Feeds

DoubleClick undergoes security audit after hack attack

Security experts say firm should consider "pulling plug on servers" until flaws are fixed

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

Internet advertising firm DoubleClick has denied reports that the security of its Web servers has been compromised by vulnerabilities which lay unnoticed for the last two years.

French security site Kitetoa.com claims that a flaw with the doubleclick.net Web server, which runs Microsoft's IIS, means hackers had backdoor access to confidential data. DoubleClick denies this but admits it is undergoing a security audit after what it said were unsuccessful attacks by hackers last week.

According to Kitetoa, missconfigured Web servers at DoubleClick allowed the installation of a Trojan horse program on the firm's systems.

A screenshot published by Kitetoa appears to show the Web servers have been tampered with and that a file called eEyehack.exe uploaded onto its servers on April 29 1999. It points to an exploit first described by security consultants eEye Digital Security as the mechanism of the attack.

Network security consultant Paul Rogers, of MIS Corporate Defence, said there is no firm evidence eEye's exploit, which allows Trojans to be uploaded onto servers, was used against DoubleClick. The date of the file was before the publication of the eEye advisory and the size of the file, which might be a Trojan, does not correspond to any well known backdoor program.

Rogers said far firmer evidence that DoubleClick's servers are insecure is provided by another screenshot Kitetoe.com has obtained. This apparently shows username and passwords protecting DoubleClick's Abacus server, its market research division.

"If I was able to obtain this whilst doing an penetration test for one of my clients I'd advise them to pull the plugs on their boxes," said Rogers. "DoubleClick should consider running their services from a different platform whilst damaged host servers are repaired. It might also consider restricting access to services."

A spokeswoman for DoubleClick denied that its servers had been compromised for the last two years but admitted that it was in the process of conducting a full security audit after an attack by hackers last week. She stated that these attacks were unsuccessful.

In a statement on the attacks sent to The Register, DoubleClick said: "Over the last week there have been unsuccessful attempts made to hack into DoubleClick's servers. DoubleClick is now undergoing a comprehensive security audit, including the expertise of external security professionals and engineers, to fully ensure the continued integrity of our servers." ®

External links:
Kitetoa.com

5 things you didn’t know about cloud backup

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
Mozilla's 'Tiles' ads debut in new Firefox nightlies
You can try turning them off and on again
No, thank you. I will not code for the Caliphate
Some assignments, even the Bongster decline must
Kaspersky backpedals on 'done nothing wrong, nothing to fear' blather
Founder (and internet passport fan) now says privacy is precious
Banking apps: Handy, can grab all your money... and RIDDLED with coding flaws
Yep, that one place you'd hoped you wouldn't find 'em
TROLL SLAYER Google grabs $1.3 MEEELLION in patent counter-suit
Chocolate Factory hits back at firm for suing customers
Primetime precrime? Minority Report TV series 'being developed'
I have to know. I have to find out what happened to my life
Ex-IBM CEO John Akers dies at 79
An era disrupted by the advent of the PC
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.