Microsoft Leaks Customer Information

Please wait...

This article was written on an older version of FileFront / GameFront

Formatting may be lacking as a result. If this article is un-readable please report it so that we may fix it.


Microsoft have leaked, among other things, a 1GIGABYTE database containing millions of customer names and mailing addresses onto one of their FTP servers, normally used for patch downloading. [quote]Although the FTP server was intended for use by Microsoft's product support organization, marketing staff appeared to be using the server, unaware that it was accessible from the Internet, said Russ Cooper, "surgeon general" at security services provider TruSecure. "They probably thought they were sharing the files just with other Microsoft people and that it was a protected server," Cooper said. A Microsoft spokeswoman said the company has disabled downloads from the PSS Support server "to improve the privacy protections on the site." The server's outgoing file directory will be brought back online after a review of its security architecture, she said. Among the many people who stumbled upon the open FTP server was Andreas Marx, a virus researcher with GEGA IT-Solutions. In a phone interview, Marx said he first noticed the security problem Nov. 15 after connecting to the FTP server to download a security patch for Microsoft Office. Marx said numerous directories in a section of the site marked "outgoing" were accessible and contained files with "really interesting names." Marx said he reported the problem to Microsoft, and the company appeared to take the FTP server offline Monday. When the server was restored later in the day, it had been "completely cleaned" of confidential files, Marx said. But shortly thereafter, he said, Microsoft employees apparently began uploading new confidential files to the public section of the FTP server. "It looked like Microsoft had a policy about what files could be uploaded, but that some employees weren't following it," said Marx. [/quote] View the full article [url="http://www.wired.com/news/infostructure/0,1377,56481,00.html.com"]HERE[/url]
Comments on this Article

There are no comments yet. Be the first!