NASA: Hackers had 'full functional control'

Summary: NASA this week released details of security breaches the organization has recently experienced. Out of 47 attempts last year, hackers managed to penetrate NASA's computer network 13 times.

The National Aeronautics and Space Administration (NASA) has finally revealed how badly it was attacked by hackers last year. The space agency's Inspector General Paul Martin explained in a testimony to Congress how NASA's computer network was penetrated by hackers at least 13 times in 2011.

Furthermore, one China-based breach in November resulted in total control of crucial systems and employee accounts at NASA's Jet Propulsion Laboratory (JPL), including full system access, the ability to modify/copy/delete sensitive files, and even upload hacking tools for wreaking further havoc. The personal credentials of 150 employees were stolen. The attack involving Chinese IP addresses is still under investigation.

Here's an excerpt of the 10-page report, titled "NASA Cybersecurity: An Examination of the Agency’s Information Security" (PDF), written by the Office of Inspector General (OIG):

In FY 2011, NASA reported it was the victim of 47 APT attacks, 13 of which successfully compromised Agency computers. In one of the successful attacks, intruders stole user credentials for more than 150 NASA employees – credentials that could have been used to gain unauthorized access to NASA systems. Our ongoing investigation of another such attack at JPL involving Chinese-based Internet protocol (IP) addresses has confirmed that the intruders gained full access to key JPL systems and sensitive user accounts. With full system access the intruders could: (1) modify, copy, or delete sensitive files; (2) add, modify, or delete user accounts for mission-critical JPL systems; (3) upload hacking tools to steal user credentials and compromise other NASA systems; and (4) modify system logs to conceal their actions. In other words, the attackers had full functional control over these networks.

Another security failure occurred in March, when an unencrypted NASA notebook computer containing algorithms to command and control the International Space Station, was stolen. NASA insists the station was never in any jeopardy. The report also noted that only 1 percent of NASA's mobile computing devices are encrypted, and 48 were stolen between April 2009 and April 2011.

In a separate event, hackers grabbed the user credentials belonging to more than 150 employees, which in turn could have been used to gain unauthorized access to NASA systems. Martin admitted the agency failed to move quickly enough to ensure those hackers wouldn't be able to take advantage of the credentials.

Martin's report further reveals that NASA saw more than 5,408 incidents of malicious software or unauthorized access of its computers between October 1, 2010, and September 30, 2011. NASA estimated the total cost of these security incidents at more than $7 million. The written testimony was delivered Wednesday to a hearing of the House Committee on Science, Space and Technology's Subcommittee on Investigations and Oversight.

OIG investigators have conducted more than 16 separate investigations of NASA computer network breaches over recent years. The motivation of the hackers ranged from "individuals testing their skill to break into NASA systems, to well-organized criminal enterprises hacking for profit, to intrusions that may have been sponsored by foreign intelligence services." Hacking suspects have been arrested in China, Estonia, Great Britain, Italy, Nigeria, Portugal, Romania, and Turkey.

"NASA has made significant progress to better protect the agency's IT systems and is in the process of implementing the recommendations made by the NASA Inspector General in this area," a NASA spokesperson said in a statement.

See also:

Topics: CXO, Networking, Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

13 comments
Log in or register to join the discussion
  • RE: NASA hack

    It would sure be be a bummer if they shut off the toilet !
    preferred user
    • fdssd

