Security

Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy 'login details leaked'

Yes, that's Gartner’s security consultancy of the year


Monday’s news that multinational consultancy Deloitte had been hacked was dismissed by the firm as a small incident.

Now evidence suggests it's no surprise the biz was infiltrated: it appears to be all over the shop, security wise.

On Tuesday, what seemed to be a collection of Deloitte's corporate VPN passwords, user names, and operational details were found lurking within a public-facing GitHub-hosted repository. These have since been removed in the past hour or so. In addition, it appears that a Deloitte employee uploaded company proxy login credentials to his public Google+ page. The information was up there for over six months – and was removed in the past few minutes.

We were tipped off to these pages by an eagle-eyed reader, and grabbed a couple of screenshots of the potentially offending data:

Screenshot of some of the alleged VPN details for accessing Deloitte's network that leaked onto GitHub – we've censored what looks like passwords

 

Screenshot of a portion of the Google+ page with Deloitte proxy login information

On top of these potential leaks of corporate login details, Deloitte has loads of internal and potentially critical systems unnecessarily facing the public internet with remote-desktop access enabled. All of this gear should be behind a firewall and/or with two-factor authentication as per industry best practices. And likely the best practices Deloitte recommends to its clients, ironically.

“Just in the last day I’ve found 7,000 to 12,000 open hosts for the firm spread across the globe,” security researcher Dan Tentler, founder of Phobos Group, told The Register today. “We’re talking dozens of business units around the planet with dozens of IT departments showing very different aptitude levels. The phrase ‘truly exploitable’ comes to mind.”

For example, he found a Deloitte-owned Windows Server 2012 R2 box in South Africa with RDP wide open, acting as what appears to be an Active Directory server – a crucial apex of a Microsoft-powered network – and with, worryingly, security updates still pending installation. Other cases show IT departments using outdated software, and numerous other security failings.

Here's an example system with NetBIOS open:

Here's what appears to be an Active Directory server with RDP open...

...complete with administrative users and, if you look closely, Windows Updates still pending:

And as other infosec experts have spotted, plenty of other stuff is sitting online, searchable using Shodan, waiting to be prodded by miscreants and other curious minds:

These systems could be used as crucial footholds for hackers into the consultancy giant's internal networks.

The Google+ page appeared to show that a Deloitte employee has been writing down VPN access controls on his personal page in full view of everyone. Using Google’s vaunted search facilities, a hacker could easily find enough information to launch an attack with a good chance of success.

All this is embarrassing for Deloitte, which billed itself as the top IT security consultancy in the industry. The firm makes millions selling its tech guru services to others for a hefty price – and yet seems to ignore potentially gaping holes in its own IT infrastructure.

The details now emerging are also rather embarrassing for analyst firm Gartner, which in June named Deloitte the world’s best IT security consultancy for the fifth year in a row. Gartner has yet to respond to a request for information on how its conclusion was reached.

It doesn’t help that Deloitte isn’t much liked by other security researchers for its business practices. The firm has a reputation for low-balling contractors on fees – particularly for penetration testing – and the schadenfreude of Deloitte being so bad at its own security has delighted some.

“Between Equifax and Deloitte, starting to see though the tissue paper of corporate America’s security industry companies making huge claims, when in reality it’s a whole bunch of hypocrites,” said Tentler.

“You’d think Deloitte claims to have all this super elder-god style security talent. If that was the case they might consider using that talent on its own infrastructure.”

Deloitte has not responded to a request for comment. ®

Send us news
78 Comments

Bank manager tricked into handing $35m to scammers using fake 'deep voice' tech

Plus: Microsoft Translator machine learning software now supports over 100 languages

In brief Authorities in the United Arab Emirates have requested the US Department of Justice's help in probing a case involving a bank manager who was swindled into transferring $35m to criminals by someone using a fake AI-generated voice.

The employee received a call to move the company-owned funds by someone purporting to be a director from the business. He also previously saw emails that showed the company was planning to use the money for an acquisition, and had hired a lawyer to coordinate the process. When the sham director instructed him to transfer the money, he did so thinking it was a legitimate request.

But it was all a scam, according to US court documents reported by Forbes. The criminals used "deep voice technology to simulate the voice of the director," it said. Now officials from the UAE have asked the DoJ to hand over details of two US bank accounts, where over $400,000 from the stolen money were deposited.

Continue reading

Amazon textbook rental service scammed for $1.5m

Michigan man arrested for borrowing costly textbooks and selling them

A 36-year-old man from Portage, Michigan, was arrested on Thursday for allegedly renting thousands of textbooks from Amazon and selling them rather than returning them.

Andrew Birge, US Attorney for the Western District of Michigan, said Geoffrey Mark Hays Talsma has been indicted on charges of mail and wire fraud, transporting stolen property across state lines, aggravated identity theft, and lying to the FBI.

Also indicted were three alleged co-conspirators: Gregory Mark Gleesing, 43, and Lovedeep Singh Dhanoa, 25, both from Portage, Michigan, and Paul Steven Larson, 32, from Kalamazoo, Michigan

Continue reading

Computer scientists at University of Edinburgh contemplate courses without 'Alice' and 'Bob'

Academics advised to consider excluding certain terminology for the sake of inclusivity

A working group in the School of Informatics at the University of Edinburgh in Scotland has proposed a series of steps to "decolonize" the Informatics curriculum, which includes trying "to avoid using predominantly Western names such as Alice/Bob (as is common in the computer security literature)."

The names Alice and Bob were used to represent two users of a public key cryptography system, described in a 1978 paper by Ronald Rivest, Adi Shamir, and Leonard Adleman, "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems." And since then, a variety of other mostly Western names like Eve – playing an eavesdropper intercepting communications – have been employed to illustrate computer security scenarios in related academic papers.

