TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bangladesh Bank exposed to hackers by cheap switches, no firewall

78 点作者 r0h1n大约 9 年前

7 条评论

dboreham大约 9 年前
This article states that the systems related to SWIFT transfers were supposed to be on an isolated network, but were not. Specifically that cheap unmanaged switches were used rather than expensive managed switches that would have allowed network isolation. Of course anyone who understands network security would point out that to rely on switch-based isolation alone is too risky. Switches can be compromised and mis-configured and sometimes don't provide the expected level of isolation even when correctly configured.
评论 #11550797 未加载
评论 #11550902 未加载
walrus01大约 9 年前
This is totally unsurprising to anyone that has seen in person the state of "enterprise" IT at a large organization in India, Pakistan or Bangladesh.
评论 #11552813 未加载
nickpsecurity大约 9 年前
I have a feeling, but not evidence, that this bank&#x27;s security was this bad on purpose to aid the thieves. Someone in the middle or on top might be getting a cut. Has anyone looked into that angle?<p>And does anyone have an I.P. address to another Bangladesh bank with $10 routers and stuff on SWIFT network? Just so I can try to SMTP a warning to that address to help them avoid being hit, too.
评论 #11552817 未加载
koolba大约 9 年前
Short of building&#x2F;installing your own router how can a highly sensitive business protect themselves from things like this? Obviously you don&#x27;t want to be running random vulnerable hardware that is never updated. But what else?<p>I was thinking about having multiple layers (<i>security loves onions!</i>) with interchangeably components that you roll over at random. That way any given attack vector at one point might be mitigated by a different interface below it. Literally unplugging and plugging things in to shake things up.
评论 #11551945 未加载
评论 #11551650 未加载
cdevs大约 9 年前
Managed switch or linksys router how the hell is it so easy to push that much money around even if I work in that &quot;room&quot; and give you access to my computer for a hour there should have been some software to notice somethings going on. The switch is could have been a $10,000 switch and it still sounds to easy. I&#x27;d say inside job unless scanning the up range screamed out the company name and some easy vulnerabilities&#x2F;old software versions which could have also been the case.
ajonit大约 9 年前
&quot;Most of the payments were blocked but $81 million was routed to accounts in the Philippines &quot; Given that in most of the countries &quot;Know Your Customer&quot; (or its variations) is strictly followed, I wonder what makes it so difficult for multi nation police( involving interpol) to reverse track the hacker - from money receiving accounts -&gt; account holders -&gt; beating the s<i></i>t out of them to reveal senders name.
评论 #11551701 未加载
评论 #11551534 未加载
nraynaud大约 9 年前
I don&#x27;t feel comfortable attacking such a poor country on the prince of their networking gear.
评论 #11551682 未加载
评论 #11552504 未加载