      Silicone Products http://www.chinawholesaletown.com/wholesale-Level-Ruler---Digital-Level/ Wholesale Thermometer Wholesale Keyboard
      Promotional Items http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Wholesale Camera Bar Holder Tray
      China Wholesale http://www.chinawholesaletown.com/wholesale-Egg-Shakers/ Business Gift Wholesale Hardware Tools
      Magnifier Ruler http://www.chinawholesaletown.com/wholesale-Pet-Dog-Leash/ Coca Cola Glass Wholesale First Aid Kit
      Wholesale Camera http://www.chinawholesaletown.com/wholesale-Alcohol-Tester/ Wholesale Bag Wholesale Racks
      Promotional Gifts http://www.chinawholesaletown.com/wholesale-Shaker-Bottle/ Silicone Bakeware Wholesale Keychain
      Wholesale Tag http://www.chinawholesaletown.com/wholesale-Note-Pad-Holder-Calendar/ Voice Recorder Electrical Gifts
      Wholesale Bookmark http://www.chinawholesaletown.com/wholesale-UV-Pen/ Solar Products Audio Video Equipment
      World Cup Products http://www.chinawholesaletown.com/wholesale-Jute-Bag/ Wholesale Pin Tube Cooler
      Wine Set http://www.chinawholesaletown.com/wholesale-Foldable-Hat---Folding-Caps_117412/ Tangle Wholesale Ashtray
      Ring Whistle http://www.chinawholesaletown.com/wholesale-Pet-Carrier/ Retractable Dog Leash Magnifier Ruler
      Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Notebook-Calculator/ Fleece Blanket Cleaner Products
      Health Care Products http://www.chinawholesaletown.com/wholesale-LED-Light-Bottle-Opener/ Wholesale Banner Wholesale Clap Hands
      Tire Tote http://www.chinawholesaletown.com/wholesale-Magnifier-Ruler/ Beauty Equipment Wholesale Tag
      Digital Spoon Scale http://www.chinawholesaletown.com/wholesale-Referee-Ring-Whistle_116906/ Garden Decorations Wholesale Tableware
      Pen Holder http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Name Card Holder Frosty Beer Mug
      Bar Holder Tray http://www.chinawholesaletown.com/wholesale-Wine-Pouch/ Men Beauty Care Wholesale Cards
      Glass Coaster http://www.chinawholesaletown.com/wholesale-Newtons-Cradle/ Pet Supplies Wholesale Clothes Rack
      Wholesale Whistle http://www.chinawholesaletown.com/wholesale-Water-Power-Clock/ Beach Towel Water Bottle
      Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Level-Tape-Measure/ Bottle Holder Teeth whitening Pen
      c http://www.chinawholesaletown.com/wholesale-Gashapon---Capsule-Toy-Empty-Shell---Easy-Open_95643/ Poncho Keychain Poncho Keychain
      Promotional Products http://www.chinawholesaletown.com/wholesale-Alcohol-Tester/ Wholesale Toys Water Filter Bottle
      Wholesale Mug http://www.chinawholesaletown.com/wholesale-Golf-Putting-Set/ Lunch Box Sport Items
      Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Electric-Heating-Mugs/ Heating Products Waterproof Beach Case
      Wholesale Stationery http://www.chinawholesaletown.com/wholesale-ID-Tag/ Permanent Match Lighter Electroluminescent
      Wholesale Towel http://www.chinawholesaletown.com/wholesale-Shopping-Basket/ Wholesale iPod iPhone Wholesale Earphone
      Wholesale Banner http://www.chinawholesaletown.com/wholesale-LED-Keychain-Light/ Promotional Gifts Wholesale Massager
      Electrical Gifts http://www.chinawholesaletown.com/wholesale-Back-Scratcher/ Bar Caddy Money Bank
      Bingo Bag http://www.chinawholesaletown.com/wholesale-Frosty-Beer-Mug/ Water Spray Fan Wholesale Badge
      Wholesale Album http://www.chinawholesaletown.com/wholesale-Lunch-Box/ Wholesale Waterproof Case Bottle Opener
      Recorder Pen http://www.chinawholesaletown.com/wholesale-Abacus/ Wholesale Wallet Wholesale Memory Card
      Wholesale Keyboard http://www.chinawholesaletown.com/wholesale-Wedding-Favors/ Wholesale Accessories Money Clip
      Wedding Coaster http://www.chinawholesaletown.com/wholesale-Decision-Maker/ Wholesale Tellurion Wholesale Bedding
      Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-Metal-Money-Bank/ Highlighter Pen Waterproof Hard Case
      Menu Holder http://www.chinawholesaletown.com/wholesale-Wine-Bottle-Cover/ Abacus China Wholesale
      Wholesale Memory Card http://www.chinawholesaletown.com/wholesale-Multifunction-Pen-Holder/ World Cup Products Highlighter
      Wholesale Pedometer http://www.chinawholesaletown.com/wholesale-Lighter-Bottle-Opener/ Glass Coaster Silicone Bakeware
      Wholesale Flag http://www.chinawholesaletown.com/wholesale-Collapsible-Water-Bottle/ Silicone Cake Mould Wholesale Tellurion
      Home Appliances http://www.chinawholesaletown.com/wholesale-Leather-Clock/ Wholesale Helmet Wholesale Mat
      Fleece Blanket http://www.chinawholesaletown.com/wholesale-Badge-Reel/ Wholesale Cap Wholesale Glasses
      Wholesale Vase http://www.chinawholesaletown.com/wholesale-Desk-Calendars/ Wholesale Kitchenware Wholesale Furniture
      jywhy888
    • RE: NASA hack