The School of Informatics' working group reflects the University of Edinburgh's commitment to diversity, equity, and inclusion and to meet specific obligations spelled out in Scottish regulations like the Equality Act 2010 and the Public Sector Equalities Duty.

Continue reading

Toyota needs more than its Cheer Squad to deal with chip shortages, as five more home factories forced into idleness

Car makers facing increasingly tough times until supply catches up

Toyota said it would cut car production by up to 150,000 vehicles due to ongoing semiconductor shortages and restrictions associated with the COVID-19 pandemic.

The car maker is idling five factories in home country Japan on some days in November, which affects the production of popular models including Corolla and Camry.

Toyota started cutting production in August due to chip shortages and said, "we expect the shortage of semiconductors to continue in the long-term".

Continue reading

Missouri governor demands prosecution of reporter for 'decoding HTML source code' and reporting a data breach

Salus populi suprema lex esto ... or perhaps not

A Missouri politician has been relentlessly mocked on Twitter after demanding the prosecution of a journalist who found and responsibly reported a vulnerability in a state website.

Mike Parson, governor of Missouri, described reporters for local newspaper the St Louis Post Dispatch (SLPD) as "hackers" after they discovered a web app for the state's Department of Elementary and Secondary Education was leaking teachers' private information.

Around 100,000 social security numbers were able to be exposed when the web app was loaded in a user's browser. The public-facing app was intended to be used by local schools to check teachers' professional registration status. So users could tell between different teachers of the same name, it would accept the last four digits of a teacher's social security number as a valid search string.

Continue reading

Everyone who wants a smartphone for Chrimbo will get one, but in the real world things are somewhat different

Global handset market slips in Q3 on sliding chipset availability, says Canalys

Crippling component shortages caused smartphone shipments to dip in calendar Q3, though it was the also-rans, vendors outside of the top five biggest brands with the lowest economies of scale, that suffered most.

Preliminary results from Canalys show the market declined 6 per cent year-on-year. The analyst was not yet ready to make public the absolute shipment figures but a year ago sales into the channel were 348 million, so they look 20.9 million units lighter.

"The chipset famine has truly arrived," said Ben Stanton, principal analyst. "On the supply side, chipset manufacturers are increasing prices to disincentivize over-ordering, in an attempt to close the gap between supply and demand. But despite this, shortages will last until well into 2022."

Continue reading

Windows terminates here. Please remember to finish setting it up on arrival

Washington Metro admin has taken an early lunch

Bork!Bork!Bork! It's a whole new world for bork today as a Washington Metro platform indicator suggests an alternative to the usual train for weary commuters. How about getting a bit more out of Windows?

This is a suggestion that everyone wants to see while waiting for a Yellow Line train at Washington Metro's Huntington Station (located, helpfully, on Huntington Avenue in the Huntington Area).

Continue reading

Boeing 737 Max chief technical pilot charged with deceiving US aviation regulators over MCAS

He hasn't got $2.5bn to hand to the DoJ, unlike his bosses

A Boeing 737 Max test pilot has been charged with obstructing US aviation safety regulators, according to the US Department of Justice, and faces up to 20 years in prison if convicted.

Former 737 Max chief technical pilot Mark Forkner, 49, of Texas, has been charged with "deceiving the Federal Aviation Administration's Aircraft Evaluation Group" (AEG) and committing fraud by misleading Boeing's airline customers into believing the 737 Max was a safe aircraft.

"Forkner allegedly abused his position of trust by intentionally withholding critical information about MCAS during the FAA evaluation and certification of the 737 MAX and from Boeing's US-based airline customers," said Assistant Attorney General Kenneth A Polite Jr of the Justice Department's Criminal Division in a statement.

Continue reading

Keep expectations low and you won't be disappointed: OVH manages 6 per cent increase on its IPO debut

French cloud provider puts outage and fire behind it to focus on beating the big players

French cloud and colocation service provider OVH has edged a 6 per cent increase in its nominal market valuation following its initial public offering on the Euronext Paris stock exchange.

The Gallic tech challenger, viewed by some as the great cloud hope for Europe, has faced its fair share of challenges this year, having seen fire engulf its Strasbourg operations on 10 March.

But the European IPO proved hot in other ways, with shares up to around €19.70, well on track with the launch price range of €18.50-€20.

Continue reading

Space boffins: Exoplanet survived hydrogen-death of its host star

Hope extended to gas giants across the universe... well, it is Friday

Those of us fatalistically counting down the minutes until the Earth is engulfed by the dying embers of the Sun in approximately 5 billion years might be offered a glimmer of hope by the news that planets – or at least gas giants – can survive the collapse of their host star.

Joshua Blackman, a postdoctoral researcher at Australia's University of Tasmania, and his colleagues have found evidence of a Jupiter-like planet orbiting a white dwarf star somewhere outside the Solar System off in the Milky Way.

It is the first time scientific evidence of a planet surviving a star's collapse has been presented, although theoretical models predicted it is possible, according to a study published in Nature.

Continue reading

Spanner in the works: The goal is not 100% compatibility, Google says of PostgreSQL interface

Meanwhile, Yugabyte says PostgreSQL compatibility for its distributed database dates back to 2019

Google has clarified details of the interface between its popular distributed SQL database-management-cum-storage-service Spanner and the open-source RDBMS PostgreSQL.

According to a blog published this week, Spanner's PostgreSQL interface uses "the familiarity and portability of PostgreSQL" to make developers' lives easier.

"Teams can be assured that the schemas and queries they build against the Spanner PostgreSQL interface can be easily ported to another PostgreSQL environment, giving them flexibility and peace of mind," said Justin Makeig, product manager for Cloud Spanner.

Continue reading