Security holes closed in New York Times intranet after hacker intrusion
Computerworld - Security holes in the intranet of The New York Times Co. have been patched following an intrusion by a 21-year-old hacker who peered into the company's databases earlier this month using Web browsers.
The hacker, Adrian Lamo, a self-described security consultant in San Francisco, said he found the holes Feb. 15 while browsing various Internet sites he chose at random.
By going through proxy servers and "figuring out the network and organizational structure," Lamo said he was able to access the company's databases in the intranet that included subscriber names and correspondence, editorial contact names, addresses and phone numbers, as well as Social Security numbers and other information about new employees. No credit card information was available, he said. The New York Times newspaper's Web site wasn't affected.
After finding the holes and the information, Lamo, who is known for previous excursions into the Web sites of companies including WorldCom Inc. (see story) and the former Excite@Home, said he contacted an intermediary at security firm SecurityFocus in San Mateo, Calif., to help him report the information to the newspaper. The paper was notified of the intrusion yesterday, Lamo said.
Toby Usnik, a Times spokesman, confirmed that the company had been notified of the security breach and has since fixed the holes that allowed Lamo to enter the intranet.
"We're continuing to investigate to ensure the security of the network," Usnik said. "At this point, we're determining what information may have been exposed. We take these kinds of potential security flaws very seriously."
Usnik wouldn't comment on what other actions might be taken by the company in connection with the incident.
Among the information Lamo said he viewed within the intranet were the home phone numbers for conservative political commentators Rush Limbaugh and Oliver North, who was a key figure in the Iran-Contra hearings during the 1980s.
While in the address database, Lamo said, he entered his own contact information along with a note describing himself as a security consultant. "It was more of a whim than anything else," he said. "It just came naturally to me while I was there."
Lamo said he didn't post notices of his penetration of the Times intranet on any public security forums and waited until the newspaper fixed the holes before going public with the information.
Lamo said he's not trying to find such holes to make corporate computing safer but rather follows his interests to see what he can find. "There was no motive behind the act. I realize that some people will



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts