NASA: Hackers had 'full functional control'
Summary: NASA this week released details of security breaches the organization has recently experienced. Out of 47 attempts last year, hackers managed to penetrate NASA's computer network 13 times.
The National Aeronautics and Space Administration (NASA) has finally revealed how badly it was attacked by hackers last year. The space agency's Inspector General Paul Martin explained in a testimony to Congress how NASA's computer network was penetrated by hackers at least 13 times in 2011.
Furthermore, one China-based breach in November resulted in total control of crucial systems and employee accounts at NASA's Jet Propulsion Laboratory (JPL), including full system access, the ability to modify/copy/delete sensitive files, and even upload hacking tools for wreaking further havoc. The personal credentials of 150 employees were stolen. The attack involving Chinese IP addresses is still under investigation.
Here's an excerpt of the 10-page report, titled "NASA Cybersecurity: An Examination of the Agency’s Information Security" (PDF), written by the Office of Inspector General (OIG):
In FY 2011, NASA reported it was the victim of 47 APT attacks, 13 of which successfully compromised Agency computers. In one of the successful attacks, intruders stole user credentials for more than 150 NASA employees – credentials that could have been used to gain unauthorized access to NASA systems. Our ongoing investigation of another such attack at JPL involving Chinese-based Internet protocol (IP) addresses has confirmed that the intruders gained full access to key JPL systems and sensitive user accounts. With full system access the intruders could: (1) modify, copy, or delete sensitive files; (2) add, modify, or delete user accounts for mission-critical JPL systems; (3) upload hacking tools to steal user credentials and compromise other NASA systems; and (4) modify system logs to conceal their actions. In other words, the attackers had full functional control over these networks.
Another security failure occurred in March, when an unencrypted NASA notebook computer containing algorithms to command and control the International Space Station, was stolen. NASA insists the station was never in any jeopardy. The report also noted that only 1 percent of NASA's mobile computing devices are encrypted, and 48 were stolen between April 2009 and April 2011.
In a separate event, hackers grabbed the user credentials belonging to more than 150 employees, which in turn could have been used to gain unauthorized access to NASA systems. Martin admitted the agency failed to move quickly enough to ensure those hackers wouldn't be able to take advantage of the credentials.
Martin's report further reveals that NASA saw more than 5,408 incidents of malicious software or unauthorized access of its computers between October 1, 2010, and September 30, 2011. NASA estimated the total cost of these security incidents at more than $7 million. The written testimony was delivered Wednesday to a hearing of the House Committee on Science, Space and Technology's Subcommittee on Investigations and Oversight.
OIG investigators have conducted more than 16 separate investigations of NASA computer network breaches over recent years. The motivation of the hackers ranged from "individuals testing their skill to break into NASA systems, to well-organized criminal enterprises hacking for profit, to intrusions that may have been sponsored by foreign intelligence services." Hacking suspects have been arrested in China, Estonia, Great Britain, Italy, Nigeria, Portugal, Romania, and Turkey.
"NASA has made significant progress to better protect the agency's IT systems and is in the process of implementing the recommendations made by the NASA Inspector General in this area," a NASA spokesperson said in a statement.
See also:
- NASA retires its last mainframe
- NASA's big ideas for the future of flight (photos)
- NASA launches multiplayer Facebook game
- Planets cover our galaxy - we are not alone
- NASA opens it Open-Source Code Doors
- NASA's Mars rover finds strong evidence of ancient water (photos)
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: NASA hack
fdssd
Promotional Items http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Wholesale Camera Bar Holder Tray
China Wholesale http://www.chinawholesaletown.com/wholesale-Egg-Shakers/ Business Gift Wholesale Hardware Tools
Magnifier Ruler http://www.chinawholesaletown.com/wholesale-Pet-Dog-Leash/ Coca Cola Glass Wholesale First Aid Kit
