Hacker compromised Royal Navy security
Tuesday 09 November 2010
Related articles
Computer details of current and former defence staff, including a former Royal Navy head, were posted on the internet after a hacker broke into a military website and shut it down.
The Royal Navy website was taken offline after being "compromised" by the hacker, codenamed TinKode, who has a history of breaching government databases including Nasa, the US Space Agency and the Pentagon.
The Ministry of Defence stressed yesterday that no "malicious damage" had been inflicted on the Royal Navy site, which did not contain any classified information. However, the site has been down for three days and TinKode, who is Romanian, posted so-called "hash values" for Ministry passwords he claimed to have obtained from his illegal entry. With hash values, hackers can crack passwords a lot more easily. One of the named accounts was for former First Sea Lord Admiral Sir Jonathon Band.
In the wake of the disclosure, other hackers piled in with additional material including five passwords for other members of staff. The MoD insisted that the information posted would not allow anyone access to secrets.
The electronic break-in took place on Friday night. Visitors to the website yesterday morning were greeted with the message "Unfortunately the Royal Navy website is currently undergoing essential maintenance. Please visit again shortly." A message posted by TinKode on the social networking site Twitter read: "Minister (sic) of Defence United Kingdom – HACKED". According to members of the hacking community, TinKode used to be a member of Hackers Blog, a collective of cyber activists who ran a campaign of breaking into websites to highlight security flaws.
Members of the group were known as "white hats" who did not harm the websites. But TinKode is said to have since become a "grey hat" – someone who deliberately publishes sensitive information online.
TinKode is believed to have used a "SQL injection attack" to target the Navy website, a common method which exploits vulnerabilities in databases used by websites. Once entry has been gained, the hacker can look at and download sensitive data as well as upload malicious software.
Rik Ferguson, a cyber security analyst at the company Trend Micro, said: "It's always embarrassing when something public is successfully hacked and should serve as a warning to anyone who has a presence online to take all the necessary steps to secure their websites." The MoD said: "There has been no malicious damage, but as a precaution the website has been temporarily suspended. Security teams are investigating."
Officials said the site had the level of security needed to prevent "things like silly pictures being put in". TinKode's actions, said one official, added nothing to the debate on cyber security.
-
Stand by for another DECADE of wet summers, say Met Office meteorologists
-
'Jail reckless bankers': Report urges the Government to introduce new criminal offence for reckless management
-
Feat of engineering: Incredible photographs show construction beneath New York's Second Avenue
-
World news in pictures
-
Google challenges US surveillance gagging order
- 1 Disability campaigners celebrate 'victory' after government rethink over plans to make it more difficult to claim disability benefits
- 2 'Jail reckless bankers': Report urges the Government to introduce new criminal offence for reckless management
- 3 Breaking the Silence: In the reality of occupation, there are no Palestinian civilians – only potential terrorists
- 4 We never knew Nigella Lawson - and we still don’t
- 5 Vice pulls 'breathtakingly tasteless' fashion shoot glorifying the suicides of famous female authors from Sylvia Plath to Virginia Woolf
Get your summer started with British Military Fitness
BMF is the UK’s biggest and best loved outdoor fitness classes
How will you make today delicious?
Tell us how you plan to make today delicious and you could win a £50 M&S gift card.
Learn a new language
Add another string to your bow with Rosetta Stone, whether it's Spanish, Italian or Mandarin...
Win a Nook® Simple Touch eReader
Find out how Nook® is supporting the Evening Standard's Get Reading campaign - and your chance to win one.
Free reading festival for families
Follow The Standard's campaign to get London's children reading - and experience this unique event at Trafalgar Square on 13 July.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
Independent Dating
iJobs General
Lighting Design Engineer
£33000 - £35000 Per Annum: The Green Recruitment Company: The Green Recruitmen...
Are you a Primary School Teacher in the Clacton area?
£110 - £135 per day: Randstad Education Chelmsford: Teaching opportunites in t...
September teaching roles - Primary
£21000 - £32000 per annum: Randstad Education Chelmsford: Primary Teaching opp...
Primary Teaching vacancies, starting in September - Southend
£21000 - £32000 per annum: Randstad Education Chelmsford: Primary School teach...
Day In a Page
First night: The Cripple of Inishmaan
Scandi-geeks descend on Nordicana for fan-convention
Female aristocrats battle to inherit the title







Comments