Skip to main content

PeopleSoft p0wnage possible with a day of GPU brute-forcing

posted onJuly 29, 2015
by l33tdawg
Credit:

L33tdawg: Dmitry Chastuhin from ERPScan will be at #HITBGSEC in Singapore where he'll show off an attack against SAP Afaria - One SMS to hack a company. 

ERPScan researcher Alexey Tuyrin says hundreds of Oracle PeopleSoft users, including banks, are running publicly-exposed services that are open to a token-plundering vulnerability.

The penetration tester says a breach could be worse than that of the Office of Personnel Management which recently lost millions of records in a hack pinned on China.

Oracle's PeopleSoft Human Resource Management System is used by more than 7000 companies including half of the Fortune 100, of which about a third are higher education organisations mainly based in the US. Tuyrin found through web searches some 549 exposed PeopleSoft systems of which 249 are commercial enterprises, 236 universities, 64 in government and military sectors, and 20 from banks.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th