MI5 Website Breached By Hacker
Jack Spine writes "UK intelligence agency MI5 has admitted that its website security was breached by hacker group Team Elite. A member of the hacker forum posted details of the hack last week, which took advantage of a cross-site scripting vulnerability in the site's Google embedded search. MI5 admitted the breach on Wednesday, but said that the flaw had not been exploited maliciously."
No doubt we'll find out on uk.misc later.
"Absorbing your worst..."
MI5 allows websurfing on critical computers.
Seriously. How else would you get hit by CSS?
It's a sort of script-injection vulnerability where you'd have to click on someone else's link to the MI5 site. I suppose it could steal cookies from someone stupid enough to click on a long link from an unknown person, but it's not like the site itself was hacked or anything, which is what "website breached by hacker" strongly implies.
If a whole bunch of fake Iraq WMD reports start showing up on the net in the next few days, then we'll know if they were really exploited or not...
I propose the MI5 website team should be known as the "Mostly Incompetent 5" team !?
Take Nobody's Word For It.
I see this and think the word "Hacked" gets thrown around a bit too easily. This is an example of non-persistent (also referred to as reflected) cross site scripting. This means that in order to take advantage of it, they have to convince a target to visit their specially crafted link. To me, "Hacked" sort of implies "They got in!" or "Data was breached!" or other such bad things and that simply isn't the case here.
So what does this type of XSS do? Mostly embarass people because defacement examples are posted to "look what I can do" forums (which is basically what happened). Think about the attack vector here, they have to get a victim to visit their specific url that includes their attack. How is that done? Malicious email, posting the link to some website or forum and hoping they find it and visit, embedding the link in other sites that have been hacked or something like a banner ad, or whatever. All of these involve the target going out of their way to visit this maliciously crafted url. When you consider that they could still do all these things without XSS and simply host malicious code themselves, all this reflected XSS is doing is making it a bit harder for an end user to spot that this is something non-standard and dangerous.
Think of it this way, "With reflected XSS, I can send them a link, and if they visit it, I can do bad things to their computer!" but then again, you can do that without XSS too, it just isn't quite as effective. How many users are taking the time to carefully look at a link before clicking on it, checking to make sure it contains the domain name they expect and not just an IP address, or a domain name that is similar, but not quite right, etc. A user who is doing this sort of thing will more likely fall victim to this XSS attack, but most users, who don't scrutinize things at that level, were just as susceptible to a classic phishing/malicious linking attack anyways.
I'm not sure I'd call exploiting an XSS vulnerability penetrating. Sure, it can be used with a hybridized CSRF attack to penetrate into otherwise restricted areas of a website (although I don't know of such areas on MI5's website), but XSS, in and of itself, is more akin to graffiti than anything else.
And, btw, I don't consider the social engineering element of XSS to be a particularly bonafide threat. If someone's going to provide all their personal info because the MI5 website, through XSS, asked for it, what's to stop them from doing it for some MI5 look-alike domain? <sarcasm>mi5verify.co.uk is asking for my info? Only MI5 could have MI5 in their domain!!!
You should be hearing black helicopters any moment. Stay in the basement - it's safer.
Sent from my iPhone
People tend to confuse hacking with cracking quite often, thanks to the mass media.
[ irc.p2p-network.net -> #zomgwtfbbq ][ http://zomgwtfbbq.info ]
any "l33t hax0r" in the house brave enought to try this shit on the NSA ?
considering that i never heard of any snafu from those guys, either their pretty good at sevuring their stuff, or incredibly efficient at snuffing anyone who tries it before news get to public.
sincerely, i don't know which one is the scariest scenario.
What ? Me, worry ?
How could they ever abuse this "hack" anyway? "Hey man check the MI5 website by following my link here, it's a really cool governmental agency really. Please click!"
Hey, did you know that someone on the MI5 site with your name is listed as a terrorist. He lives in the (your city) region as well. I'd watch out if I were you, someone might get the wrong idea. Here's a link so you can check it out yourself.
If they were smart, they'd start with the guy who thought it was a good idea to allow browsers to run javascript outside the <HEAD> section.
Then they'd go after all the cowboy coders who'd be screaming "but it's soooo convenient".
Send in the new Bond after them, hackers might think twice after seeing these guys get a few bullets in the back of their heads!
... apparently the hackers used jailbroken iPhones ;-)
http://apple.slashdot.org/story/09/07/29/1440233/Apple-Says-iPhone-Jailbreaking-Could-Hurt-Cell-Towers
Roberto
Fort Knox announced today that someone broke in and took a dump on the Gold ... nothing was stolen though.
News of hacked public websites of powerful public agencies is titillating but technically insignificant. These sites are usually maintained by the lowest bidder on the cheapest servers with the most scant security. And they generally have no useful information. Boring! On the other hand, cyber warfare is constant and both government and industry networks with valuable information assets are under constant attack. I know this first hand from having had oversight of network security in a major scientific lab several years ago. Little or nothing is reported either in the way of successful penetrations and damage or attacks thwarted. That is the frontier people, where there is not only action with major consequences but hard computer and network science happening every day.
There's no sense in being precise when you don't even know what you're talking about. -- John von Neumann
Man.. James Bond villains are getting a lot nerdier.
Somebody beat you to this conclusion.
A hacker's apartment in London was invaded by a gang of unknowns. Nothing was stolen, but his computer was smashed, his books urinated on, and the victim suffered a broken leg, torn elbow tendon, and a few cracked ribs after reportedly being waterboarded in his own kitchen.
This is my sig.
What about wardriving?
The Tao of math: The numbers you can count are not the real numbers.
You mean, like, in the onClick attribute?
Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
And yet you still feel the need to hide behind AC?
Your method of communication exposes your stink of fear....
I'll spare you the shame and follow up....
TE is a bunch of pu#$^#$%^$%^ ---NO CARRIER