[ISN] European Space Agency hacked, sensitive data released publicly

From: InfoSec News <alerts_at_private>
Date: Tue, 19 Apr 2011 01:08:49 -0500 (CDT)
http://thenextweb.com/eu/2011/04/18/european-space-agency-hacked-sensitive-data-released-publicly/

By Matt Brian
The Next Web
April 18, 2011

It is reported that yesterday the European Space Agency (ESA) website 
was compromised by a hacker, opening up sensitive project logs and 
exposing hundreds of email addresses and passwords associated with some 
of Europe’s top science institutes.

The hacker, known by the alias TinKode, posted a full disclosure of the 
attack on his website, highlighting FTP accounts, database users, hashed 
passwords as well as SHA1-hashed server root password. Perhaps a little 
more worrying for the ESA was that fact the attacker was also able to 
access some of the agency’s space projects including satellite 
activities, calibration sources and environmental details.

Despite showcasing the data stolen in the attack, the hacker did not 
disclose how the ESA website was compromised.

Administrator and editor credentials were discovered to be in plain 
text, as were user email addresses and passwords, which look to consist 
of serveral CERN science institute employees, staff at defence 
corporation BAE Systems and many other contractors and companies linked 
to the agency.

[...]


___________________________________________________________      
Tegatai Managed Colocation: Four Provider Blended
Tier-1 Bandwidth, Fortinet Universal Threat Management,
Natural Disaster Avoidance, Always-On Power Delivery 
Network, Cisco Switches, SAS 70 Type II Datacenter. 
Find peace of mind, Defend your Critical Infrastructure.
http://www.tegataiphoenix.com/
Received on Mon Apr 18 2011 - 23:08:49 PDT

This archive was generated by hypermail 2.2.0 : Mon Apr 18 2011 - 23:18:58 PDT