Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
The Internet Government United States Technology

Unpatched US Government Website Gets Pwned By Pro-Iran Script Kiddie (arstechnica.com) 87

An anonymous reader quotes a report from Ars Technica: On the heels of the killing of Iranian Revolutionary Guard Corps General Qassem Soleimani by a U.S. MQ-9 Reaper strike on January 2, the U.S. Department of Homeland Security warned of potential cyberattacks against critical infrastructure by Iran. That warning probably didn't apply to the website of the Federal Deposit Library Program, operated by the U.S. Government Printing Office -- which was defaced on January 4 with a pro-Iranian message and an image of a bloodied President Donald Trump being punched by an Iranian fist.

The FDLP website is no stranger to defacement attacks. As a brief analysis of the attack by a security researcher with the Twitter username @sshell_ noted, the site has been defaced twice in the last 10 years -- most recently in 2014, when it was replaced with an electronic dance music video featuring a dancing cat. Based on a fingerprint of the site's files, the site -- based on the Joomla content management system -- had not had its code updated since 2012. And the site had modules that used a version of Joomla's RSForm that had been flagged 11 months ago as being vulnerable to a SQL Injection attack. While the image depicting Trump had no metadata attached to it, another image with text had Exchangeable Image File Format (EXIF) data indicating it had been created with Adobe Photoshop CS 6 for Windows in 2015. As sshell_ noted, the image was used in a defacement reported to the "cybercrime archive" Zone-H by a user identifying themselves as IRAN-CYBER on December 2, 2015.
A DHS spokesperson for the Cybersecurity and Infrastructure Security Agency (CISA) said that "there is no confirmation that this was the action of Iranian state-sponsored actors."
This discussion has been archived. No new comments can be posted.

Unpatched US Government Website Gets Pwned By Pro-Iran Script Kiddie

Comments Filter:
  • by NewtonsLaw ( 409638 ) on Monday January 06, 2020 @03:32PM (#59593176)

    Trump boasts that the USA has spent trillions on defense but I guess they ran out of money for software updates eh?

    I'd much rather that Iran's response was in the form of posting pretty pictures than something more tangible and violent. So far so good!

    • Comment removed based on user account deletion
      • Iran is sexually frustrated, that's all.

        Really? Their population growth rate is over 1 percent...

        Whatever, the story is war mongering bullshit, "Pro-Iran"? Please!

    • by OzPeter ( 195038 )

      Trump boasts that the USA has spent trillions on defense but I guess they ran out of money for software updates eh?

      I'd much rather that Iran's response was in the form of posting pretty pictures than something more tangible and violent. So far so good!

      Regardless of who did this*, this was the lowest of the low hanging fruit. A much smarter move would be to not telegraph your capabilities and surreptitiously install hacks and then wait for the right moment to trigger them.

      -----

      * It could have been Iran, or it could have been another state actor pretending to be Iran and seeing a fun opportunity present itself

    • I'd much rather that Iran's response was in the form of posting pretty pictures than something more tangible and violent. So far so good!

      Do you think the lack of a violent response is due to a rational and reasonable decision on the part of the Iranians?

    • by Freischutz ( 4776131 ) on Monday January 06, 2020 @04:07PM (#59593322)

      Trump boasts that the USA has spent trillions on defense but I guess they ran out of money for software updates eh?

      I'd much rather that Iran's response was in the form of posting pretty pictures than something more tangible and violent. So far so good!

      The Iranians have to come up with something spectacular but victimless that does not trigger the full blown war Trump wants for his 2020 election campaign. Doing things like using cyber attacks to take down the electrical grid in parts of the US would probably serve that purpose. If this does end in a war I sure hope that they draft the Trump supporters first as cannon fodder for the ground invasion of Iran, they are the ones who got us into this mess. The Israelis can also contribute some boots, Netanyahu has been itching for a war with Iran for years although I think his plan has been for the US to pay for it, US troops to do the fighting and US troops to do the dying.

      • by gtall ( 79522 )

        You got the Israel part backwards. Iran has been bucking for a war with Israel down to the last Arab (Iran is Persian). They'll be safely behind them 100%. First up in the cannon fodder line will be Hezbollah, but even Nasrallah isn't stupid enough to put his balls out there where Israel will be happy to step on them. Rather, Iran will use their useful idiots in Syria to take a few pot shots, Israel will take a few pot shots back and that will be that. Unless La Presidenta Tweetie does something further tha

        • Re: (Score:3, Informative)

          by Freischutz ( 4776131 )

          You got the Israel part backwards. Iran has been bucking for a war with Israel down to the last Arab (Iran is Persian).

