Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Two NASA sites recently were hacked by an individual wanting to demonstrate that the sites are susceptible to SQL injection.The websites for NASA's Instrument Systems and Technology Division and Software Engineering Division were accessed by a researcher, who posted screen shots taken during the hack to his blog.The researcher, using the alias "c0de.breaker," used SQL injection to hijack the sites, according to Gunter Ollmann, VP of research at security firm Damballa. SQL injection is an attack process where a hacker adds additional SQL code commands to a page request and the web server, and then tries to execute those commands within the backend database, Ollman said. Vulnerable web applications process the extra SQL commands, which then cause the web application to leak additional information, such as user credentials, which can be used to log into the targeted application.The NASA hack yielded the credentials of some 25 administrator accounts, Ollman said. The researcher also gained access to a web portal used for managing and editing those websites. “The researcher had the ability to add and change any content or administrators for the website,” Ollmann said. A NASA spokesperson did not respond to an SCMagazineUS.com request for comment, but a NASA security analyst who contacted Ollman said the issues have been addressed and the sites are no longer vulnerable. Cybercriminals are constantly looking for sites that are susceptible to SQL injection, which is a recurring problem, as new content is developed and sites are updated, Ollman said. “SQL injection is a common technique that's well understood and provides a bountiful target because you are literally going after databases, which is frequently where large stores of information exist,“ said Amit Yoran, chairman and CEO of networking security monitoring firm NetWitness.In this particular case, the researcher found the vulnerabilities, made NASA aware of them, then published findings after the websites had been fixed, Ollman said. An attacker, however, could have tried to use that web server as an entry point into other systems NASA might control, or edit the content of the sites and use them for drive-by downloads.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.