From owner-freebsd-security@FreeBSD.ORG Thu Feb 5 03:08:24 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A895A106564A for ; Thu, 5 Feb 2009 03:08:24 +0000 (UTC) (envelope-from smithi@nimnet.asn.au) Received: from sola.nimnet.asn.au (paqi.nimnet.asn.au [220.233.188.227]) by mx1.freebsd.org (Postfix) with ESMTP id 2CBC98FC1C for ; Thu, 5 Feb 2009 03:08:23 +0000 (UTC) (envelope-from smithi@nimnet.asn.au) Received: from localhost (localhost [127.0.0.1]) by sola.nimnet.asn.au (8.14.2/8.14.2) with ESMTP id n152f6dU063776; Thu, 5 Feb 2009 13:41:06 +1100 (EST) (envelope-from smithi@nimnet.asn.au) Date: Thu, 5 Feb 2009 13:41:06 +1100 (EST) From: Ian Smith To: Janos Dohanics In-Reply-To: <200902041003.38182.web@3dresearch.com> Message-ID: <20090205132745.S38905@sola.nimnet.asn.au> References: <200902041003.38182.web@3dresearch.com> MIME-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="0-1291112551-1233801666=:38905" Cc: freebsd-security@freebsd.org Subject: Re: OT - Heartland Payment Systems X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 05 Feb 2009 03:08:25 -0000 This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --0-1291112551-1233801666=:38905 Content-Type: TEXT/PLAIN; charset=ISO-8859-1 Content-Transfer-Encoding: 8BIT On Wed, 4 Feb 2009, Janos Dohanics wrote: > I came across this today: > > http://information-security-resources.com/2009/01/29/did-heartland-ceo-make-insider-trades/ > > The article discusses some questions about the security breach which occurred > at Heartland Payment Systems. Among other things, the article says: > > ˙˙Somehow, these guys went directly to the base level of the machine (to an > area) that was not part of the file table for the disk˙˙ > > ˙˙Somehow, they got around the operating system." > > I'm wondering what is suggested here? Apart from poor grammar, to me it suggests that they're trying really hard to not reveal which version of Windows they're running .. Ian --0-1291112551-1233801666=:38905--