Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

[ Create a new account ]

Pentagon Hid Magnitude of Data Loss From Recent Breach

Posted by Soulskill on Saturday March 08, @12:18AM
from the it's-just-a-flash-wound dept.
blueton tips us to a brief story about recent revelations from the Pentagon which indicate that the attack on their computer network in June 2007 was more serious than they originally claimed. A DoD official recently remarked that the hackers were able to obtain an "amazing amount" of data. We previously discussed rumors that the Chinese People's Liberation Army was behind the attack. CNN has an article about Chinese hackers who claim to have successfully stolen information from the Pentagon. Quoting Ars Technica: "The intrusion was first detected during an IT restructuring that was underway at the time. By the time it was detected, malicious code had been in the system for at least two months, and was propagating via a known Windows exploit. The bug spread itself by e-mailing malicious payloads from one system on the network to another."

Related Stories

[+] Chinese Military Hacked Into Pentagon 405 comments
iFrated informs us of a successful penetration of US Defense Department computers by the Chinese military last June. From the article: "The Pentagon acknowledged shutting down part of a computer system serving the office of Robert Gates, defense secretary, but declined to say who it believed was behind the attack. Current and former officials have told the Financial Times an internal investigation has revealed that the incursion came from the [Chinese] People's Liberation Army. One senior US official said the Pentagon had pinpointed the exact origins of the attack. Another person familiar with the event said there was a 'very high level of confidence... trending towards total certainty' that the PLA was responsible." The PLA is also accused of breaking into German government computers, including a network in the office of the Chancellor.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.

Pentagon Hid Magnitude of Data Loss From Recent Breach 25 Comments More | Login | Reply /

 Full
 Abbreviated
 Hidden
More | Login | Reply
Keybindings Beta
Q W E
A S D
Loading ... Please wait.
  • Windows strikes again. (Score:5, Informative)

    by urcreepyneighbor (1171755) on Saturday March 08, @12:21AM (#22684634)

    was propagating via a known Windows exploit.
    DARPA may want to rethink funding [news.com] OpenBSD. :)

    The DoD doesn't need Windows, we need bunkers.
    • Re:Windows strikes again. (Score:4, Insightful)

      by NeverVotedBush (1041088) on Saturday March 08, @12:29AM (#22684670)
      It's to the point that you would think Microsoft itself would take an interest just for patriotic reasons.

      It's also apparently to the point that the US government ought to consider dropping Windows entirely.

      That, or maybe we should all just set our login names to Bejing and the password to China. Just let them have the run of anything we have of value.

      Running Windows just slows them down a little. A very little.
      • Re:Windows strikes again. (Score:5, Insightful)

        by liquidpele (663430) on Saturday March 08, @12:59AM (#22684856) Homepage Journal
        Now now, this isn't really Microsoft's fault. The Pentagon had un-patched windows machines all over the place, and didn't even notice when it was emailing itself around the building! Their network admins should be fired on the spot, that's ridiculous. This could have been avoided with 1) Intrusion Detection Software 2) Decent firewall alerting you to connections to chinese IP space, 3) network anomaly detection software, 4) patching your damn boxes!
        • Re:Windows strikes again. (Score:5, Interesting)

          by SethJohnson (112166) on Saturday March 08, @01:31AM (#22684976) Homepage Journal


          2) Decent firewall alerting you to connections to chinese IP space,

          Duhh.. these guys weren't amateurs. They wouldn't have been communicating directly with the compromised hosts. There'd be like three or more hops of compromised boxes between them and the Pentagon. Not to mention that the intrusion might have originally been thanks to a viral botnet where the controllers recognized some interesting IPs within their herd. Then used the command-control structure to issue specific commands to those boxes to further infiltrate the Pentagon. Probably was always outbound connections uploading data and grabbing new marching orders (encrypted in both cases).

          Seth
      • Re:Windows strikes again. (Score:5, Interesting)

        by Hemogoblin (982564) on Saturday March 08, @02:49AM (#22685186)
        Speaking as someone who has worked as an Immigration Officer with the Canada Border Services Agency, I can say that our immigration laws are quite fine, thank you. In addition, our antiterrorism laws are quite robust, and I would argue that the United States' laws are needlessly draconian. Thank you for your time.
  • Hmm... (Score:4, Funny)

    by calebt3 (1098475) on Saturday March 08, @12:23AM (#22684650) Homepage
    So they snuck in through broken Windows?
  • by unassimilatible (225662) on Saturday March 08, @12:29AM (#22684674) Journal
    I guess the standard and proper response to espionage would be to publicly confirm the value of the intelligence to the Chinese?

    What is it with you people? Is there no such thing as a state secret anymore? Should the Pentagon just list all its secrets on its Web site and get it over with? Let's just post all the targeting information, launch codes, encryption keys, advanced weapons and defense systems. etc. Let's just post it all on .mil in the interest of openness.

    Not everything is a scandal folks! Nothing to see here, move along.

  • Not stolen! (Score:5, Funny)

    by Subm (79417) on Saturday March 08, @12:30AM (#22684680)
    This is Slashdot. The data wasn't stolen. It was copyright infringed.

    When will everyone learn the difference?

    The solution is obvious: sic the Mafiaa on the attackers.
  • by NeverVotedBush (1041088) on Saturday March 08, @12:35AM (#22684712)
    OK, all you government workers - especially those in the military, CIA, or NSA that are running Windows on open networks.

    Compose a few Microsoft Word documents about a planned nuclear attack on Beijing on the opening day of their olympics. Make it sound nice and juicy, say a few things about ICBMs, nuclear submarines just off their coastline. Mention the proposed megatons and expected damage. Talk about a free Taiwan

    Let them chew on that.
  • Poem (Score:5, Funny)

    by Anonymous Coward on Saturday March 08, @12:41AM (#22684754)
    Me Chinese,
    Exploit SOCKS
    Me Put Malware
    On Your Box

    Me Chinese,
    Go To Town,
    Me Pull Fast,
    Your Data Down

    Me Chinese,
    Make Cheap Shoe
    Take You Secrets
    Laugh At You

    Me Chinese
    Let You Think
    Here You Go
    Bring You Drink

    Me Chinese,
    Me Play Joke
    Me Put Pee-Pee
    In Your Coke
  • by AHuxley (892839) on Saturday March 08, @12:48AM (#22684794)
    Gary McKinnon is accused of cracking into 97 United States military and NASA computers in 2001 and 2002.
    He talked of blank MS passwords and using a tiny Perl script.
    So maybe you do not crack or hack MS Pentagon computers but just surf on in.

    http://news.bbc.co.uk/2/hi/programmes/click_online/4977134.stm [bbc.co.uk]

    You know, one time we had a box DoS, for 12 hours. When it was all over, I walked up. We didn't find one of 'em, not one stinkin' Asian ip.
    The smell, you know that Microsoft smell, the whole box. Smelled like... owned.
  • It's not the Chinese People's Liberation Army. It's the People's Liberation Army of China. The Chinese People's Liberation Army is a bunch of wankers.
  • simple question... (Score:4, Insightful)

    by skydude_20 (307538) on Saturday March 08, @01:03AM (#22684866) Journal
    why the hell is any DoD network connected to the Internet????
  • M$CROSOFT SUCKS (Score:5, Insightful)

    by EdIII (1114411) * on Saturday March 08, @01:08AM (#22684880)
    Here's the thing.... even putting the hyperbole in the title aside, Microsoft really does suck , and at so many many many levels.

    I am in my 30's and I have been using Microsoft all my life, since I was about 9 years old (I started using computers when I was 7). I build their machines, I repair them, I even program them too. I also attempt to provide security on them as well. So I have been involved with Microsoft about as long as some people have been married. So I believe that I am entitled to get drunk occasionally and rant about the "Ex" for awhile. I earned it, so to speak.

    Have people noticed that Microsoft is like a little sickly Boy in the Bubble? You have to protect him at all times.

    You have to put up a router and a firewall at a minimum to protect your little herd of MS machines. Keep them safe from the big bad wolves and all that. Of course, these days you also need to have some really good routers with IDS, gateway anti-virus, etc. to do it even better. But that is not enough. Those little guys can get into trouble just "looking" out on the Internet. So you need anti-virus, anti-phishing, anti-spam, anti-spyware, anti-malware, etc.

    When the Internet first started coming out, I remember telling people it would be cold day in hell before I hook my computer up to an unknown network in which anybody could send packets to my machines. Obviously, I had to get over that "shyness" and learn to adapt or die. However, since then, I have had to invest enormous amounts of time and energy and cold hard cash into preventative measures to keep my own Microsoft OS's from being hijacked by any asshat on the Internet.

    There is billions being made, that's with a B folks, in 3rd party solution providers that specialize in providing the security solutions just to cover the fact that Microsoft can't code security if their "life depended on it".

