Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 12th, 2011, 08:20 GMT · By

U.S. Military Contractor Hacked and Email Addresses Exposed

SHARE:

Adjust text size:


Hackers break in Booz Allen Hamilton's computer network
Enlarge picture
Hackers affiliated with the Anonymous collective and its Antisec campaign have hacked into computer systems belonging to U.S. military contractor Booz Allen Hamilton and leaked sensitive data found inside.

The hackers described the attack in the description of a torrent posted on ThePirateBay which also contains a list of 90,000 email addresses belonging to military personnel together with crackable password hashes.

"We infiltrated a server on their network that basically had no security measures in place. We were able to run our own application, which turned out to be a shell and began plundering some booty," the hackers write.

In addition to the email addresses, the attackers also included an sql dump of the database and additional data found on other internal servers they were able to access.

Four gigabytes of source code were allegedly copied from the company's svn server and its contents were wiped clean afterwards. The code is not included in the torrent.

Booz Allen Hamilton declined to comment. "As part of @BoozAllen security policy, we generally do not comment on specific threats or actions taken against our systems," the company wrote on Twitter.

The hackers claim that the compromise provided them with the access keys for other government related targets which they plan to hit in the future.

The security breach and data leak raise serious concerns because of the nature of the information involved. First of all, it's not probably average soldiers who have accounts with Booz Allen Hamilton, but ranking officers, particularly those dealing with intelligence.

The fact that hashes were generated with the SHA1 algorithm and are not salted makes them susceptible to brute force cracking attempts, especially if the original passwords were not strong to begin with.

But even if the access codes don't get cracked or if they weren't used anywhere else except Booz Allen Hamilton, there is still the risk of targeted email attacks, like the ones reported by Google in June.

Update July 13, 2011: The leaked email address database was made searchable by Dazzlepod so that military personnel can easily determine if they were affected by the leak.

TELL US WHAT YOU THINK:

1,816 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Anonymous Hacks into FBI Contractor's Network

Yahoo and Hotmail Users also Targeted in Sophisticated Webmail Attacks

Military Personnel Info Stolen from Defense Industry News Website

Northrop Grumman Abruptly Suspends Remote Access to Its Network

L-3 Communications Also Targeted Following RSA Breach

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM