Slashdot Mirror


Mapping The CIA Nonclassified Network

jeffy124 writes "A security firm Matta Security in London has mapped the CIA non-classified network. Using only legal and open sources, the company mapped topology of machines and even found networks otherwise closed to the public. The company never port scanned or probed the network directly. Among items they found were emails and phone numbers of sys admins and other employees. Amazingly, they did all this in two days."

38 of 242 comments (clear)

  1. Portscanning? by LWolenczak · · Score: 5, Insightful

    Last I checked, Portscanning was legal?

    1. Re:Portscanning? by Monkelectric · · Score: 5, Interesting
      Im a sysadmin for a major university, and I can tell you first hand that even pinging will get you a letter from the agency you pinged.

      One of my users decided to ping a DOD (department of defense) computer ... he pinged it, and a few days later we got an email from them asking us A: if we have been compromised B: if we hadn't please dont do it again. The letter was very courtious, and explained they understand that pinging in itself is not illegal or not even unusual, the real point was to inform us that we may have been compromised (prolly a good idea). A buddy of mine who works for the air force claims if you ping an air-force server, armed FBI agents will appear at your door quickly ... Obviously I am unwilling to test this :)

      --

      Religion is a gateway psychosis. -- Dave Foley

    2. Re:Portscanning? by Baca · · Score: 4, Funny

      Question is if you ping them and they show up, do they respond with "pong?"

      --
      "The once beautiful rose blackens slowly..."
    3. Re:Portscanning? by brer_rabbit · · Score: 5, Funny

      what's the worse that could happen?

      % ping hidden.airforce.mil
      PING hidden.airforce.mil from 192.168.1.4 : 56(84) bytes of data.
      64 bytes from hidden.airforce.mil: icmp_seq=0 ttl=57 time=20.871 msec fbi_agents_in=10
      64 bytes from hidden.airforce.mil: icmp_seq=1 ttl=57 time=19.560 msec fbi_agents_in=9
      64 bytes from hidden.airforce.mil: icmp_seq=2 ttl=57 time=20.497 msec fbi_agents_in=8
      64 bytes from hidden.airforce.mil: icmp_seq=3 ttl=57 time=20.820 msec fbi_agents_in=7
      64 bytes from hidden.airforce.mil: icmp_seq=4 ttl=57 time=19.732 msec fbi_agents_in=6
      64 bytes from hidden.airforce.mil: icmp_seq=5 ttl=57 time=20.805 msec fbi_agents_in=5
      64 bytes from hidden.airforce.mil: icmp_seq=6 ttl=57 time=19.830 msec fbi_agents_in=4
      64 bytes from hidden.airforce.mil: icmp_seq=7 ttl=57 time=20.770 msec fbi_agents_in=3
      64 bytes from hidden.airforce.mil: icmp_seq=8 ttl=57 time=19.781 msec fbi_agents_in=2
      64 bytes from hidden.airforce.mil: icmp_seq=9 ttl=57 time=20.790 msec fbi_agents_in=1

      --- hidden.airforce.mil ping statistics ---
      10 packets transmitted, 10 packets received, 0% packet loss, 100% user loss
      round-trip min/avg/max/mdev = 19.560/20.345/20.871/0.541 ms

    4. Re:Portscanning? by AnalogBoy · · Score: 4, Funny

      Pentagon (AP)

      A massive, national mobilization of FBI agents was reported today by sources speaking on condition of anonymity. While officially the situation is classified, the source said there was a massive DOS attack of every major government site.

      "We don't believe this to be the work of ametures." said the source, "The attack was highly organized - thousands of users, from all over the globe, using a special form of denial of service attack called the 'Slashdot Effect'."

      The government has been keeping an eye on the hacker portal "Slashdot", at http://slashdot.org/, for quite some time, stating that it is always the best place to find out what the next big illegal thing is, whether it be irritating the MPAA, RIAA, or disrupting critical government networks.

      President Bush is quoted as saying something inconsequental, ignorant, and stupid, as usual.

