Hacked British Royal Navy site sinks

 

Hacker claims to breach site security.

The British Royal Navy website remained down this morning after a hacker claimed to have successfully exploited the site and its underlying database yesterday.

An attacker going under the web pseudonym TinKode stated in a blog to have compromised the website with an SQL injection attack this weekend.

TinKode claimed to have accessed both usernames and passwords to different sections of the website, although the Royal Navy has refuted the suggestion any classified information was taken.

The Royal Navy admitted the site was compromised, but said no “malicious damage” was caused.

The website has been suspended as a precaution while security teams investigated, a spokesperson added.

Visitors to www.royalnavy.mod.uk today were greeted by a message reading: “Unfortunately, the Royal Navy website is currently undergoing essential maintenance. Please visit again soon.”

The news comes not long after the  BritishGovernment ranked cyber defence as one of the most important areas of national security, placing it alongside international terrorism and military crises.

The Coalition also recently announced an extra £500 million (AU$795 million) funding for cyber defence, along with £900 million (AU$1.4 billion) towards targeting tax evaders and fraud with better use of technology.

Jason Hart, senior vice president in Europe for two-factor authenticaton provider CRYPTOCard, said the hack had wider implications for the security sphere.

"The fact that a high profile military website can be targeted shows the underlining issues facing organisations and the threat of cyber crime," Hart said.

"Fundamentally this shows that the basic forms of attack can still be executed successfully on very secure sites through the simple tools to obtain the username and password."

Graham Cluley, senior technology consultant for Sophos, labelled the hack “embarrassing.”

“If someone with more malice in mind had hacked the site they could have used it to post malicious links on the Navy's JackSpeak blog, or embedded a Trojan horse into the site's main page,” Cluley said in a blog.

“It is to be hoped that the extent of this attack will be egg on the face of the Ministry of Defence, rather than a more significant assault on a website presenting the public face of an important part of the armed forces.”

This article originally appeared at itpro.co.uk

Copyright © ITPro, Dennis Publishing


Hacked British Royal Navy site sinks
"oops, copy and paste error! Thanks @scan06disk"
By BrettWinterford
 
 
 
Comments: 2
scan06disk
Nov 10, 2010 8:18 AM
might wanna change this "£900 million (AU$796 million)"...
BrettWinterford
Nov 10, 2010 11:59 AM
oops, copy and paste error! Thanks @scan06disk
Comments have been disabled for this article.
 
 
 
Top Stories
Australian miners send drones to work
In-depth: Unmanned aerial vehicles in the resources sector.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  20%
 
No
  80%
TOTAL VOTES: 507

Vote