    Now that the Pentagon is using them, it would seem that in a roundabout way, Microsoft's life IS depending on it.

    We can bash Microsoft all we want, and talk and talk and talk about it. What it really comes down to though, is that Microsoft just may not be a secure enough environment for our National Security apparatuses to be using. If we have to work that hard at it, with that many vendors, and have that many points in which someone can screw up and leave machines vulnerable, then we need another solution .

    On another side note, where the HELL are those super secured networks I keep hearing about that my tax dollars paid for huh? Apparently, the Pentagon's networks must be in really bad shape too. You would think that trillions of dollars could provide some pretty secure networks, communication infrastructures, and operating systems.

    All that "bashing" on my part aside, Microsoft may make a decent OS for the little guy. The mom and pops at home with their families. Let's face it, it is easier to use then Linux, otherwise Linux would have a greater market share. Let's just not use it inside the Pentagon OK?
  • It reminds me of the Doonesbury comic years ago about Reagan's SDI shield, that was going to protect us from Soviet missiles by a single, always-perfect shield of protective devices. The comic was drawn in crayon, as I recall, with the voice of a little girl explaining that the world was beautiful because SDI was protecting us. Then in the last frame it said something abrupt to the effect of "Oops, one got through. Bye."

    What makes this story so scary isn't just that something got broken into, it's the thing in the back of all our minds that says "my goodness, is that the place where All Knowledge of Everything is centrally stored?" Bad enough when someone breaks into your computer and gets all your bank accounts or passwords, but when someone breaks into The Government and gets all knowledge of launch codes, defensive systems, registries of guns in the US, files on who sympathizes with who, files on who calls who, etc. ... well, that info collected with the intent of defending us might suddenly be a liability.

    That's why things like the telecom phone tapping, national IDs, etc. are so troublesome. The mere centralization of information at all for any reason is a risk that the Bush administration has been ignoring, working instead (for all we know, none of this being auditable) to pile all of everything in one fragile place. The founding fathers kept trying to decentralize things and minimize what in modern computer terms we'd call "single point of failure". They distributed power in a way that made it hard to just break in and take control, right down to making sure there was not a single head of government. It's too bad that in all the puffery we hear spouted about Constitutional original intent, the modern Republican leaders don't show more care about that kind of original intent.

    • by r00t (33219) on Saturday March 08, @12:41AM (#22684752) Journal
      Sysadmins must apply patches IF AND ONLY IF they are army approved.

      Sounds decent so far, hmmm?

      The army has some committee that regularly decides which patches to approve.

      Still not too bad, hmmm?

      The committee approves patches for things that are being actively exploited.

      Ponder that one for a moment. It means that every security hole will be exploitable on the army networks. Every security hole gets a chance, since "not exploited yet" means "not a problem".

    • Re:$TRILLIONS for Insecurity (Score:5, Informative)

      by Adambomb (118938) on Saturday March 08, @12:56AM (#22684842) Journal
      While i agree with your overall point, those are relatively poor metrics to base it on.

      The vietnam war cost 600B$USD considering 1968 USD.

      If you consider inflation based on the first inflation calculator google link that I clicked [westegg.com], plugging in 600B$ from 1968 yields:

      What cost $600000000000 in 1968 would cost $3688102617038.20 in 2007.

      thats 3.68 trillion in north american terms no?
    • Re:What known exploit was used? (Score:5, Insightful)

      by causality (777677) on Saturday March 08, @01:23AM (#22684946)

      The 'open source attitude' is supposed to be about choice and sharing, not about elitism.

      Choice alone isn't very useful unless you make an effort to make good choices.

      ............

      Sure, the default settings on Linux are more secure than on Windows. Linux is also not designed with the common man in mind. You shouldn't be surprised, especially IT guys, with how much of the problems with Windows are because of the marketing department rather than the actual coders.

      To the attacker trying to break into your systems, it really doesn't matter whether the security weaknesses were caused by marketing, the coders, or whatever, so I am not sure what your point is. What I can say is that what it looks like is a weak apology for Microsoft's poor security history. At any rate, as you indicated, marketing departments do not security make. You just gave a good reason why Windows would be a poor choice in a context where, presumably, security really matters. Therefore, the two are not on equal ground in this case. It is certainly not "elitist" to say that Linux would have been a superior choice (though probably OpenBSD would have been better still). Especially not when professional IT staff are not the "common man".

      Even if the client machines must use Windows, the servers hosting the sensitive data certainly do not need to use it. The wrong tool was used for the job; there is nothing "elitist" about it.