    5. Re:Portscanning? by SpinyNorman · · Score: 4, Informative

      Maybe ... legal until you're accused of hacking into the syetem you portscanned, then it'll be used against you as evidence of hacker intent.

      This has already been done.

    6. Re:Portscanning? by technos · · Score: 4, Interesting

      Apparantly they've become more paranoid.. I remember portscanning .mil subnets as recently as 97-98, though that was from a badly implemented net sampling tool and not through malice. (Line read scan(n_ipb,n_ipc,n_ipa,n_ipd), should have been alphabetic order) For years and years, I used to set the system clock on my CMOS-battery impaired DOS box from the clock on a Air Force server I found manually trolling hosts. Didn't respond to ping, but telnet got me the time..

      Don't recall ever hearing from anyone about it. I even tried to send an explaination of the port-scan, but the published email I had bounced.

      --
      .sig: Now legally binding!
    7. Re:Portscanning? by CodeMonky · · Score: 4, Insightful

      You are welcome to be completely ignorant of other countries laws if you plan on never leaving the us. However if you are gonna ever travel abroad you may wish to keep track of what is and isn't legal elsewhere when it comes to computers. It would be a shame for you to portscan a computer while on a trip to china and be put to death.

      --
      --"Karma is justice without the satisfaction"
    8. Re:Portscanning? by Darth_Burrito · · Score: 3, Funny

      whew, I'm just glad the ttl isn't counting down as well.

    9. Re:Portscanning? by mallie_mcg · · Score: 4, Funny

      64 bytes from hidden.airforce.mil: icmp_seq=5 ttl=57 time=20.805 msec fbi_agents_in=5

      I think you have the wrong domain name. (Well i know www is not hidden., but ill look into it for you!! :p~

      PING www.af.mil (131.84.1.31) from 192.168.83.206 : 56(84) bytes of data.
      From h1-0.dtic.bbnplanet.net (4.1.1.254): Packet filtered
      From h1-0.dtic.bbnplanet.net (4.1.1.254): Packet filtered
      From h1-0.dtic.bbnplanet.net (4.1.1.254): Packet filtered
      From h1-0.dtic.bbnplanet.net (4.1.1.254): Packet filtered

      Yes actuall results. I wonder when i will get the email. (Yes i am an Admin on the domain, yes i am bored), or failing that visits from people in really bad suits. (Im lonely too, it will be nice to have someone to talk to!!) --- www.af.mil ping statistics --- 27 packets transmitted, 0 packets received, +4 errors, 100% packet loss

      --


      Do the following really mean anything? SCSA MCP CCSA CCNA
      --I'm not actually after an answer!
    10. Re:Portscanning? by cloudmaster · · Score: 3, Interesting

      I ran a quick "nmap -O" on a few air force servers just a few weeks ago, because they were mirrorring one of our web sites very aggressively (many requests per second) and I wanted to get some information on exactly what the machine was that was pulling stuff down that hard. I've yet to be visited by anyone, in person or via email.

      Then, the site being mirrored was one that we'd developed for the air force, so I assume that they must've figured it was ok or maybe realized that it's bad form to monopolize most of our T1 for several minutes at a time and not felt like pushing the issue... :)

      I'm pretty sure that individual bases or however they're grouped each are alowed some leeway in their security implemntations, so they probably don't all track connection information down to each individual ping...

    11. Re:Portscanning? by Cally · · Score: 3, Interesting

      > Im a sysadmin for a major university, and I can
      >tell you first hand that even pinging will get you a
      >letter from the agency you pinged.

      I can assure you that this is NOT the case for us outside the US. I've been known to use www.af.mil as a test of connectivity / UDP / ICMP, and I've not seen a letter, an email or indeed any MIB.

      --
      "None are more hopelessly enslaved than those who falsely believe they are free." -- Goethe
    12. Re:Portscanning? by gfreeman · · Score: 3, Funny

      [Russian/Connery accent] Vasily, verify number of hops to our target - one ping only ...

