Skip to navigation
   
Davey Winder's Blog

Spear phishing Catch 22 for Salesforce.com

By Davey Winder in Editorial

Posted in Uncategorized on November 10, 2007 at 11:39 am

Permalink | Author Profile

Salesforce.com has been the victim of a classic spear phishing attack, where a highly targeted social engineering exploit is used in an attempt to persuade a single employee to reveal confidential corporate information that can then be used as ammunition for further and more widely spread attacks.

The CRM vendor has admitted that one of its employees had fallen foul of such a spear phishing scam and handed over a password to the cyber-criminal involved. This led to a customer contact database being copied, and consequently the “first and last names, company names, email addresses, telephone numbers of salesforce.com customers, and related administrative data belonging to salesforce.com” being leaked. I am led to believe that a number of the customers so exposed were then taken in by a phishing scam which was made all the more believable by the amount of accurate personal data it was able to use.

John Stewart, founder of secure authentication specialists Signify reckons the whole thing should not come as a surprise to anyone, telling me “the growing popularity of the SaaS (Software as a Service) model means that it’s too big a honeypot for the Internet Underworld to ignore.” One of the problems being that there’s a blind spot in corporate security: whereas two factor authentication and VPN encryption is considered essential before remote users are allowed access to this data on the corporate network, as soon as it is hosted by a third party, it seems that just a web browser and a password are all that’s needed. “In essence, you’ve uploaded your entire customer database and sales pipeline to a public website and protected it with a basic password” Stewart insists, adding the data is no more secure than your Facebook login.”

Salesforce.com is now recommending the use of two-factor authentication (2FA) for service login, but this requires replacing the password with a 2FA process by enabling the single sign on function: something that is limited in the edition used by the majority of SME ‘Pro Edition’ customers. With single sign on being, effectively, a global setting which is either on or off for everyone it doesn’t take a genius to realise that Salesforce still as a long way to go. SMEs are going to baulk at the cost of deploying 2FA tokens to every user, including everyone on the road, all managers, office and admin staff. The spear phishing attack has shown how just a single weak link in the chain can be exploited after all. The other option is the equally expensive upgrade to the Enterprise Edition, something of a Catch 22 it seems.

“It is frustrating that our customers cannot extend the use of their tokens to secure their Salesforce.com accounts too.

12345
Rated: 20% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Tom Wiseman - November 13, 2007 on 11:02 am

I presume this jargon ridden 1st paragraph means simply that an employee was blackmailed or coerced - if so, say so - say what you mean in clear English.
Criminal activity will always find a way of exploiting human weaknesses or vulnerabilities and so ‘mere’ ‘mechanical’ or ‘electronic’ procedures however clever are always at risk of subversion - as ever, you need to look after your staff, however clever you think you are.

Comment by Davey Winder - November 13, 2007 on 11:50 am

It means what it says: that an employee was the victim of social engineering in a highly targeted manner, something known as spear phishing. Try reading it again and you might spot that the paragraph actually explains what spear phishing is. I would hardly call the use of the widely understood term ’social engineering’ and the detailed explanation of ’spear phishing’ to constitute a jargon ridden anything…

Comment by Mas Funaki - June 30, 2008 on 1:28 am

NHK is Japan’s public television network.(http://www.nhk.or.jp/nhkworld/) NHK produces a program called; ” Close-up Today ” a half hour prime time program broadcated at 7:30PM from Monday to Thursday in Japan.This is one most watched programs for last fourteen years.The format of the program is that the host of program discusses with guests on subject which focuses on viewers’ current interests and questions such as social trends,social problems,people and so on.This program is similar to ” Nightline ” on ABC.

I’m currently working on an upcoming project about SaaS(Software as a Service).Most viewers are not aware of SaaS which are used by businesses we deal with everyday. In this program, we are going to show our viewers about this business trend in IT field. This program will focus on how SaaS work by showing provider side and customer side.
Also, we would like to address downside of SaaS as well.

I am looking for a person who could discuss why SaaS are target of hackers and cutting edge hacking
technology for on camera interview.I would like to find out weather you could discuss as well as your
availability for this week.
Thank you for your assistance.

Mas Funaki

Comment by karry - November 3, 2008 on 2:51 am

http://www.batterygoshop.co.uk/acer/as07a32-battery.htm acer as07a32 battery

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

office information dumb Application Notebooks Voice disclosure Programming chips Kill Switch carbon copy meme standards Johnny Depp theft MiniBook Flash ROFL Palm payments Cisco Architecture environment transactional security Supercomputer Top 500 Jobs acquisition MessageLabs stupid security Europe man-in-the-middle hacking linkedin Michael Jackson money Windows memory adware lawsuit Firefox CAPTCHA Patents students Beta hypervisor earth hour green cloud christmas Army spending remote working trust payment server Digg Data Centre universe VeriSign sick shopping Apple iPad terrorism data ISP EU spam smartphone Noro Analysis innovation fake App Lotus Blogging Texting betting rootkits stupidity mobile Windows 7 Olympics computing Software fraud scareware NASA management OCR AMD open source debian fool economy policy scam Mafia Internet Explorer Energy privacy Browser Psychic Blog second life Paris Hilton prison Mars Parenting Sex outsourcing Browsers Harry Potter data protection e-commerce Mobile Phones virtualisation Research banks patent Media ASUS politics computers ecommerce virus web Election Licensing Dell Health IDC worm Microsoft Enterprise gadgets Game Google Earth Children services archiving Linux virtual world productivity Backlash Kindle PS3 Meh code remote home family SSL Palm Pre Zango staffing Education exploit games botnet hacker Spotify fun FBI service Obama Porn football banking statistics patch management Trojan black hat help Netbook Silverlight network global Music GMail gaming social networking Kaspersky Performance computing Mobile Phone credit card fraud Business MSN Intel Twitter printing VPN Bill Gates RAM xmas President Nexus web 2.0 Recall encryption size malware ISPA digitise Deal Gateway museum Madness Video recession Developers Space Project BOFH admin economics YouTube graphics millions snooping Networks Adobe Digital Footprint mail Ballmer Tesco tax iPhone 3G avatar Kin nightmare monetisation Scotland Banned Russia Google Android Review support App Store Rumour parental control poll virtual machine Marketing news Eee PC storage Battery law Steve Jobs Facebook InfoSec USA library books scan biometrics holidays iPhone 3GS hardware Gadget Death Windows Phone 7 Series Yahoo SMS OS eBook Press Internet Conference search hubdub work credit crunch McKinnon surveys Hack Web Development Rant Gartner workplace NBC Finjan copyright compromise IBM Pirate development Guardian Advertising Nintendo symantec IT Big Brother hoax Funny School HPC Amazon Employment crime report iPhone DNS ID Theft computer VM survey Jesus Phone phishing Opinion documentation The Federation worker MSNBC Steve Ballmer Military desktop Addiction iPod Texas Instruments email migration world of warcraft Eee Top 10 wifi IP technology console Experiment Acer Trousers Apps Microchip teleworking Study tech BSI Government China RATM e Geeks Vista GSM XP Psion broadband Sony Retail campaign HP science
Advertisement
Advertisement