Wholesale Camera http://www.chinawholesaletown.com/wholesale-Alcohol-Tester/ Wholesale Bag Wholesale Racks
Promotional Gifts http://www.chinawholesaletown.com/wholesale-Shaker-Bottle/ Silicone Bakeware Wholesale Keychain
Wholesale Tag http://www.chinawholesaletown.com/wholesale-Note-Pad-Holder-Calendar/ Voice Recorder Electrical Gifts
Wholesale Bookmark http://www.chinawholesaletown.com/wholesale-UV-Pen/ Solar Products Audio Video Equipment
World Cup Products http://www.chinawholesaletown.com/wholesale-Jute-Bag/ Wholesale Pin Tube Cooler
Wine Set http://www.chinawholesaletown.com/wholesale-Foldable-Hat---Folding-Caps_117412/ Tangle Wholesale Ashtray
Ring Whistle http://www.chinawholesaletown.com/wholesale-Pet-Carrier/ Retractable Dog Leash Magnifier Ruler
Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Notebook-Calculator/ Fleece Blanket Cleaner Products
Health Care Products http://www.chinawholesaletown.com/wholesale-LED-Light-Bottle-Opener/ Wholesale Banner Wholesale Clap Hands
Tire Tote http://www.chinawholesaletown.com/wholesale-Magnifier-Ruler/ Beauty Equipment Wholesale Tag
Digital Spoon Scale http://www.chinawholesaletown.com/wholesale-Referee-Ring-Whistle_116906/ Garden Decorations Wholesale Tableware
Pen Holder http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Name Card Holder Frosty Beer Mug
Bar Holder Tray http://www.chinawholesaletown.com/wholesale-Wine-Pouch/ Men Beauty Care Wholesale Cards
Glass Coaster http://www.chinawholesaletown.com/wholesale-Newtons-Cradle/ Pet Supplies Wholesale Clothes Rack
Wholesale Whistle http://www.chinawholesaletown.com/wholesale-Water-Power-Clock/ Beach Towel Water Bottle
Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Level-Tape-Measure/ Bottle Holder Teeth whitening Pen
c http://www.chinawholesaletown.com/wholesale-Gashapon---Capsule-Toy-Empty-Shell---Easy-Open_95643/ Poncho Keychain Poncho Keychain
Promotional Products http://www.chinawholesaletown.com/wholesale-Alcohol-Tester/ Wholesale Toys Water Filter Bottle
Wholesale Mug http://www.chinawholesaletown.com/wholesale-Golf-Putting-Set/ Lunch Box Sport Items
Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Electric-Heating-Mugs/ Heating Products Waterproof Beach Case
Wholesale Stationery http://www.chinawholesaletown.com/wholesale-ID-Tag/ Permanent Match Lighter Electroluminescent
Wholesale Towel http://www.chinawholesaletown.com/wholesale-Shopping-Basket/ Wholesale iPod iPhone Wholesale Earphone
Wholesale Banner http://www.chinawholesaletown.com/wholesale-LED-Keychain-Light/ Promotional Gifts Wholesale Massager
Electrical Gifts http://www.chinawholesaletown.com/wholesale-Back-Scratcher/ Bar Caddy Money Bank
Bingo Bag http://www.chinawholesaletown.com/wholesale-Frosty-Beer-Mug/ Water Spray Fan Wholesale Badge
Wholesale Album http://www.chinawholesaletown.com/wholesale-Lunch-Box/ Wholesale Waterproof Case Bottle Opener
Recorder Pen http://www.chinawholesaletown.com/wholesale-Abacus/ Wholesale Wallet Wholesale Memory Card
Wholesale Keyboard http://www.chinawholesaletown.com/wholesale-Wedding-Favors/ Wholesale Accessories Money Clip
Wedding Coaster http://www.chinawholesaletown.com/wholesale-Decision-Maker/ Wholesale Tellurion Wholesale Bedding
Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-Metal-Money-Bank/ Highlighter Pen Waterproof Hard Case
Menu Holder http://www.chinawholesaletown.com/wholesale-Wine-Bottle-Cover/ Abacus China Wholesale
Wholesale Memory Card http://www.chinawholesaletown.com/wholesale-Multifunction-Pen-Holder/ World Cup Products Highlighter
Wholesale Pedometer http://www.chinawholesaletown.com/wholesale-Lighter-Bottle-Opener/ Glass Coaster Silicone Bakeware
Wholesale Flag http://www.chinawholesaletown.com/wholesale-Collapsible-Water-Bottle/ Silicone Cake Mould Wholesale Tellurion
Home Appliances http://www.chinawholesaletown.com/wholesale-Leather-Clock/ Wholesale Helmet Wholesale Mat
Fleece Blanket http://www.chinawholesaletown.com/wholesale-Badge-Reel/ Wholesale Cap Wholesale Glasses
Wholesale Vase http://www.chinawholesaletown.com/wholesale-Desk-Calendars/ Wholesale Kitchenware Wholesale Furniture
RE: NASA hack
Those $200 toilet seats can be had for $5 @ Wally World now.
Just think how much our government can save!
Rehashing Old News
This is why it is imperative to proceed with the 'smart grid'
Only 47 yeah right ok NOT
And of course at the end, I take great confidence in knowing that NASA is taking advice on fixing these problems from the NASA Inspector General.