      --
      Graham

      --
      Ceci n'est pas un sig.
  2. Web Logs by CokeBear · · Score: 4, Funny
    Checking all my logs now for any access from 198.81.x.x

    Always nice to know if the spooks are checking up on me. (Not that I would give them any reason to)

    --
    Reality has a liberal bias
  3. So what? by oni · · Score: 4, Funny

    It don't claim to have found any private or restricted information. Everything they found was specifically put on the web to be found.

    Simply knowing the names and e-mail addresses that Matta turned up would be enough for some social engineers to get the rest of the information necessary to mount an attack

    Sorry, I don't buy that. "Hi, this is chuck, the webmaster. Can I have the names of our russian agents please?"

    Post the article again when someone breaks in or actually finds classified info.

    1. Re:So what? by kafka93 · · Score: 5, Insightful

      Social engineering is probably *the most* dangerous form of attack, as well as the most often overlooked from a defensive standpoint. Although the webmaster may not directly have details of russian agents, to use your example, he may have access to information that might compromise the security of the entire system. From my admittedly limited experience, the military and other "important" organisations are often little better prepared for attacks than the average web startup: even where great care and attention has been given to firewalls and the like, there will still exist employees who will disclose information, and there is still always the capacity for human error.

      Besides, addressing this kind of issue "when someone breaks in" is too late. And it's important that the civilian be aware of and take an interest in problems in its government, police force, legal system, etc.

    2. Re:So what? by dvdeug · · Score: 3, Interesting

      Of all organisations that might be vulnerable to social engineering, I am least worried about the military.

      A small team of men managed to literally roll an airplane out the back gate of an Air Force base, primarily using social engineering tactics. This team, hired by the military, found that military security wasn't all that it was cracked up to be.

      if people only hire intelligent software engineers, no one will be able to social engineer anything.

      How does *that* follow? Many social engineering attacks get the user to hand over username and password, and if you can't check IP (think mobile users) then you've just lost. At best you can contain it to that user's files, but that still may be a severe security leak.

    3. Re:So what? by monkeydo · · Score: 5, Insightful

      First, anyone who answers the phone at the CIA is trained not to tell you anything. For that matter, they don't know anything. Everything os compartmentalized, computer systems, intelegence, even people. Social engineering on the scale you mention usually doesn't happen in the wild. Social engineer as a hacker technique is popular because of the low risk exposure. If you are a team hired by the AF to try and steal a plane you have zero risk no matter what you try, so you'll do some things no one would do in real life.

      Second, do you really think the CIA uses username/password authentication for *anything*? Think smartcards, one time key generators, palm scanners, etc. I guarantee there isn't a single secure system you can get into without at least a token and a passphrase. The most secure systems require multiple authentications. Hello, we're are talking about the largest *inteligence* agency in world.

      --
      Si vis pacem, para bellum
      The only thing more annoying than a Libertarian is an (un|mis)informed Libertarian
    4. Re:So what? by oni · · Score: 3, Informative

      terrorist group targets Chuck and his SysAdmin pals before launching some kind of attack.

      I should have made this clear in my last post, and this is based on my experience in the military: The web-page flozies typically work in the public affairs departments. They could be abducted by aliens and no one would care much. The real IT people have nothing to do with "administering" web sites.

      Maybe the CIA does things differently - but I doubt it.

  4. Not that impressive by fiber_halo · · Score: 5, Insightful

    I wouldn't say that they mapped the CIA's network. Sure, they found some machine names that route mail. Big deal. I'll bet more that half of the slashdotters here could have gotten the same (or more) information. I don't see how knowing what machines route mail pose any security threat. Anyone outside the network could just look at their mail headers and see what internal machines were used to forward the mail.

    If someone can get classified information from CIA via social engineering, I'd say someone needs to be retrained. These guys should be on the lookout for that at all times.

    1. Re:Not that impressive by Happy+go+Lucky · · Score: 5, Insightful
      Social engineering is by far the most cost-effective way to run an intelligence agency. I'll let you spend billions on fancy software and hardware. I'll spend a grand on a hooker to wink at one of your sysadmins - and I've got all the access I want.

