How to hack the FBI
By Davey Winder in Editorial
Posted in networks, Data Protection, Blog, Security on
It appears that a professional penetration tester with some 17 years experience in the job has managed to hack his way through from an unnamed civilian government agency network right into the heart of a not at all civilian FBI crime database in less than six hours from start to finish.
The report reveals how the security consultant at PatchAdvisor was able to uncover unpatched vulnerabilities within the government agency web server and network during a routine and otherwise harmless scan. This kick started a chain of events that began with grabbing logins being reused on a number of enterprise systems which then became open to inspection, and in turn revealed unsecured account details to provide the pen tester with Windows domain admin privileges. As anyone who has the slightest experience on either side of the hacking fence will recognise, this has become a classic case of an escalation-of-privileges exploit.
So it should come as no surprise that it led to the ability to access a police workstation on-site, nor that in turn this led to the pen tester being able to install monitoring software upon it to discover applications connecting to the FBI National Crime Information Center database. If he had so wished, and it seems he did not, then the next step would have been installing a keylogger to grab the logins required to access it.
I guess the moral of this tale comes down to the obvious and oft repeated mantra of no matter how solid the security further up the food chain (in this case that FBI database) if the small fish are allowed to swim freely around at the bottom of the tank then eventually some shark is going to come along and gobble up everything. Patch management coupled with sensible firewalling of that police network could surely have prevented what has become something of an embarrassing as well as potentially serious, in the face of the ongoing war on terror, security slip up.
Comment by Gary Gemmell - June 3, 2008 on 10:11 am
Even worse is publicising it - giving the terrorists even more grist for the mill.
I can see in this day and age why companies would rather not publicise their security failures.
For an agency like this there is no excuse mind you the UK government are doing quite well in this field too - only a couple of million national insurance numbers , names addresses etc have been compromised oh and not to mention the failure of the new NHS system - What a joke - My question is where do they get all these overpaid consultants and what do they actually do apart from sit all day pontificating.
We only seem to learn when there is a big disaster ala TKMaxx then shore up the defences much like the flooding in England!
Its not as if patch management or securing a firewall is a hard job either!
Comment by battery - June 13, 2008 on 7:34 am
[…] Read the rest of this great post here […]
Make a comment
Tag cloud
Archives
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- Cuil frozen out: market share drops to next to nothing
20 comments
- Windows XP: the invincible OS
- Gatecrashing the WiFi hotspot party
- The 24 year old software that is still going strong
- Home workers are sick
- Big Brother Apple
- Spear phishing Catch 22 for Salesforce.com
- Dumbest phisher in history revealed
- Is BT misleading consumers with Option 2 broadband?
- Why ecommerce fails
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Betting on Hubdub technology (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Slowly slowly catchee Government IT monkey (100%)
- Who needs another set of web standards? (100%)
- The 6.5 billion quid hello (100%)

