What Eric did is commendable, in the developed world, its mandatory that any security breaches be made public!

only in Kenya is where you find strangers calling you with knowledge of how much you have in your account and how much more you can qualify for in loans!

examples;

http://www.itsecurity.com/features/top-security-breaches-2007-012208/

http://www.pwc.co.uk/eng/publications/berr_information_security_breaches_survey_2008.html

Date: Wed, 18 Feb 2009 18:40:58 +0300
From: kabugum@gmail.com
To: skunkworks@my.co.ke
Subject: Re: [Skunkworks] CBA - Dumpster Diving

the reality of the matter is that CBA messed up with their records and whoever discovered it is not the issue here, its not even relevant. You may have a point about hiding the I.D but then again thats a debatable issue. So many people discover vulnerabilities and post them online without hiding their identity. Chucks posted some materials on weak wireless networks in nairobi...i dont recall you saying anything about it.

nway, i support Joram in that unless you clearly point out an issue and show some kind of evidence, no one will take it seriously......i have seen it in my line of work.....even auditors will never take your word on anything....they need some kind of evidence...



2009/2/18 Evans Ikua <ikua.evans@gmail.com>
How about some anonymity? Its not exactly good sense to just post someone else's info while not even hiding your ID.

2009/2/18 Joram Mwinamo <joram.mwinamo@gmail.com>

Evans if companies are not taken to task about such stuff they will never improve. How do you feel knowing your personal banking information could be wrapping the meat for your gardener?Worse still there could be thugs collecting private info coz they know where to get it

I think organisations should be more careful,i dont see any security breach with posting such info here....

2009/2/18 Evans Ikua <ikua.evans@gmail.com>

Thats really serious. But I would advise against posting this kind of info on a list. That they have made a mistake does not mean that we have a right to place it on the internet. With the new laws you may get yourself in trouble. This is debatable but I think ethics will support me.

Anyone on this list with a security responsibility had better learn.

2009/2/18 Jacob Odada <jacob.odada@gmail.com>

wow ! thats interesting.
Now could you go back to that place and get goodies again maybe this time you will get logs with account balances, I will be more interested in those with over 5 million (possibly female)   ;)

On a serious note I think that is negligence considering the logs are for april last year which means 90% of those ID's probably still work.


2009/2/18 Eric Mugo <kabugum@gmail.com>
Folks,


    Yesterday i go to buy fries near home and as the dude is wrapping up my goodies, i notice that the paper he is using has security logs (see attached) of CBA staff obviously from one of their logging systems. One can pick up several usernames and i shudder to think what more information i can get using those user-names just through Social Engineering.  Question is:

1. How did a record of Logs end up at kinoo
2. who manages such information at CBA? Surely they must have shredders somewhere.

Chuks i guess now you have an idea where to conduct your next War Drive........... or maybe you could try social engineering.

Regards,
Eric Mugo.

_______________________________________________
skunkworks mailing list
skunkworks@my.co.ke
http://ole.kenic.or.ke/mailman/listinfo/skunkworks
Blog http://skunkworks-ke.blogspot.com
Beta Blog http://blog.my.co.ke
Get Skunkworks RSS Feeds: http://www.jahazi.com/rss/


_______________________________________________
skunkworks mailing list
skunkworks@my.co.ke
http://ole.kenic.or.ke/mailman/listinfo/skunkworks
Blog http://skunkworks-ke.blogspot.com
Beta Blog http://blog.my.co.ke
Get Skunkworks RSS Feeds: http://www.jahazi.com/rss/


_______________________________________________
skunkworks mailing list
skunkworks@my.co.ke
http://ole.kenic.or.ke/mailman/listinfo/skunkworks
Blog http://skunkworks-ke.blogspot.com
Beta Blog http://blog.my.co.ke
Get Skunkworks RSS Feeds: http://www.jahazi.com/rss/



--
Sent from my Watch©

Our greatest fear is not that we are inadequate,but that we are powerful beyond measure.It is our light, not our darkness, that frightens us.There is nothing enlightened about shrinking so that other people won't feel insecure around you.As we let our own light shine, we consciously give other people permission to do the same.
As we are liberated from our fear,our presence automatically liberates others.

_______________________________________________
skunkworks mailing list
skunkworks@my.co.ke
http://ole.kenic.or.ke/mailman/listinfo/skunkworks
Blog http://skunkworks-ke.blogspot.com
Beta Blog http://blog.my.co.ke
Get Skunkworks RSS Feeds: http://www.jahazi.com/rss/


_______________________________________________
skunkworks mailing list
skunkworks@my.co.ke
http://ole.kenic.or.ke/mailman/listinfo/skunkworks
Blog http://skunkworks-ke.blogspot.com
Beta Blog http://blog.my.co.ke
Get Skunkworks RSS Feeds: http://www.jahazi.com/rss/



Invite your mail contacts to join your friends list with Windows Live Spaces. It's easy! Try it!