<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Jobs.ie Hacked - Anyone Else?</title>
	<atom:link href="http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/</link>
	<description>Software for the Human Capital Industry</description>
	<pubDate>Thu, 28 Aug 2008 13:04:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Alison Deegan</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-253</link>
		<dc:creator>Alison Deegan</dc:creator>
		<pubDate>Sun, 06 Apr 2008 21:32:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-253</guid>
		<description>I am one of the people who's CV/resume was apparently illegally downloaded. I was horrified at this. I do not have a bebo, myspace facebook or any other social networking type site that puts your information on the internet. I just wanted a job.  I also tried to delet my account but all I could do was delete my CV and change my account, very poor! I have to now put up a further secure warning in my bank, I got a call from a recruitment agency, perhaps that is who downloaded the CVs. Besides all my complaining, I would like to know what exaclty will happen with my details?and why my cv it was awful!!!!!.
Alison</description>
		<content:encoded><![CDATA[<p>I am one of the people who&#8217;s CV/resume was apparently illegally downloaded. I was horrified at this. I do not have a bebo, myspace facebook or any other social networking type site that puts your information on the internet. I just wanted a job.  I also tried to delet my account but all I could do was delete my CV and change my account, very poor! I have to now put up a further secure warning in my bank, I got a call from a recruitment agency, perhaps that is who downloaded the CVs. Besides all my complaining, I would like to know what exaclty will happen with my details?and why my cv it was awful!!!!!.<br />
Alison</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan &#124; JobsBlog.ie</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-27</link>
		<dc:creator>Ivan &#124; JobsBlog.ie</dc:creator>
		<pubDate>Wed, 02 Apr 2008 16:02:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-27</guid>
		<description>Well when you get someone from a far away country that you are not too sure what continent is it on, paying with the credit card of a resident in the US, usually a very young one, subscribing to your CV database online,... as a manager of a job board, should act as a safe keeper of the users data, and should not think about the revenue that you can make quickly there.

Monster had it, Jobs.ie had it, and LoadzaJobs.ie was offline the whole day yesterday!!!

Just a bit too greedy....

Ivan</description>
		<content:encoded><![CDATA[<p>Well when you get someone from a far away country that you are not too sure what continent is it on, paying with the credit card of a resident in the US, usually a very young one, subscribing to your CV database online,&#8230; as a manager of a job board, should act as a safe keeper of the users data, and should not think about the revenue that you can make quickly there.</p>
<p>Monster had it, Jobs.ie had it, and LoadzaJobs.ie was offline the whole day yesterday!!!</p>
<p>Just a bit too greedy&#8230;.</p>
<p>Ivan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glandore Systems Blog &#187; Blog Archive &#187; Resume theft? Tell Us Your Story.</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-25</link>
		<dc:creator>Glandore Systems Blog &#187; Blog Archive &#187; Resume theft? Tell Us Your Story.</dc:creator>
		<pubDate>Tue, 01 Apr 2008 14:09:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-25</guid>
		<description>[...] Contact      &#171; Jobs.ie Hacked - Anyone Else? [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Contact      &laquo; Jobs.ie Hacked - Anyone Else? [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-23</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Tue, 01 Apr 2008 11:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-23</guid>
		<description>I think it is also possible to move the upload directory to a non-web-accessible folder, that might be a better idea. 

But you are right, these people will go to any lengths to try and break into information rich databases. Having emails/phone numbers/backgrounds of people and addresses is a good start at the whole identity theft idea. 

I'm guessing that Jobs.ie did have some way of detecting the break in, maybe it was a counter for checking how many CVs were being downloaded. On Boards.ie someone mentions that up to 60k CVs could have been compromised.

paul</description>
		<content:encoded><![CDATA[<p>I think it is also possible to move the upload directory to a non-web-accessible folder, that might be a better idea. </p>
<p>But you are right, these people will go to any lengths to try and break into information rich databases. Having emails/phone numbers/backgrounds of people and addresses is a good start at the whole identity theft idea. </p>
<p>I&#8217;m guessing that Jobs.ie did have some way of detecting the break in, maybe it was a counter for checking how many CVs were being downloaded. On Boards.ie someone mentions that up to 60k CVs could have been compromised.</p>
<p>paul</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-21</link>
		<dc:creator>James</dc:creator>
		<pubDate>Tue, 01 Apr 2008 09:36:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-21</guid>
		<description>Paul, that's what I mean.  There are other ways of getting to the data than accessing an open directory, and the easiest way is the Monster way - by hijacking an employer's account.  By giving full search functionality to all employers, all it takes is for someone to break into an account (there are lots of ways - a brute force attack, social engineering, session hijacking, SQL injection, etc.) and they can use a bot to automatically download thousands of CVs in seconds.  

