The Register® — Biting the hand that feeds IT

Feeds

Gamers raid medical server to host Call of Duty

230,000 patient records exposed

A server storing sensitive patient information for more than 230,000 people was breached by unknown hackers so they could use its resources to host the wildly popular Call of Duty: Black Ops computer game.

New Hampshire-based Seacoast Radiology warned patients on Tuesday that the hacked server stored their names, social security numbers, medical diagnosis codes, address, and other details. On a website established after the mid-November breach, the medical group urged patients to monitor their credit reports for signs of identity theft, although there's no evidence of any misuse of the information.

The unknown hackers used the server's bandwidth to play the the Call of Duty game, said Lisa MacKenzie, a spokeswoman for ID Experts, a firm that was brought in the respond to the breach. Investigators believe the hackers were located in Scandinavia, but she didn't say how that determination was made. People with the smarts to compromise a medical group's server also have the ability to spoof their IP address.

The breach was discovered on November 12, after an admin noticed a loss of bandwidth. It was unclear how long the hackers had access to the server before the hack was discovered.

Seacoast Radiology brought in security experts to investigate. The weakness that made the compromise possible has since been discovered and fixed. The breach has been reported to the federal Department of Health and Human Services and New Hampshire's attorney general. ®

Ugh...

I'm reading sentences like this a lot recently:

"spoof their IP address"

If you spoof your IP address you will not receive the data. If you HIDE your IP address with the likes of Tor you certainly won't be playing Call of Duty. If you login to a server and change the log files such that your IP is hidden that is also not spoofing.

15
0

Anyone care to venture a guess as to why...

a server hosting sensitive patient information was open to the internet, from the sounds of it with a whole lot of non-standard UDP and TCP ports open?

8
1

Yeah right...

Did they also discover 'Some hackers' had installed COD on all the network admins pc's aswell?

5
1

erm...

You use Tor to comprimise the machine and set it up as a game server.

Then you don't use Tor to connect as a regular player (not doing anything wrong!) and enjoy.

I would doubt it was a scandinaivan who comprimised the machine, It would be a local player wanting a good ping. However since Tor is popular in scandinavia I would guess that Tor was used to comprimise the machine, hence looking like a scandinavian hack.

3
0

Yeah... Right

And you certainly would not be playing call of duty on an American server from Scandinavia. The latency is sufficient to make any hard core gamer choke on their beverage of choice at the mere suggestion of doing so.

3
0

More from The Register

US boffin builds 32-way Raspberry Pi cluster
Beowulf cluster built for the price of a single PC
MYSTERY Nokia Lumia with gazillion-pixel camera 'spotted'
With 20Mp sensor - NOW will you try Windows Phone 8?
 breaking news
Review: HP Pavilion 14 Chromebook
All roads lead to Chrome?
Borked your iDevice? Pay EVEN MORE to have it fixed by Applecare
Or scream at their hapless techies on their forums
Dell's PC-on-a-stick landing in July: report
Wyse up, suckers, could this be a new set-side-stick?
Euro PC shipments plummet into bottomless pit of DOOOOM
11th quarter of decline, 20pc drop on last year - Gartner
Nintendo throws flaming legal barrel at YouTubing fans
All your walk-through vid revenue are belong to us
Report: AT&T dropping Facebook phone after dismal sales
Turns out folks won't buy that for a dollar