CIS BenchmarkSYSTEM HARDENING VULNERABILITY MANAGEMENT

Accenture has reported leaked information on at least four cloud-based Amazon S3 storage servers.

The publicly downloadable servers exposed secret API data, authentication credentials, certificates, decryption keys, customer information, and other details that could be used to attack Accenture or one of its high profile clients.

The S3 buckets were found to be configured for public access, allowing anyone to download the data of they entered the relevant web addresses information their web browser. Learn about NNT’s System Hardening & Vulnerability Management solution.

One of the servers contained 40,000 plain text passwords, many of whom could belong to Accenture clients. Another server contained internal access keys and credentials for use by the Identity API used to authenticate credentials, and the master access keys for Accenture’s account with the AWS Key Management Service. If these credentials were stolen, this could allow an attacker full control over the company's encrypted data stored on Amazon's servers.

The information within these cloud servers in the wrong hands can do some serious harm to Accenture and its elite customer base.

 

Read this article on InfoSecurity Magazine

 

 

 

NNT Products
USA Offices
New Net Technologies Ltd
Naples
Suite #10115, 9128 Strada Place
Naples, Florida, 34108
Atlanta
201 17th Street, Suite 300
Atlanta, Georgia, 30363.

Tel: 1-888-898-0674
email[email protected]
UK Office
New Net Technologies Ltd
Spectrum House, Dunstable Road
Redbourn,
St Albans

Herts
AL3 7PR

Tel: 08456 585 005
Fax: 08456 122 031
email[email protected]
NNT Newsletter
Sign up to receive our monthly newsletter covering breaking security news, how-to-tips, trends and commentary directly to your inbox.


Google+ Linkedin Twitter - Change Tracker Facebook rss feed YouTube
CIS benchmarking SEWP Cybersecurity 500 Sans Institute
Copyright 2017, New Net Technologies Ltd. All rights reserved. 
NNT and Change Tracker are registered trademarks of New Net Technologies Ltd.
All other product, company names and trademarks are the property of their respective owners.