<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wal-Mart&#8217;s VPN Data Breach Raising Server Log Questions</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/wal-marts-vpn-launched-data-breach-raising-data-logging-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/wal-marts-vpn-launched-data-breach-raising-data-logging-questions/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Sun, 20 May 2012 01:49:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Michael Argast</title>
		<link>http://storefrontbacktalk.com/securityfraud/wal-marts-vpn-launched-data-breach-raising-data-logging-questions/comment-page-1/#comment-64051</link>
		<dc:creator>Michael Argast</dc:creator>
		<pubDate>Thu, 15 Oct 2009 21:52:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4018#comment-64051</guid>
		<description>@Lucas - one aspect of the story talks about how the security staff found a copy of l0phtcrack on the initial server that crashed. So, they could have (a) stolen multiple accounts initially or (b) cracked multiple accounts once into the environment.

Once you have an intruder in your environment you need to start making all sorts of assumptions about security - account compromise, data compromise, etc - unless you can prove otherwise. One good thing they learned from the lesson was to implement 2-factor for remote access, which at least should reduce remote attacks in the future.</description>
		<content:encoded><![CDATA[<p>@Lucas &#8211; one aspect of the story talks about how the security staff found a copy of l0phtcrack on the initial server that crashed. So, they could have (a) stolen multiple accounts initially or (b) cracked multiple accounts once into the environment.</p>
<p>Once you have an intruder in your environment you need to start making all sorts of assumptions about security &#8211; account compromise, data compromise, etc &#8211; unless you can prove otherwise. One good thing they learned from the lesson was to implement 2-factor for remote access, which at least should reduce remote attacks in the future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lucas Zaichkowsky</title>
		<link>http://storefrontbacktalk.com/securityfraud/wal-marts-vpn-launched-data-breach-raising-data-logging-questions/comment-page-1/#comment-64049</link>
		<dc:creator>Lucas Zaichkowsky</dc:creator>
		<pubDate>Thu, 15 Oct 2009 15:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4018#comment-64049</guid>
		<description>There is significance in the fact that the attacker was able to gain access to not one, but multiple VPN accounts. There must have been an underlying security failure to account for that.</description>
		<content:encoded><![CDATA[<p>There is significance in the fact that the attacker was able to gain access to not one, but multiple VPN accounts. There must have been an underlying security failure to account for that.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

