Shostack + Friends Blog Archive


North Carolina Transportation Department, 16,000 credit card #s, outside intruder

The Associated Press is reporting that:

An Internet server used by the state Transportation Department’s Ferry Division to process credit card payments for ferry fares may have been breached by outsiders, the agency said Friday.
The computer database contained 16,000 credit card numbers, the DOT said. The Office of the State Controller has notified its credit card processor about the possible breach and it will contact credit card companies.

Why are database servers reachable from the internet?