      But wait..
      Those $200 toilet seats can be had for $5 @ Wally World now.
      Just think how much our government can save!
      sfaid
  • Rehashing Old News

    House Committees, especially when they are Republican-led, are usually worse than a GONBS (Guy on next barstool) in terms of, shall we say, "completeness" in releasing supposedly investigative reports. In this case, they seem to be rehashing bit and pieces from already publicly available, and much more detailed audits and reports from last year, especially one from late last spring rather descriptively titled "Inadequate Security Practices Expose Key NASA Network to Cyber Attack"
    JustCallMeBC
  • This is why it is imperative to proceed with the 'smart grid'

    All of our utilities, including electricity, natural gas and water, should be accessible from the internet. Without delay!
    Rabid Howler Monkey
  • Only 47 yeah right ok NOT

    Let's see NASA only decided to acknowledge 47 attacks, how many do you suppose they don't know about? And perhaps the title of this article should be (what happens to unencrypted NASA notebook computer).

    And of course at the end, I take great confidence in knowing that NASA is taking advice on fixing these problems from the NASA Inspector General.

    I'm to guess that this Inspector General is a new position recently concocted, because if this person was there at the time, they should have had these changes in place. And only 1 percent of NASA mobile devices are encrypted? That's too funny.
    deafears
  • that's the price paid

    for not using FOSS!
    The Linux Geek
  • sdfd

    Crystal Gifts Lunch Box http://www.chinawholesaletown.com/wholesale-CD-Holder/ Sport Items
    Wholesale T-Shirts Name Card Holder http://www.chinawholesaletown.com/wholesale-Money-Clip/ Electrical Gifts
    Computer Accessories Wholesale Ashtray http://www.chinawholesaletown.com/wholesale-Muslim-Products/ Silicone Products
    Wholesale Cooler Wholesale Fan http://www.chinawholesaletown.com/wholesale-Tableware/ Personal Safety Products
    Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
    Lighting Products Wholesale Tellurion http://www.chinawholesaletown.com/wholesale-Socks/ Giveaway Material
    Photo Frame Pet Supplies http://www.chinawholesaletown.com/wholesale-Hardware-Tools/ Compass
    Water Bottle Medicine Instrument http://www.chinawholesaletown.com/wholesale-Calendar/ Stapler
    Wholesale Shoe Wholesale lable http://www.chinawholesaletown.com/wholesale-Computer-Keyboard/ China Wholesale
    Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
    Wholesale Hardware Tools Wholesale Umbrella http://www.chinawholesaletown.com/wholesale-Towel/ Clothing
    Wholesale Keyboard Business Gift http://www.chinawholesaletown.com/wholesale-World-Cup/ Tag
    Wholesale Glass Book Light http://www.chinawholesaletown.com/wholesale-Bedding/ Patient Care Products
    Promotional Gifts Digital Photo Frame http://www.chinawholesaletown.com/wholesale-Outdoor---Leisure/ Outdoor Leisure Products
    Wholesale Raincoat Wholesale Glass http://www.chinawholesaletown.com/wholesale-Mobile-Phone/ Waterproof Case
    Stuffed Animals Audio Video Equipment http://www.chinawholesaletown.com/wholesale-Pure-Cotton-Compressed/ Kitchenware
    Coca Cola Gifts Wholesale Belt http://www.chinawholesaletown.com/wholesale-Coca-Cola-Gifts/ Mouse
    Heating Products Wholesale Cooler http://www.chinawholesaletown.com/wholesale-Automotive-Products/ Carabiner
    Beauty Equipment Wholesale Toys http://www.chinawholesaletown.com/wholesale-Christmas-Gifts/ Socks
    Pet Supplies Wholesale Bedding http://www.chinawholesaletown.com/wholesale-Crystal-Gifts/ Candle
    Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
    Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
    Wholesale Bag Wholesale Scissors http://www.chinawholesaletown.com/wholesale-Wallet/ Vuvuzela
    Wholesale Waterproof Case Wholesale Cup http://www.chinawholesaletown.com/wholesale-Electrical-Gifts/ Bracelet
    Wholesale Ashtray Wholesale Vuvuzela http://www.chinawholesaletown.com/wholesale-Mug/ Wine Set
    Wholesale Massager Wholesale Watch http://www.chinawholesaletown.com/wholesale-Frisbee/ Clap Hands
    Muslim Products Wholesale Tie http://www.chinawholesaletown.com/wholesale-Umbrella/ TelePhone
    Wholesale Tag Promotional Products http://www.chinawholesaletown.com/wholesale-Personal-Safety/ Camera
    Safety Suppliers Wholesale Shoe http://www.chinawholesaletown.com/wholesale-Stress-Ball/ Magnifier
    Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
    Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
    Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
    Wholesale Stress Ball Wholesale Mug http://www.chinawholesaletown.com/wholesale-Clocks/ Lunch Box
    Medicine Instrument Wholesale Jewelry http://www.chinawholesaletown.com/wholesale-Eye-Masks/ Playing Card
    Wholesale Scissors Arts Crafts http://www.chinawholesaletown.com/wholesale-Reflective-Safety-Vest/ Safety Suppliers
    Wholesale Stapler Wholesale Calculator http://www.chinawholesaletown.com/wholesale-Badge---Pin/ Puzzle
    Wholesale Dartboard Wholesale Lanyard http://www.chinawholesaletown.com/wholesale-Toys---Games/ Tellurion
    jywhy888
  • Wha happened??