      A few years ago, Archer-Daniels Midland actually did try to hire a few hookers to get some market information from a competitor. The plan got scrapped when nobody could keep a straight face at the thought of some lady of the evening moaning "f--- me! F--- me! Harder! What's your method for removing impurities from lysine? Oh, god, harder!"

      But I agree with paiute. It's people who have information, and getting information means getting it from people. Sending them hookers who then blackmail them is one option-a US Marine assigned to our embassy in Moscow fell for that back in the 80's.

      And a lot of people will talk just because. Rajid at the 7-11 (not flamebait-that's really his name), a half-dozen homeless guys, and a handful of "undocumented workers" who are just as happy that the gringo cop speaks Spanish and doesn't know INS' phone number like to talk about what goes on in one particular neighborhood, and that includes talking to cops who want to buy coffee at 3AM (mainly me) and as a result I know pretty much everything that happens within two blocks of that 7-11.

      It's all about people, and knowing how to listen to them. If the CIA had the good sense to hire street cops, semi-experienced newspaper reporters, multilingual cabdrivers, and a very few really good clinical psychologists to send overseas, they'd be able to tell us what kind of lube Osama bin Laden uses when he has relations with his goats, whether Jiang Zemin really is a pedophile or if that's just office gossip, if there's another reason why Vladimir Putin is cranky this week, and where the communist guerillas in Colombia buy their cigarettes. The really REALLY good information-gatherers know that they need to talk to people instead of wasting money on techno-toys.

  5. Big deal! by shyster · · Score: 5, Insightful
    Big deal! So they managed to map their public space and their mail servers on the inside. All of this is pretty easy to find out and is hardly supposed to be a secret.

    As for the email addresses and sysadmin names, I really don't think that's a big deal.

    "Simply knowing the names and e-mail addresses that Matta turned up would be enough for some social engineers to get the rest of the information necessary to mount an attack,"

    Guess we better stop posting our email addresses and names! And, god forbid, get rid of your business cards! And don't forget your whois information!!!!

    If that's really an avenue to social engineering, then we're all in trouble.

  6. PH34R MY SK1LLZ by spoonist · · Score: 5, Funny
    h3y d00dz!

    nslookup -q=mx www.cia.gov

    - m4tt4 s3cur1ty 1337 h4x0r

  7. good link on legality of port scanning by zkosky · · Score: 5, Informative

    A link that has some good info on the legality of port scanning is: Journal of Technology Law and Policy
    If you take the time to read it, there is a bunch of interesting stuff in it. Just do a page search for "port" and you'll get to the cool stuff.

  8. Original PDF Report by Alien54 · · Score: 5, Informative
    It doesn't look like the information they gathered alone is really anything remarkable

    Exactly. It is the typical information that any sysadmin from the outside. The graphic diagramming the networking layout shows nothing remarkable.

    You can seen the original report in PDF format here, with _all_ of the juicy details.

    Which is funny, because the link is not directly accessable from the main site.

    talk about security.

    --
    "It is a greater offense to steal men's labor, than their clothes"
  9. Anyone else notice the Lotus Domino Server by Anonymous Coward · · Score: 5, Interesting

    version 5.0.6a

    Why you may ask?

    Because Lotus Notes and Lotus Domino is the only mail product that gives email administrators zero access to information within mail files. Each Notes database has an access control list, and you can specify who's on it. The mail server can have "depositor" access, which means it can only place information inside the database. The database can also be encrypted so that only the server can read it -- meaning someone has to steal a copy of the database itself off of the file system, in order to have a chance at decryption.

    1. Re:Anyone else notice the Lotus Domino Server by Cedric+C.+Girouard · · Score: 5, Informative
      Because Lotus Notes and Lotus Domino is the only mail product that gives email administrators zero access to information within mail files. Each Notes database has an access control list, and you can specify who's on it. The mail server can have "depositor" access, which means it can only place information inside the database. The database can also be encrypted so that only the server can read it -- meaning someone has to steal a copy of the database itself off of the file system, in order to have a chance at decryption.

      Little known fact: The password entry box you get when logging in to a domino client/server setup with the 4 little hieroglyphs, is a CIA-requested add-on. That and the random amount of X's you get when you punch in the password.

