FBI Hacked — Hacker Blames “Lazy” Security and Outdated Operating System

IT | Jan 12, 2017 | Master3395

s: A hacker has claimed to have breached the content management system used by the FBI. The hacker uses Twitter handle @CyberZeist and claims to have dumped email addresses and hashes on Pastebin. The fbi.gov’s server was hosted on an outdated FreeBSD VM, according to the hacker.

Ahacker, who operates the Twitter handle @CyberZeist, has made claims regarding hacking the FBI’s website, fbi.gov, and gaining sensitive information. Prior to this claim, the hacker claimed to have exposed the flaw on 22 December. 

The hacker has dumped 155 stolen credentials on the Pastebin. @CyberZeist accessed the data by exploiting a zero-day vulnerability in the open source cms software, named Plone, used by the FBI to host its website’s content. He found the flaw in a Python module.

The websites of the National Intellectual Property Rights Coordination Center and the European Union Agency for Network and Information Security are also hackable, says @CyberZeist.

On Twitter, @CyberZeist tweeted that various sources contacted hacker, requesting a copy of stolen data, which was declined.

As the website was hosted in a VM, the hacker was unable to gain root access. Still, he managed to get some server data. The FBI website’s server was actually a FreeBSD version 6.3_RELEASE.

Interestingly, the hacker also says that the zero-day used in the exploit is being sold on the dark net. So, he doesn’t plan to share more details until it’s available for purchase.

@CyberZeist has also claimed that FBI’s webmaster has a very lazy attitude as she/he stored the backup files on the same folder as the site’s root.

Did find this story on FBI hack helpful? Don’t forget to share your views and feedback.

Keywords: FBI, Security, Hacker

Author: Master3395


comments powered by Disqus

Page 1 of 376  >  >>

Working hard to preserve all public posts on Google+


Mar 20, 2019 | Category: Google | Comments

Now it will not be long.

read more…

New Window Defender Extension Launches - Insecure Websites Open in Edge


Mar 19, 2019 | Category: General | Comments

Works in Chrome and Firefox.

read more…

Now the extensions have appeared - public testing is approaching


Mar 18, 2019 | Category: General | Comments

Found 82 extensions for new Edge.

As we interpret recently Microsoft's activity, we are not the long wait from a public testing period of their new Chromium-based browser. Last week we got a sneak peek at new Edge in some photos you can see here, and it was explained that the first tests only had support in 64-bit Windows 10.

read more…

Page 1 of 376  >  >>