Re: [CentOS] anthem details

2015-02-07 Thread Mark LaPierre
On 02/06/15 18:24, Les Mikesell wrote: > On Fri, Feb 6, 2015 at 5:05 PM, John R Pierce wrote: >> On 2/6/2015 7:19 AM, Always Learning wrote: >>> >>> stronger passwords for SQL >> >> >> the hackers had the database administrators user account credentials, and >> were coming in through the V

Re: [CentOS] anthem details

2015-02-06 Thread Rob Kampen
On 02/07/2015 12:48 PM, Always Learning wrote: On Fri, 2015-02-06 at 17:24 -0600, Les Mikesell wrote: On Fri, Feb 6, 2015 at 5:05 PM, John R Pierce wrote: On 2/6/2015 7:19 AM, Always Learning wrote: stronger passwords for SQL the hackers had the database administrators user accoun

Re: [CentOS] anthem details

2015-02-06 Thread Always Learning
On Fri, 2015-02-06 at 17:24 -0600, Les Mikesell wrote: > On Fri, Feb 6, 2015 at 5:05 PM, John R Pierce wrote: > > On 2/6/2015 7:19 AM, Always Learning wrote: > >> > >> stronger passwords for SQL > > > > > > the hackers had the database administrators user account credentials, and > > wer

Re: [CentOS] anthem details

2015-02-06 Thread John R Pierce
On 2/6/2015 3:24 PM, Les Mikesell wrote: Hmmm, maybe a reasonable argument for the crypto-card type VPNs where the passwords aren't reusable... indeed, my $job uses an RSA token based authentication for the VPN, but internal host access uses simple username/password. -- john r pierce

Re: [CentOS] anthem details

2015-02-06 Thread Les Mikesell
On Fri, Feb 6, 2015 at 5:05 PM, John R Pierce wrote: > On 2/6/2015 7:19 AM, Always Learning wrote: >> >> stronger passwords for SQL > > > the hackers had the database administrators user account credentials, and > were coming in through the VPN via said credentials. I doubt stronger > pa

Re: [CentOS] anthem details

2015-02-06 Thread John R Pierce
On 2/6/2015 7:19 AM, Always Learning wrote: stronger passwords for SQL the hackers had the database administrators user account credentials, and were coming in through the VPN via said credentials. I doubt stronger passwords would have mattered. -- john r pierce

Re: [CentOS] anthem details

2015-02-06 Thread Valeri Galtsev
On Fri, February 6, 2015 9:19 am, Always Learning wrote: > > On Fri, 2015-02-06 at 08:40 -0600, mshinn wrote: > >> I recommend reading up on kreb's site: >> >> http://krebsonsecurity.com/2015/02/china-to-blame-in-anthem-hack/ >> >> Not sure the "hack" was an issue with their platforms per se. >> >

Re: [CentOS] anthem details

2015-02-06 Thread Always Learning
On Fri, 2015-02-06 at 08:40 -0600, mshinn wrote: > I recommend reading up on kreb's site: > > http://krebsonsecurity.com/2015/02/china-to-blame-in-anthem-hack/ > > Not sure the "hack" was an issue with their platforms per se. > > " > “On January 27, 2015, an Anthem associate, a database admini

Re: [CentOS] anthem details OT

2015-02-06 Thread Tom Bishop
On Fri, Feb 6, 2015 at 8:17 AM, Chris Wensink < cwens...@five-star-plastics.com> wrote: > Hello Everyone, > > Does anyone have any more detail about what kind of system Anthem / Blue > Cross was running and what kind of attack broke into their system? > > It's terrible that it happened, but I thin

Re: [CentOS] anthem details

2015-02-06 Thread mshinn
On 02/06/2015 08:17 AM, Chris Wensink wrote: Hello Everyone, Does anyone have any more detail about what kind of system Anthem / Blue Cross was running and what kind of attack broke into their system? It's terrible that it happened, but I think it would benefit all Admins everywhere to learn