Hard Light Productions Forums

Off-Topic Discussion => General Discussion => Topic started by: Kosh on February 18, 2007, 03:51:29 am

Title: DoD networks getting pwn3d
Post by: Kosh on February 18, 2007, 03:51:29 am
http://politics.slashdot.org/politics/07/02/17/1936236.shtml


Anyone remember a couple of years ago about that British guy who hacked it looking for UFO's? I remember listening to his interview on the BBC and according to him the security setup was amatuerish. They used un0updated versions Windows on their servers, and on top of that they couldn't even be bothered to put passwords in the built in Administrator accounts. He said he was able to hack it easily with a couple of applications that were freely available on the internet.

He also said there were many other people poking around in there from many countries including Pakistan, China, Turkey, and a few others. These guys seriously need to get their acts together when it comes to network security.....
Title: Re: DoD networks getting pwn3d
Post by: Flipside on February 18, 2007, 12:54:51 pm
Please don't tell me they keep deployment details on a Microsoft Access DB or something....
Title: Re: DoD networks getting pwn3d
Post by: jr2 on February 18, 2007, 01:46:47 pm
... What about that guy from Russia in the late '90s IIRC that was hacking into the Treasury with a 386?  That one true?
Title: Re: DoD networks getting pwn3d
Post by: NGTM-1R on February 18, 2007, 04:02:30 pm
These guys seriously need to get their acts together when it comes to network security.....

You underestimate them. They understand that the only true security is having no outside connections. Anything else isn't worth bothering with. That's why MILNET exists.
Title: Re: DoD networks getting pwn3d
Post by: Unknown Target on February 18, 2007, 09:25:46 pm
ngtm1r's right. All the super-sensitive stuff probably isn't even connected to each other. I wouldn't be surprised if some of it was so isolated that each machine would only be connected to one other machine, and that's it.
Although it is disconcerting that they let so much stuff hang out in the open.
Title: Re: DoD networks getting pwn3d
Post by: Herra Tohtori on February 18, 2007, 09:47:33 pm
"No networked computers aboard this ship." :nod:

Works for sure... and keeps productivity better. ;7
Title: Re: DoD networks getting pwn3d
Post by: Mars on February 18, 2007, 10:33:01 pm
Although it is disconcerting that they let so much stuff hang out in the open.

My thinking is that it might even be a ploy
Title: Re: DoD networks getting pwn3d
Post by: jr2 on February 19, 2007, 01:24:49 am
Although it is disconcerting that they let so much stuff hang out in the open.

My thinking is that it might even be a ploy
I was wondering the same thing.  Prolly looking to catch some really good hackers, then they'll blackmail them into service... ;)
Title: Re: DoD networks getting pwn3d
Post by: Herra Tohtori on February 19, 2007, 01:32:37 am
Heh, in any case it can't be considered reliable by the hacky cracky people. Must be frustrating. It could be the real deal, but then again it could just as easily not be. So back to square one.

AS we all know, things are best hidden in public, broad daylight.


...in any case, having un-updated windows systems in use is ridiculous unless they use them as decoy. But then again, it could just be that the DoD of US just is that inane. Or they want us to think that they are inane, and they use it as a decoy. Or, it isn't a decoy but they want us to think it's a decoy, or...:snipe:
 :lol:
Title: Re: DoD networks getting pwn3d
Post by: Kosh on February 19, 2007, 01:39:18 am
The DoD does seem to use windows for at least some things:

http://seclists.org/politech/2000/Aug/0027.html
Title: Re: DoD networks getting pwn3d
Post by: aldo_14 on February 19, 2007, 03:05:26 am
The network might be designed by the smartestest engineers on the planet, but it doesn't stop the users being ****wits....