      Also, stealing a copy of the database will not help you if persistent ACL's were set up.

      Other nice features of Domino is that you can have multiple level of access within each documents, meaning that group XYZ would have read access to the entire document, while group XY would only get 2/3rd of the forms in it, and group X would get only 1/3rd of the forms within the document.

      Reasons why they're not using Exchange ? Well... Exchange did never get its security clearance...

      --

      Marriage is considered capital punishment for the theft of a goat in some third world countries...

    2. Re:Anyone else notice the Lotus Domino Server by DavittJPotter · · Score: 3, Interesting

      Except: as an administrator, if you *really* want to read someone's mail, you can re-register and re-certify that person, thereby generating a new ID file, which will match the entry in the .nsf's ACL. You then Switch ID to that user, and open their database. The ACL reads Davitt J Potter/CIA/GOV/US, and... well, you're in. Why do I know this? :) Users forget passwords, and this is how we recovered passwords. Granted, this is not the most secure implementation, but it is the default for a Domino installation.

      You *can* disable this, however, by setting up password recovery within Domino, which I recommend that ALL Domino admins do. Then it requires anywhere from 2 to (I think) 4 different ID's to enter a recovery password, which will then recover the user's password.

      Domino/Notes also is interesting in that your password is never sent over the wire, encrypted or otherwise. Your machine gets a copy of about a 2K $user.id file, which contains your authentication certificate to the Domino server. Your password identifies to your certificate that "I am Davitt J Potter/CIA/GOV/US." The Notes client then sends the certificate info to Domino, which then checks to make sure that certificate was generated by the Domino server, and is still a valid certificate. (Domino servers can set certificate expirations, so even if your password is valid, your certificate may be expired.)

      I found Domino to be a really nice enterprise level email solution; I only wonder why it isn't used more?

      --
      "If there's hope, it lies in the proles..."
    3. Re:Anyone else notice the Lotus Domino Server by twinpot · · Score: 3, Informative
      Except: as an administrator, if you *really* want to read someone's mail, you can re-register and re-certify that person, thereby generating a new ID file, which will match the entry in the .nsf's ACL. You then Switch ID to that user, and open their database. The ACL reads Davitt J Potter/CIA/GOV/US, and... well, you're in.


      This won't work if the mail is encrypted, because if you create another ID with the same name, the public/private key combo is different. Therefor the only thing you may be able to read is the subject line. The message body will have been encrytped (you can encrypt the DB itself, and you can specify that all emails you receive are encrypted too).

  10. Fuckin' A! by Knunov · · Score: 4, Funny

    "Sorry, I don't buy that. "Hi, this is chuck, the webmaster. Can I have the names of our russian agents please?""

    I always find it amusing when people try to make the CIA/FBI/NSA out to be bumbling idiots. They're not perfect, but they are really f'ing good.

    In fact, if someone brought that weak 'social engineering' their way, it wouldn't surprise me if they were logged, traced, then given a visit by a couple really solemn-looking men in bad suits and dark sunglasses that smelled like pistachios.

    I dare even one of the cynical know-it-all people that read this board to try it. Be sure to post your results so we can laugh at your cornholing.

    Knunov

    --
    Why do users with IDs under 100,000 or over 700,000 usually have the most worthwhile comments?
  11. Re:Hah. by CokeBear · · Score: 3, Insightful
    Thats not the point!

    The point is, that anyone in the USA should be allowed to discuss the merits of any social/political system. For a long time, that discussion was cut off, and people who held a particular viewpoint (however absurd it might seem to us rational people) were fired from their jobs, spied on, and even imprisoned.

    --
    Reality has a liberal bias
  12. Hackers tools by The+Monster · · Score: 3, Insightful
    Who needs portscans. The article says:
    "The fact that this information was gathered through a search on Google.com, which is hardly considered by most people to be a hacker's tool, is especially interesting,"
    Absolutely true, if you think about it. Google is most definitely a hacker's tool, but not a tool for doing what most people consider to be 'hacking', nor for that matter do most people consider google itself.
    --

    [100% ISO 646 Compliant]
    SVM, ERGO MONSTRO.

