Redspin
Redspin Research
Redspin Presentations
Redspin Videos
Redspin Data Sheets
Redspin White Papers
Technical Resources
Regulatory Resources
Security Management
Advisory
Contact Us Toll Free - 800-721-9177
Request A Quote
Security Blog
Assessment Services Assessment Tools Security Research About Us Contact Us
Redspin Research
Anatomy of a Hack
By Nathan Drier



Read the Free Redspin Article
Fill out the form below to download "Anatomy of a Hack" researched and written by Nathan Drier at Redspin.

The following story is true. It took place on a live production network. The tools, methods, vulnerabilities, and risks are all very real. Names and IP addresses have been changed to protect the businesses involved.

What makes this interesting to me, and why I thought it would be educational to document this, is the unique chain of misconfiguration and vulnerabilities that had to line up to allow a hack of this scale. The vulnerabilities by themselves weren't that critical, but the information I was able to obtain and the level of access I had are the things that nightmares are made of. This isn't skimming a few credit card numbers or sniffing some sensitive docs over unsecured wireless. This is the type of hack that makes businesses close their doors with little chance of recovery. If there is one thing I hope you can learn from this, it's: care about the little things, because fixing even one of the minor vulnerabilities described here could have broken this entire chain of events.

Please supply us with the following details. Your information will be kept completely private.
* = Required Information
Contact Information:
*
*
*
*
*
©2009 Redspin, Inc. Home  |  Assessment Services  |  Assessment Tools  |  Security Research  |  About Us  |  Contact Us  |  Site Map
©2009 Redspin, Inc. | Privacy Policy
Site Design and Development by Petro Design Co.

External Network Security Assessments

Internal Network Security Assessments

Website Security Assessments

Special Security Assessment Services

PCI Services

Casino IT Audits

Testing and Certification Program

NMap XML2SQL

fTrace

Crackulator

Redspin Research

Penetration Testing Resources

Regulatory Resources

Security Management Advisory

Corporate Ethos

Environmental Ethos

Redspin In The News

Press Releases

Upcoming Events

Careers

Contact Us

Request Pricing