I don't know how many of the major job boards are protecting against this yet.  One mode of protection would be to limit the number of CVs that any one account could download in a minute to protect against scripts.  Breaches of this nature happen every day but are rarely disclosed, let alone making it to the newspaper.</description>
		<content:encoded><![CDATA[<p>Paul, that&#8217;s what I mean.  There are other ways of getting to the data than accessing an open directory, and the easiest way is the Monster way - by hijacking an employer&#8217;s account.  By giving full search functionality to all employers, all it takes is for someone to break into an account (there are lots of ways - a brute force attack, social engineering, session hijacking, SQL injection, etc.) and they can use a bot to automatically download thousands of CVs in seconds.  </p>
<p>I don&#8217;t know how many of the major job boards are protecting against this yet.  One mode of protection would be to limit the number of CVs that any one account could download in a minute to protect against scripts.  Breaches of this nature happen every day but are rarely disclosed, let alone making it to the newspaper.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-19</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Tue, 01 Apr 2008 07:50:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-19</guid>
		<description>James : Technically the CVs are uploaded, and then deleted. The upload folder is protected by .htaccess in case anyone looks at it at the right/wrong time and tries to download the CV.</description>
		<content:encoded><![CDATA[<p>James : Technically the CVs are uploaded, and then deleted. The upload folder is protected by .htaccess in case anyone looks at it at the right/wrong time and tries to download the CV.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-17</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 31 Mar 2008 23:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-17</guid>
		<description>Ivan - wow, that &lt;a href="http://www.jobsblog.ie/Jobs/developing-a-jobs-site-job-board/58" rel="nofollow"&gt;Irishgradjobs.ie security flaw&lt;/a&gt; looks very bad - all of the resumes open in a publicly accessible folder.  You are dead right in the post on your blog - there are so many job boards springing up over the past two years, far too many of them cut corners on the application development and pay little attention to security.  Even medium sized job boards often do not have software developers on staff who can identify and patch security flaws when they do happen.

Paul - you send the CVs direct to the employer, do you store a copy online?  If not, then you have saved yourself a lot of potential headache -  as they say, the only 100% secure database is the one that doesn't exist :)</description>
		<content:encoded><![CDATA[<p>Ivan - wow, that <a href="http://www.jobsblog.ie/Jobs/developing-a-jobs-site-job-board/58" rel="nofollow">Irishgradjobs.ie security flaw</a> looks very bad - all of the resumes open in a publicly accessible folder.  You are dead right in the post on your blog - there are so many job boards springing up over the past two years, far too many of them cut corners on the application development and pay little attention to security.  Even medium sized job boards often do not have software developers on staff who can identify and patch security flaws when they do happen.</p>
<p>Paul - you send the CVs direct to the employer, do you store a copy online?  If not, then you have saved yourself a lot of potential headache -  as they say, the only 100% secure database is the one that doesn&#8217;t exist <img src='http://www.glandoresystems.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan &#124; JobsBlog.ie</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-15</link>
		<dc:creator>Ivan &#124; JobsBlog.ie</dc:creator>
		<pubDate>Mon, 31 Mar 2008 20:17:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-15</guid>
		<description>And they aer not the first and teh only one...

Ivan &#124; www.JobsBlog.ie</description>
		<content:encoded><![CDATA[<p>And they aer not the first and teh only one&#8230;</p>
<p>Ivan | <a href="http://www.JobsBlog.ie" rel="nofollow">http://www.JobsBlog.ie</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-13</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Mon, 31 Mar 2008 20:16:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.glandoresystems.com/blog/2008/03/31/jobsie-hacked-anyone-else/#comment-13</guid>
		<description>James, I would be interested to hear what you do. Currently we run jobberbase on www.jobsinireland.org , which sends the CVs direct to the employers. It's a simple approach, but it works !
&lt;i&gt;paul&lt;/i&gt;</description>
		<content:encoded><![CDATA[<p>James, I would be interested to hear what you do. Currently we run jobberbase on <a href="http://www.jobsinireland.org" rel="nofollow">http://www.jobsinireland.org</a> , which sends the CVs direct to the employers. It&#8217;s a simple approach, but it works !<br />
<i>paul</i></p>
]]></content:encoded>
	</item>
</channel>
</rss>