  13. Ever heard of stripping headers? by tweek · · Score: 3, Insightful

    The least they could do is have the outbound mailserver strip the internal mail headers from the message before sending it out. It's easy to do with postfix and that's what we do. Why give out anymore information than needed? I noticed that they were able to get what CIDR block they use for internal IP's from the mailserver.

    Jesus I don't run a covert espionage agency and I at least do that at our company. Hell I even proxy requests to private servers from an apache server in the DMZ.

    Isn't this just basic network security?

    --
    "Fighting the underpants gnomes since 1998!" "Bruce Schneier knows the state of schroedinger's cat"
  14. Wana know more? by kruczkowski · · Score: 3, Informative

    Here, get this CD/Video set, it's free! Learn how to secure Windows NT/UNIX to goverment standards! Order now!

    http://iase.disa.mil/eta/index.html

    --
    hmm... for fun I enjoy launching DDoS attacks against 127.87.42.5
  15. Re:wonderful by gad_zuki! · · Score: 3, Funny

    Related Stories: Report warns of al-Qaeda's potential cybercapabilities
    don't you just love when we do half the terrorists jobs for them then wonder how they pull off elaborate attacks?


    Yeah, they sure are helping the enemy.

    The terrorists have connected to port 25, I repeat the terrorists have connected to port 25!!!!

  16. Significance? by hyrdra · · Score: 3, Interesting

    I have a feeling this made news just because of it's affiliation with the CIA -- the all powerful super secret spy agency of the US government. I sure wish I could generate news stories by doing recursive whois reports and DNS queries.

    What's next? I would think that if you were not able to map the CIA's unclassified public network than they must have some sort of major DNS problem.

    There is absolutely no significane to this news story other than organizations who maintain a publically accessible web site with such services as e-mail and a web site must have a logical network structure to deliver said services. The CIA is no exception.

    --


    "I'll just chip in a bit for RedHat: I actually have that installed on my university machine." - Linus, '95
  17. Port scanning by lightspawn · · Score: 3, Insightful

    (Is there a site/whatever where people with ideas suggest what software is missing and people with time may choose to implement them?)

    What I want is a kernel module to defeat port scanning. Whenever a remote tries to connect to a port that isn't bound, the module kicks in, accepts the connections, and doesn't do anything, or echos the incoming data, or sends random data, or behaves like a web/ftp/etc server, or a combination of the above.

    If most computers used this, wouldn't port scanning become impractical?

    Would there by any harm in it?

  18. Never re-route CIA packets... by darkonc · · Score: 4, Interesting
    A friend of mine once described a run-in that his company had with 'the CIA' a number of years ago.

    Before his company got attached to the net, they were using an address of '11.*' for their internal computers, which included a number of Sun workstations -- some doing double duty as routers. For those of you who don't know, RFC 1918 officially designates 3 network ranges for this sort of work -- 192.168.*, 10.* and 172.16.0/12. 11.0 obviously doesn't fit in that range.

    When they got their network attached to the 'net, they had to do a good deal of work to renumber all of their computers to have 'proper' IP addresses (either in their assigned block, or in an RFC1918 non-routing block).

    Within an hour of connecting their box to the 'net, they got a rather brusque call from an intelligence agency official demanding to know why they were stealing his packets. They had to disconnect from the network and root around their network until they found (and removed) the errant subnet stub. It turns out that they had managed to miss one SUN with a second ethernet card that was no longer attached to an active subnet (but still routing to the stub subnet). This was back at a time when any SUN with two ethernet cards routed by default, and every machine ran routed(8) as a matter of course (much easier than having to do manual routing all the time!). It turns out that the route to the stub network had leaked out to the larger internet and poisoned the routing for a huge pool of machines.

    When I teach networking, I use it as an example of why you should always use the proper non-routing addresses for internal networks.

    (I just did a whois, and 11.0/8 is actually owned by the Defence Intelligence Agency, not the CIA. Not like there's a big difference for us civies.)

    --
    Sometimes boldness is in fashion. Sometimes only the brave will be bold.