IBurst hacked

08.11.2005

"...another South African ISP with egg on their face and their inefficiencies shining through... iBurst and WBS will be resolving these security flaws and will be providing you with better efficient service in the future. Maybe. We're still thinking about it."

37 screenshots of the compromised server have been made available on the Internet, showing, in detail, the information to which the hacker[s] had access.

The screenshots included the personal details of 94.7 Highveld Stereo personality, Paul Rotherham (ID number, bank account details, contact details etc.), as well as user offense monitoring systems, traffic shaping tools, sales projections and CRM functions associated with the company's equipment orders and cost prices etc.

When asked about the vulnerability, iBurst seemed to be ignorant of the fact that its systems had been compromised, having only mentioned the hoax e-mail to CSA, and not the security breach. Mpondo-Hendriks would not offer any further comment on the issue prior to going to print, saying: "The issue is currently under investigation."

In the screenshots that were made public, Rotherham's details were masked. The second posting on MyADSL added: "We would also like to confirm that the individuals who compromised the server did so in order to highlight these vulnerabilities, and did not in any way, shape or form, use the information obtained."