          While I appreciate the loyalty to Israel that compels you to whitewash them of any blame in the mess that is the Middle East conflict I feel compelled to point out that when two people are feuding it is never just one of them that is to blame. Just because I pointed out how the Israelis are itching for (the USA) to go to war with Iran because they themselves don't have the capability to do it themselves does not mean that I'm in denial about how much Iran hates Netanyahu's Israel. From a dispassionate Machi

        • No one cares about impeachment except the far far far left who dream something will come of it, somehow, this time will be it after the previous zillion attempts to get rid of trump came to nothing. And Trump tweets about it like he tweets about everything else where the left are trying to crazy shit. Nothing new there. This pos got killed because he just arranged a large attack on our embassy and was in town to plan more attacks. Exactly when do -you- think would have been a "good" time to kill him? M
      • You're crazy ignorant if you think this is going to turn into a massive land war. I laughed out loud when I read that stupid genz are crashing Fed websites trying to get information on the draft. The days of drafts are over. By the time any country could call up, train, arm, and ship enough kids to anywhere the war they were drafted for would be long over. It's ridiculous nonsense. Boots? Lmao, omg.... too funny. Iran will do what it has been doing since 79: use proxy forces they've trained and armed
    • More troubling than anything is the outpouring of support for the Islamic Republic of Iran, a fascist theocratic imperialist state that just got through murdering thousands of its own citizens who rose up in protest.

      They went straight on supporting Shiia militias in Iraq trying to undermine Iraq's own governing structures to gain influence there, ethnically cleansed Sunni areas under the guise of fighting ISIS, and are a major reason why Assad has survived by supporting his violent oppression of his peopl

      • by cusco ( 717999 )

        Iraq's own governing structure? You mean the puppet government that the US put in power? May as well stop reading there.

    • Honeypot?
    • by Jeremi ( 14640 )

      Trump boasts that the USA has spent trillions on defense but I guess they ran out of money for software updates eh?

      Trump demanded they change update providers:

      "It sounded bad to me. Digital. They have digital. What is digital? And it's very complicated, you have to be Albert Einstein to figure it out. [...] I said, 'What system are you going to be--' 'Sir, we're staying with digital.' I said, 'No you're not. You going to goddamned Steam [steampowered.com], the digital costs hundreds of millions of dollars more money and it's no good.'"

  • by Tinsoldier314 ( 3811439 ) on Monday January 06, 2020 @03:50PM (#59593252)
    Not necessarily a bad thing if a bunch of independent script kiddies expose of our weak points but otherwise cause little harm.
  • I see the federal deposit library program as critical infrastructure under threat of attack. And throwing up a cat video isn't exactly p0wning when if they had really cracked the site they could have ordered 10M paper copies of the Mueller report be delivered to the White House. I have significant agita that a response on the part of Iran will lead to a disproportionate escalation on the part of Trump, so if this is their response, I'm fine with it. Trump can respond by tweeting something angry, and we'l
  • To get serious (Score:4, Interesting)

    by AlanObject ( 3603453 ) on Monday January 06, 2020 @04:00PM (#59593288)

    If pro-Iran hackers really wanted to strike back what they should do is break into every one of the private e-mail servers in use by Trump, his kids, and cabinet members and staff. You know -- the kind that they wanted to "lock her up" for?

    I am sure there is enough material there to do more damage than any physical attack anywhere.

    • by MightyMartian ( 840721 ) on Monday January 06, 2020 @04:05PM (#59593310) Journal

      They could break into Donald Trump's Twitter account and start posting sensible, rational, coherent tweets. The GOP would probably collapse at that point.

      • by Tablizer ( 95088 )

        break into [his] Twitter account and start posting sensible, rational, coherent tweets...

        I'd panic also. It could mean the "new" President had become an avatar.

        (Although, rumor has it the current one is a child avataring in an adult's body. It happens. [fandom.com])

        • break into [his] Twitter account and start posting sensible, rational, coherent tweets...

          I'd panic also. It could mean the "new" President had become an avatar.

          I'm not seeing the downside.

      • by Livius ( 318358 )

        They could break into Donald Trump's Twitter account and start posting sensible, rational, coherent tweets.

        Would Trump deny responsibility or take credit? And would people believe him or not believe him if he did one or the other?

        • They could break into Donald Trump's Twitter account and start posting sensible, rational, coherent tweets.

          Would Trump deny responsibility or take credit?

          Yes

          And would people believe him or not believe him if he did one or the other?

          Yes

    • by AmiMoJo ( 196126 )

      They have been targeting Trump properties for decades. That's why they ask have bed bugs, design reminiscent of Saddam's abandoned palaces and smell of elderberries.

  • and now that Kiddie can face adult solder time.

    But will that be in an nice POW camp with an get out free when the war is over?

    • by cusco ( 717999 )

      Adult solder time? What will he be soldering? Do you think he'll be a better hardware hacker than he was a script kiddie? :-)

      • Is an state hacker an soldier under the Geneva convention??

        • by cusco ( 717999 )

          Ah, you didn't see the misspelling, 'solder' for 'soldier'.

          No, I don't believe that a hacker would be considered a soldier under the Geneva Convention unless they're uniformed, no more than a janitor at the Pentagon would be.

