Another Defense Contractor Hacked in AntiSec Hacktivism Spree
A torrent just popped up on the Pirate Bay a few hours ago that leaks 90,000 emails and unsalted MD5 hashes as well as other reportedly damanging information about Booz Allen Hamilton, a contractor to the US government. Several news sites already have the story, or at least what we know of it. The hashes themselves are relatively easy to crack using commodity cracking tools, but likely that isn't the real damage here. Anonymous has claimed credit for the hack.
At this point, the means by which BAH was breached is unknown and likely pure speculation. That said, it is no longer secure to hash your passwords with MD5, much less when it is unsalted. Take a look at using a SHA-2 variant, if possible. Also, require strong and long passwords while minimizing password re-use to avoid compromised credentials being used to dig deeper into an organization. As more facts are known, this port will be updated.
--
John Bambenek
bambenek at gmail /dot/ com
Bambenek Consulting
Comments
were there any forensics measures taken?
pcap
Jul 12th 2011
1 decade ago
No Love.
Jul 12th 2011
1 decade ago
JimS
Jul 12th 2011
1 decade ago
I suspect that companies like this are ripping off the US taxpayer for millions/billions of dollars annually.
farploop
Jul 12th 2011
1 decade ago
Ms. Callahan was also a former CIO at the Department of Labor, and was also involved in the White House e-mail subpoena scandal known as Project-X.
farploop
Jul 12th 2011
1 decade ago
nativevlan
Jul 12th 2011
1 decade ago
farploop
Jul 12th 2011
1 decade ago
wildman
Jul 12th 2011
1 decade ago
Charles
Jul 12th 2011
1 decade ago
That's exactly the thinking that causes the problem.
The issue is not that they were hacked.
Steven
Jul 12th 2011
1 decade ago