I'm to guess that this Inspector General is a new position recently concocted, because if this person was there at the time, they should have had these changes in place. And only 1 percent of NASA mobile devices are encrypted? That's too funny.
that's the price paid
sdfd
Wholesale T-Shirts Name Card Holder http://www.chinawholesaletown.com/wholesale-Money-Clip/ Electrical Gifts
Computer Accessories Wholesale Ashtray http://www.chinawholesaletown.com/wholesale-Muslim-Products/ Silicone Products
Wholesale Cooler Wholesale Fan http://www.chinawholesaletown.com/wholesale-Tableware/ Personal Safety Products
Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
Lighting Products Wholesale Tellurion http://www.chinawholesaletown.com/wholesale-Socks/ Giveaway Material
Photo Frame Pet Supplies http://www.chinawholesaletown.com/wholesale-Hardware-Tools/ Compass
Water Bottle Medicine Instrument http://www.chinawholesaletown.com/wholesale-Calendar/ Stapler
Wholesale Shoe Wholesale lable http://www.chinawholesaletown.com/wholesale-Computer-Keyboard/ China Wholesale
Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
Wholesale Hardware Tools Wholesale Umbrella http://www.chinawholesaletown.com/wholesale-Towel/ Clothing
Wholesale Keyboard Business Gift http://www.chinawholesaletown.com/wholesale-World-Cup/ Tag
Wholesale Glass Book Light http://www.chinawholesaletown.com/wholesale-Bedding/ Patient Care Products
Promotional Gifts Digital Photo Frame http://www.chinawholesaletown.com/wholesale-Outdoor---Leisure/ Outdoor Leisure Products
Wholesale Raincoat Wholesale Glass http://www.chinawholesaletown.com/wholesale-Mobile-Phone/ Waterproof Case
Stuffed Animals Audio Video Equipment http://www.chinawholesaletown.com/wholesale-Pure-Cotton-Compressed/ Kitchenware
Coca Cola Gifts Wholesale Belt http://www.chinawholesaletown.com/wholesale-Coca-Cola-Gifts/ Mouse
Heating Products Wholesale Cooler http://www.chinawholesaletown.com/wholesale-Automotive-Products/ Carabiner
Beauty Equipment Wholesale Toys http://www.chinawholesaletown.com/wholesale-Christmas-Gifts/ Socks
Pet Supplies Wholesale Bedding http://www.chinawholesaletown.com/wholesale-Crystal-Gifts/ Candle
Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
Wholesale Bag Wholesale Scissors http://www.chinawholesaletown.com/wholesale-Wallet/ Vuvuzela
Wholesale Waterproof Case Wholesale Cup http://www.chinawholesaletown.com/wholesale-Electrical-Gifts/ Bracelet
Wholesale Ashtray Wholesale Vuvuzela http://www.chinawholesaletown.com/wholesale-Mug/ Wine Set
Wholesale Massager Wholesale Watch http://www.chinawholesaletown.com/wholesale-Frisbee/ Clap Hands
Muslim Products Wholesale Tie http://www.chinawholesaletown.com/wholesale-Umbrella/ TelePhone
Wholesale Tag Promotional Products http://www.chinawholesaletown.com/wholesale-Personal-Safety/ Camera
Safety Suppliers Wholesale Shoe http://www.chinawholesaletown.com/wholesale-Stress-Ball/ Magnifier
Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
Wholesale Stress Ball Wholesale Mug http://www.chinawholesaletown.com/wholesale-Clocks/ Lunch Box
Medicine Instrument Wholesale Jewelry http://www.chinawholesaletown.com/wholesale-Eye-Masks/ Playing Card
Wholesale Scissors Arts Crafts http://www.chinawholesaletown.com/wholesale-Reflective-Safety-Vest/ Safety Suppliers
Wholesale Stapler Wholesale Calculator http://www.chinawholesaletown.com/wholesale-Badge---Pin/ Puzzle
Wholesale Dartboard Wholesale Lanyard http://www.chinawholesaletown.com/wholesale-Toys---Games/ Tellurion
Wha happened??
Tell OIG to Listen to Richard Clarke
Richard Clarke: China has hacked every major US company
This is only the tip of a HUGE iceberg.
It is cyberwar if any substantial proportion of the 47 NASA breaches are all from a single country.
Be informed.
Any small high-tech Co CEO's with good technology in house? Get protected!
Cyber War?
We still prefer to put soldiers on the ground in some foreign country to be blown up, and mentally traumatized at a lifetime cost of a couple million each on average.
We should be paying little Johnny Hacker +$70k a year at 18 to sit home and hack the 4377 out of China. Crash everything in China that is network accessible!
They complain, bring our cards to the table with proof they are doing it to us.
Fight fire w/fire...?
What if we (aka "politicians") spent as much time and money on securing our internet infrastructure as we ("they") do on trying to regulate it and make a profit from it? Or, just for $h!+s and grins, maybe we could actually EDUCATE instead of MEDICATE our children so that when Little Johnny grows up, he'll have the intellectual capacity to save us from ourselves... sigh, so much to do, so little potential to get it done...
Security
Pretty sad :(