    First, I thought NASA was closing down. Why are they so interested in secrets from a skeleton agency? Second, how is it that America is not prepared, and properly defended against, attacks like this? Is Chinese (or whomever's) IT so much further along than ours that we can just say "oops, wha happened?".....this is ridiculous.
    James Keenan
  • Tell OIG to Listen to Richard Clarke

    Per another ZDNet blog:
    Richard Clarke: China has hacked every major US company

    This is only the tip of a HUGE iceberg.

    It is cyberwar if any substantial proportion of the 47 NASA breaches are all from a single country.

    Be informed.
    Any small high-tech Co CEO's with good technology in house? Get protected!
    daves1646
  • Cyber War?

    We haven't got there yet.
    We still prefer to put soldiers on the ground in some foreign country to be blown up, and mentally traumatized at a lifetime cost of a couple million each on average.
    We should be paying little Johnny Hacker +$70k a year at 18 to sit home and hack the 4377 out of China. Crash everything in China that is network accessible!
    They complain, bring our cards to the table with proof they are doing it to us.
    sfaid
    • Fight fire w/fire...?

      Well, SFAID, you're right about the use of our military and I certainly think that we (the U.S.) need to be MUCH better prepared, defended, and educated than we are regarding cyber security. But at the same time, I'm not sure that paying "little Johnny Hacker" to stick his red, white, and blue finger in China's eye is the best answer (although it would be fun as "4377"...)

      What if we (aka "politicians") spent as much time and money on securing our internet infrastructure as we ("they") do on trying to regulate it and make a profit from it? Or, just for $h!+s and grins, maybe we could actually EDUCATE instead of MEDICATE our children so that when Little Johnny grows up, he'll have the intellectual capacity to save us from ourselves... sigh, so much to do, so little potential to get it done...
      BET7139
  • Security

    This is not the 1st goverment agency that does not encrypt their data. IRS,FBI and the DOD just to name a few. Encrypting is easy to do and it makes it difficult to crack. Why won't they do it is beyond me. Even Microsoft offers some encryption on Windows Vista and all operating systems since.

    Pretty sad :(
    pc boss