Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    Anonymous Breaches Booz Allen Hamilton to Reveal 90,000 Military Passwords

    Written by

    Fahmida Y. Rashid
    Published July 11, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The hacking collective Anonymous released documents it claims were stolen from government contractor Booz Allen Hamilton as part of its anti-government AntiSec campaign.

      The documents Anonymous released July 11 on The Pirate Bay contained personal and official email addresses and passwords of an estimated 90,000 United States military employees. Anonymous announced the massive data dump on its Twitter feed as part of “Military Meltdown Monday.”

      The approximately 190MB data torrent included log-in information of personnel from US CENTCOM, SOCOM, the Marine Corps, Air Force facilities, Department of Homeland Security, Department of State and other private-sector contractors. The passwords were unsalted SHA1 hashes stored as a text string, making them vulnerable to being cracked using brute-force methods, Alex Rothacker, director of security research for Application Security’s TeamSHATTER, told eWEEK.

      “It’s slightly better than MD5, but still considered easily crackable with the tools available today,” Rothacker said.

      The group also claimed to have uncovered “maps and keys for various other treasure chests buried on the islands of government agencies, federal contractors and shady whitehat companies.” Anonymous also stole 4GB of source code from its Subversion code repository and erased it from the servers.

      Despite working with the federal government on “defense and homeland security matters,” Booz Allen Hamilton was more like a “puny wooden barge” and not a “state-of-the-art battleship” when it came to network security, Anonymous said in its statement posted on Pirate Bay.

      The server it compromised “had no security measures in place,” allowing the attackers to run its own application on the box and dump the SQL database. During the four-hour-long intrusion, Anonymous gained access to other unspecified servers uncovering credentials.

      “As part of @BoozAllen security policy, we generally do not comment on specific threats or actions taken against our systems,” the consulting giant posted on Twitter.

      The group claimed to have targeted Booz Allen Hamilton partially for its participation in government surveillance and intelligence-gathering programs as well as for potential illegal activities.

      Anonymous linked Booz Allen Hamilton with HB Gary Federal, and claimed both companies were working on a project to “manipulate social media.” The hacker collective uncovered HB Gary Federal’s activities after breaching the company’s systems and stealing all its emails in February, when the company’s CEO claimed to have unmasked the group’s top members.

      The Booz Allen data release followed the data dump on July 8 from IRC Federal, a contractor that works with the Army, Navy, NASA, the Department of Justice and other government agencies. Anonymous found emails with information about various contracts, development schematics, internal proposals and various log-in credentials.

      Snippets were posted on text-sharing site Pastebin, and a complete 107MB torrent file was posted onto Pirate Bay. Anonymous said it obtained an administrator’s log-in credentials via a SQL injection attack on the Website to first gain a foothold in the network. It used other techniques to grab database information and emails. The attack was helped along by the fact that some administrators reused their passwords across various systems.

      “So we laid nuclear waste to their systems, owning their pathetic Windows box, dropping their databases and private emails, and defaced their professional-looking Website,” Anonymous wrote on Pastebin.

      Anonymous is doing exactly what many security experts have warned: By compromising one server, the attackers transform themselves from intruders to trusted insiders. Attackers often go after “softer, easier targets” to gain a foothold in the network, Josh Shaul, CTO of Application Security, told eWEEK. Once the attackers are inside the network, they can look for other user accounts to gain access to more critical and valuable systems, Shaul said.

      The group LulzSec launched the AntiSec campaign with Anonymous against private-sector firms and government agencies, with the stated purpose of exposing their alleged corruption. LulzSec disbanded in late June after 50 days of data-breach mayhem. But Anonymous has continued the attacks. It appears that some of the LulzSec members have just switched names and are continuing their activities under the Anonymous banner.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×