Feeds

PlusNet blames itself for webmail spamfest

Russian connection in hacking investigation

The essential guide to IT transformation

PlusNet has accepted blame for its latest email blunder, having previously fingered vulnerabilities in third party webmail software for last week's security flap.

The Sheffield-based ISP admitted late yesterday that it was its implementation of @Mail's webmail code which exposed thousands of subsciber email addresses and contacts to spammers. The firm made the mea culpa in an detailed incident report posted on its website, which had been promised for last Friday.

On Wednesday last week, a company spokesman told us the hackers had found a new vulnerability in @Mail's messaging platform. Today Plusnet said: "The attacker exploited a vulnerability within the @Mail webmail code which was compounded by vulnerabilities within our own implementation."

Since it took the service offline, PlusNet has implemented a more basic SquirrelMail open source webmail platform, which it plans to stick with. The BT-owned outfit said it was researching "longer term" options for improving the service and integrating it with the PlusNet portal and other communications tools, as @Mail had been.

In the wake of the crisis, PlusNet also made a series of promises to improve its security, including SSL encryption for FTP, and POP3 and IMAP email. Subscribers should be able to change their username in future too, to escape spam-stuffed inboxes.

As well as stealing customer data, the attackers loaded pop-up malware on to one of PlusNet's six email servers. The frame linked to a Russian video site which loaded a Trojan on to the user's machine. Beyond the Russian connection, PlusNet has not released any details of the ongoing criminal investigation into the hack. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?