Royal Navy Website hacked!!

Discussion in 'Current Affairs' started by yamyamdabber, Nov 6, 2010.

    Highlights the usual laxadaisical attitude to IT security but the main danger this would present is showing the navy in a bad light. The site itself is meant for PR and recruiting purposes only, it's not like a hack would be able to tunnel into any C4ISTAR systems is it?
  2. Its probably a civvie that runs it anyway! Either which way they have had there weekend screwed seen as the site is "down for essential mantainance at the minute"!
    I have admin access to the RM forum on the Royal Navy site, so for all I know my account has been hacked also, depsite a relatively secure random password.

    All it does is simply bugger-up a public service information site with non-critical data in the name of notoriety & infamy. If the hacker had an ounce of intelligence beyond a quest for celebrity, they could earn a living out of it working for the online financial banking institutions, rather than simply cause malicious damage to non-critical data.
  4. That would be sensible though NS, even though i have heard that this will affect waiting times! :)
    Rather amusingly, the item about the hacker states that they were able to access a section called "Global Operations" & gasp... bloggs too.

    Somehow it's doubted Northwood is in a flap about the previous positions of submarines & surface ships reported in the Navy News, (page two) also, which can be readily accessed at your local WH Smiths & all good newspaper vendors. If they accessed a bit of the intranet, rather than public internet, particularly the page with a big red button marked "Trident launch" then it would perhaps be a little more significant.
  6. Hmm,

    'The public disclosure was made by a Romanian self-confessed security enthusiast who uses the online handle of "TinKode."

    The grey hat hacker specializes in finding Web vulnerabilities like SQL injection and cross-site scripting.'

    Grey Hat = Publicity seeking loser who really has not got the skills or knowledge to be hired by a large banking institution and become a 'White hat'. Normally laughed at by 'Black hat' community

    SQL injection/Cross site scripting vunerabilities = Script kiddie

    Script kiddie = loser who does not have the skills or knowledge to identify their own exploits or vunerabilities and relies on skill and experience of black hats.
    Black Hats - competent hackers who normally have severe ego/willy size problems and should be ditched out of a Hercules somewhere over the Atlantic. (Criminal fecking Losers).

    TinKodes previous 'attacks' have been similarly pointless attacks against nothing but PR websites. Embarrassing yes but easy enough to correct once the 'functionallity over security' techies have been sent to the naughty step and told to STFU.

    Hopefully someone will be being kicked in the goolies while being forced to ensure that the site now suitably hardened.

    Love things like this, makes my job more in demand and secure in the current economic climate :) Apart from that bit of a non-story.
    Really, who by?
  8. Meaning what exactly?

    RN reputation is RN reputation, whether it's a civilian expert who does web managing as a career or RN personnel doing the job for two years before shuffling off to do something else.
  10. FFS Normong, get some feckin pile ointment and cheer up. Have you always been a miserable whining spastic or did it come on suddenly?
    Perhaps you should join an euthanasia group instead of coming on here and acting the cunt.
  11. :lol: :lol: :lol: Don't hold back - say what you mean!
  12. Apologies!
  13. I forgive you mate, time difference and all that. :)
  14. Thanking you, it's like being on 'dial up' too which does'nt help!
    It's a non news story being whipped into something. Mr Clueless from SOPHOS calling it a major embarrasment for MOD is a bit rich; wonder if he realises it's operated by a civilian company and has no links to any operational system nor contains any personal data?

    At worst its a minor blip, whoopee
  16. Contains plenty of personal details. I'm sure it wouldn't be too hard for the guy to get the passwords on the PRMC forum, use the email address's they signed up with, see if the passwords for the forum and your email are the same and hey presto your email is compromised.

    Even if he just got your email it could be a bit shirt.

