Web attacks continue'this time, pranksters prey on Army's site

Web attacks continue'this time, pranksters prey on Army's site

By Bill Murray

In the first successful attack on the Army's main Web site, hackers on Sunday, June 27, replaced the default page. The fraudulent page was up for at least 13 hours before officials restored the correct version.

Service officials have installed safeguards at www.army.mil, but 'we can only do so much,' said Lt. Col. William L. Wheelehan, an Army spokesman. 'It's a nuisance. That's all it is.'

Invasion route

The hackers exploited a vulnerability in the site's ColdFusion application, he said.

ColdFusion is a Web development environment from Allaire Corp. of Cambridge, Mass. The company in a May 19 e-mail security bulletin advised ColdFusion users to remove sample programs and code installed by default into a particular Allaire directory that made sites potential targets.

The hackers' vandalism included messages in white lettering, such as 'trust very few people,' and 'this site lies to people,' Wheelehan said. One message referred to a loosely knit hacker group that the FBI has targeted in its recent hacker crackdown.

'The impact was probably minimal,' as the site was back up by 6:08 a.m. on Monday, June 28, he said. The site has the most traffic during business hours, he said.

The importance of delivering information to the public through the site outweighs the limited security risks, Wheelehan said.

'No classified information was compromised. ' We don't believe this was an example of cyberwarfare,' he said. Even so, Criminal Investigation Division officials in the Army Computer Emergency Response Center are probing the attack, he said.

inside gcn

  • machine learning

    Mitigating the risks of military AI

Reader Comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group