From owner-freebsd-security@FreeBSD.ORG Wed Feb 4 15:42:25 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8CAF91065676 for ; Wed, 4 Feb 2009 15:42:25 +0000 (UTC) (envelope-from web@3dresearch.com) Received: from smtp.3dresearch.com (dorabella.3dresearch.com [66.167.251.2]) by mx1.freebsd.org (Postfix) with ESMTP id 5ED038FC13 for ; Wed, 4 Feb 2009 15:42:25 +0000 (UTC) (envelope-from web@3dresearch.com) Received: from fracasso.3dresearch.com (pool-96-236-181-134.pitbpa.east.verizon.net [96.236.181.134]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by vmail.3dresearch.com (Postfix) with ESMTP id F05A2D5128 for ; Wed, 4 Feb 2009 10:03:39 -0500 (EST) Received: from fracasso.3dresearch.com (fracasso.3dresearch.com [10.61.70.2]) by fracasso.3dresearch.com (Postfix) with ESMTP id 132AB17267 for ; Wed, 4 Feb 2009 10:03:39 -0500 (EST) From: Janos Dohanics Organization: 3D RESEARCH To: freebsd-security@freebsd.org Date: Wed, 4 Feb 2009 10:03:38 -0500 User-Agent: KMail/1.9.7 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Message-Id: <200902041003.38182.web@3dresearch.com> Subject: OT - Heartland Payment Systems X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 Feb 2009 15:42:25 -0000 I came across this today: http://information-security-resources.com/2009/01/29/did-heartland-ceo-make= =2Dinsider-trades/ The article discusses some questions about the security breach which occurr= ed=20 at Heartland Payment Systems. Among other things, the article says: =E2=80=9CSomehow, these guys went directly to the base level of the machine= (to an=20 area) that was not part of the file table for the disk=E2=80=9D =E2=80=9CSomehow, they got around the operating system." I'm wondering what is suggested here? =2D-=20 Janos Dohanics