Feeds

PlusNet blames itself for webmail spamfest

Russian connection in hacking investigation

Securing Web Applications Made Simple and Scalable

PlusNet has accepted blame for its latest email blunder, having previously fingered vulnerabilities in third party webmail software for last week's security flap.

The Sheffield-based ISP admitted late yesterday that it was its implementation of @Mail's webmail code which exposed thousands of subsciber email addresses and contacts to spammers. The firm made the mea culpa in an detailed incident report posted on its website, which had been promised for last Friday.

On Wednesday last week, a company spokesman told us the hackers had found a new vulnerability in @Mail's messaging platform. Today Plusnet said: "The attacker exploited a vulnerability within the @Mail webmail code which was compounded by vulnerabilities within our own implementation."

Since it took the service offline, PlusNet has implemented a more basic SquirrelMail open source webmail platform, which it plans to stick with. The BT-owned outfit said it was researching "longer term" options for improving the service and integrating it with the PlusNet portal and other communications tools, as @Mail had been.

In the wake of the crisis, PlusNet also made a series of promises to improve its security, including SSL encryption for FTP, and POP3 and IMAP email. Subscribers should be able to change their username in future too, to escape spam-stuffed inboxes.

As well as stealing customer data, the attackers loaded pop-up malware on to one of PlusNet's six email servers. The frame linked to a Russian video site which loaded a Trojan on to the user's machine. Beyond the Russian connection, PlusNet has not released any details of the ongoing criminal investigation into the hack. ®

Mobile application security vulnerability report

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.