          • Persons who accompany the armed forces without actually being members thereof, such as civilian members of military aircraft crews, war correspondents, supply contractors, members of labour units or of services responsible for the welfare of the armed forces, provided that they have received authorization from the armed forces which they accompany, who shall provide them for that purpose with an identity card similar to the annexed model.

        • Comment removed based on user account deletion
  • they've attack our soil. Time to start WW3.
  • This seems like a site that is designed to be taken over by any enemy who wishes harm to us. It's not that important, and not patched up to date in years. Now we have proof Iran wants to mess with our IT... shields up everyone!

  • Where's the link to the electronic dance music video featuring a dancing cat?

  • by nospam007 ( 722110 ) * on Monday January 06, 2020 @05:26PM (#59593588)

    Some Iran-Americans got blocked or flatly refused entry at the Canadian border when they tried to get home from a concert so I guess Trump and his goons will open new concentration camps for the 2 million living in the US, they still have the plans from when they did it to the Japanese during WWII.

    • by ebvwfbw ( 864834 )

      The facsist democrats in Virginia are preparing to lock people up for not following their new gun seizure scheme. They actually said they were increasing the budget to put Virginians in jail.

      Democrats/socialist/communists/fascist put people in concentration camps. Look at your history.

  • by deviated_prevert ( 1146403 ) on Monday January 06, 2020 @05:28PM (#59593598) Journal
    The actions of the US government in 1953 in support of the oil industry are still the reason why we see the majority of Iranians hating America. In the very same year the CIA was busy with the same tactics overthrowing the legally elected government of Honduras so that the oppressive American Fruit industry could abuse cheap labour and at the same time control the use of land in Honduras. The same shit was happening in Cuba and elsewhere.

    The tactics of the CIA under the thinly veiled guise of "fighting international communism" is in reality the huge lie which any sane individual can see through. The reality is that the tactics used by players like E. Howard Hunt and the others in the CIA are just another form of fascism in disguise. I do not know if the US can dig itself out of the hole it has created since the inception the CIA, I fear the hatred of what the CIA has done internationally even where undeserved is too strong. The Russians are certainly no better bed fellows in this regard but the damage done by the cold war and corporate sponsored international anti democratic actions by the CIA runs deep. People are not stupid they know who is stopping democracy, it matters little whether it is the actors in the CIA or what was the KGB the truth about what is really happening is well understood by the common folk.

    I am deeply afraid that the situation this time around cannot be resolved until the US owns up to the crimes it has committed against democracy. And finally stops supporting corporate and economic terrorism world wide.

    • by cusco ( 717999 )

      Well, there was the action in 1953, but also supporting the Shah while he massacred 8-10% of the population of the country, then feeding chemical weapons to Iraq during the Iraq/Iran war as well feeding both sides intel to keep the war going longer, and most recently the illegal embargoes that have given a gut-punch to the local standard of living. The Iranians have lots of reasons to hate the US government, although surprisingly they seem to hold little to no acrimony against the regular US citizens.

      • The Shah did not do any massacres ....
        During the Iran/Iraq war, he was long disposed ... so he could not feed any chemical weapons to anyone.
        And your posts makes double plus ungut no sense: as the Shah was the ruler of Iran ... so why the funk would he give chemical weapons to Iraq and sent intel to both of them?

        • by cusco ( 717999 )

          The Shah's secret police killed or disappeared tens of thousands, the police and military ran rampant and killed with impunity, and the minority groups were subject to repeated massacres any time they stepped out of line. Protests were machine gunned. Of course we didn't hear about that in the west, since the Shah was "our" ally he had to be a a good guy after all. Remember, we didn't hear about the 'disappeared' in Argentina until the Junta had been removed, or even about East Timor until Suharto was lo

          • The Shah's secret police killed or disappeared tens of thousands, No, they/he did not.
            the police and military ran rampant and killed with impunity, and the minority groups were subject to repeated massacres any time they stepped out of line. nope.
            Protests were machine gunned. nope.

            Actually the only ones who protested were former nobility from which he took the land and distributed it to the poor.
            The Shah was a Robin Hood for Iran. There were no protests big enough that a machine gun would be useful.

            He was

    • by jonwil ( 467024 )

      If the US (and UK) had not overthrown the democratically elected leader of Iran in order to protect the British AIOC oil company (which would later become BP) then Iran likely wouldn't be a problem (or an Islamic dictatorship)

    • by twosat ( 1414337 )

      “I spent 33 years and four months in active military service and during that period I spent most of my time as a high class muscle man for Big Business, for Wall Street and the bankers. In short, I was a racketeer, a gangster for capitalism. I helped make Mexico and especially Tampico safe for American oil interests in 1914. I helped make Haiti and Cuba a decent place for the National City Bank boys to collect revenues in. I helped in the raping of half a dozen Central American republics for the benef

  • That site gets dozens of visitors. Dozens!
    therearedozensofus.jpg

Never test for an error condition you don't know how to handle. -- Steinbach

Working...