Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Another Defense Contractor Hacked in AntiSec Hacktivism Spree

Published: 2011-07-11
Last Updated: 2011-07-11 21:49:24 UTC
by John Bambenek (Version: 1)
13 comment(s)

A torrent just popped up on the Pirate Bay a few hours ago that leaks 90,000 emails and unsalted MD5 hashes as well as other reportedly damanging information about Booz Allen Hamilton, a contractor to the US government.  Several news sites already have the story, or at least what we know of it.  The hashes themselves are relatively easy to crack using commodity cracking tools, but likely that isn't the real damage here.  Anonymous has claimed credit for the hack.

At this point, the means by which BAH was breached is unknown and likely pure speculation.  That said, it is no longer secure to hash your passwords with MD5, much less when it is unsalted.  Take a look at using a SHA-2 variant, if possible.  Also, require strong and long passwords while minimizing password re-use to avoid compromised credentials being used to dig deeper into an organization.  As more facts are known, this port will be updated.

--
John Bambenek
bambenek at gmail /dot/ com
Bambenek Consulting

13 comment(s)
Diary Archives