European Space Agency Website Hacked

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
The website of the European Space Agency (ESA) has been hacked into and a list of FTP accounts, as well as email addresses and passwords for administrators and editors have been leaked.

The www.esa.int Web server was compromised by a well known Romanian grey hat hacker who uses the online moniker of TinKode.

The hacker posted details of the compromise on his blog in full disclosure style. However, the method he used was not revealed.

The published data includes FTP accounts for a range of ESA subsites with passwords in clear text.

A list of database users with hashed passwords was also disclosed, together with the SHA1-hashed server root password.

The site administrator and editor credentials were exposed in plain text, as well as email addresses and passwords corresponding to website user accounts.

The passwords are in readable form, but TinKode took the measure of partially hiding them before publishing. There is also a list of associated proxy user names and passwords.


More details - link
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
That is very bad...passwords for people to read
 

LoftedAphid86

New Member
Feb 24, 2011
1,107
I seriously wonder why all of these high key sites don't take further steps to stop this happening to their site.
Even anonymous have been thwarted by high security, yet sites don't seem to follow in the survivor's footsteps.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Yet password/usernames and other sensitive information are leaked. Seriously they must fixed that.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
They need to buck up the way they have their security
 

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Seems like the hackers are from my country (Romania) ... I wonder how they managed to get access to the FTP accounts:D
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Probably they guess some passwords and when they typed it activated or something using a tool for there.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top