Estimated reading time: 1 minute, 6 seconds

HACKERS TO ATTACK DYNAMICS GP

Tom Eston, SecureStateHackers are set to demonstrate how to attack Dynamics GP in a presentation at the Black Hat Abu Dhabi conference this week. Tom Eston and Brett Kimmell were expected to unveil Project Mayhem, which a press release describes as "a proof of concept tool that makes accounting fraud easy and potentially undetectable ...."

The two work for SecureState, a company that specializes in information security. That comforting scenario is accompanied by the release of a white paper to demonstrate how the code enables attackers to enter information into the accounting system in a way that is described as making it very difficult for technical security controls to detect. Asked for comment, Microsoft provided a link to a blog entry that states "There is not a security vulnerability in Microsoft Dynamics GP." However, this was written on May 24, 2010. But it would have been surprising if there had been a comment and an admission of vulnerability would have been astounding. Project Mayhem was actually designed to assist penetration testers in performing attacks, and the whitepaper describes controls for countering each attack method. In the words of the statement, "The goal of a public release for this utility is to promote security awareness for accounting controls and ensure that stronger controls are put in place for Microsoft GP and other financial systems in the future."

Read 1775 times
Rate this item
(0 votes)

Visit other PMG Sites:

PMG360 is committed to protecting the privacy of the personal data we collect from our subscribers/agents/customers/exhibitors and sponsors. On May 25th, the European's GDPR policy will be enforced. Nothing is changing about your current settings or how your information is processed, however, we have made a few changes. We have updated our Privacy Policy and Cookie Policy to make it easier for you to understand what information we collect, how and why we collect it.