• On TechRepublic: Get 5 cool Microsoft apps -- for free
August 23, 2007 7:38 AM PDT

Monster puts kibosh on rogue server

by Dawn Kawamoto
  • Font size
  • Print
  • 3 comments

Malicious attackers beware, a Monster may be coming after you.

After a malicious attackers pilfered job candidate information from its job seeker database, Monster located the attacker's rogue server and pulled the plug, the company announced Wednesday. But fallout from that episode remains.

The hooligans, who loaded a Trojan horse called Infostealer.Monstres on the company's resume database, got access to job candidates' names, addresses, phone numbers and e-mail addresses.

They weaseled their way in by gaining access to a legitimate log-in credential reserved for employers, via a computer that had been infected with the malicious software.

Now, Monster is assessing the extent of the damage. The company is investigating the number of job seekers who were affected and will be contacting them. Monster is also offering information on avoiding online scams, phishing and fraud during a job search.

Dawn Kawamoto covers enterprise security and financial news relating to technology for CNET News. E-mail Dawn.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (3 Comments)
  • prev
  • next
Monsterous F-up
by ericwoodford August 23, 2007 2:54 PM PDT
We'll probably never find out if it was some admin surfing the web from the production server, but man what a mistake. Luckily for Monster, I don't have financial information up on their site, unfortunately, my spam count will probably double now.
Reply to this comment
Monster Rogue Server Problem
by bjayers August 25, 2007 12:39 PM PDT
I became aware of this early on and is exactly why I have not posted my resume on Monster for my current job search. Monster clearly is not doing a good job in securing their database.
Reply to this comment
Monster's debacle
by pslm46vs10 August 27, 2007 12:54 PM PDT
Woa! I'm glad that i get the security newsletter, otherwise i'm not sure I would have known about this. I've been getting calls from people claiming that they got my information from a resume site such as Monster, Career Builder, etc, and that I'd requested information from them. I DID NOT! I'm wondering if this was the cause of those calls?
(3 Comments)
  • prev
  • next
advertisement

Google's social side aims for some Buzz

Facebook and Twitter are the darlings of the social-media world, not Google--which hopes to change that with Buzz, betting it can organize your online social life.

Watching the birth of a gaming start-up

Stewart Butterfield and his friends are back at it with a new company. CNET's Daniel Terdiman was given exclusive, behind-the-scenes access as they built it from scratch.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right