evidence that hackers had exploited the security hole.

The information Lamo discovered could allow an intruder to divert network traffic for any of the affected companies or disable their networks altogether.

WolrdCom spokeswoman Jennifer Baker explained that a router which had an inappropriate filter had caused the problem. The filter was removed and the router was reconfigured to close the hole.

Baker confirmed that none of the company's global users were affected. "We learned that unauthorised access could be made to our administrative internal data network and made sure that no WorldCom customers were affected," she said.

Lamo told security intelligence firm SecurityFocus.com that he had discovered open internet proxy servers at WorldCom. By using a common hacker tool called Proxy Hunter, Lamo scanned WorldCom's corporate web address space and found five open proxies.

A proxy server is a dedicated machine that sits between a local network and the outside world, passing internal web requests out to the internet.

Over the last few months Lamo has found security problems at several major computer firms including Microsoft, AOL Time Warner and Yahoo.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Lead PHP Developer - Technical Architect - Ecommerce Manager

Lead PHP Developer - Technical Architect - Ecommerce...

C# / .NET Software Engineers – Leeds City Centre – C# (£30-50k)

C# Software Engineers required to join rapidly expanding...

Java / J2EE Developers – Leeds City Centre – Java / J2EE (£30-50k)

Java / J2EE Software Engineers required to join rapidly...

Developer (MIS - SQL / T-SQL, HTML, CSS or Javascript)

Developer (MIS / Business Systems - SQL / T-SQL, HTML...

To send to more than one email address, simply separate each address with a comma.