BADC Webserver compromised - temporary holding page

Latest news 1620, Tuesday 13th September 2011

The BADC's main webserver became compromised during the weekend following an attack from an external source where an intruder was able to gain access to the server. As a consequence we have removed this server from operation while it is returned to a secure state and investigations to the extent of the hack are carried out.

The BADC website and those services reliant on the web-server in question will be unavailable while these corrective measures are put into place.

At present it is unclear to the extent of the intrusion over the weekend and our staff are already examining logs to ascertain if any personal login details were recovered from our systems. As a precautionary step, regardless of the encrypted nature of our password storage, we will reset all user passwords and issue emails with replacement passwords as soon as possible.

We apologise for the inconvenience this event has caused and we hope to return full service as soon as possible.

New news items will be posted on this page as the situation develops. Any other additional significant information will also be emailed to all users on the BADC/NEODC email list hosted by JISC mail and the BADC RSS feed (once this has been reinstated).

In the meanwhile, should you have any questions or require assistance please feel free to contact the BADC helpdesk on badc@rl.ac.uk or 01235 446432.

Regards,

BADC/NEODC team