Welcome | Sign In
TechNewsWorld.com
Security

Military Secrets Discovered on Unprotected Web Sites

Print Version
E-Mail Article
Reprints
Military Secrets Discovered on Unprotected Web Sites

A security gap has allowed dozens of secret military documents to appear on the Internet, unguarded and for anyone with the right FTP address to access. The documents include plans for air bases and national laboratories. While one would have to know the exact location of the documents in order to find them, hackers are known to continually run scanners looking for open FTP sites.


Dozens of documents containing classified information that could affect the safety of U.S. troops in Iraq and Afghanistan have been posted on unprotected servers by military agencies and related companies, according to a survey by the Associated Press.

The AP, abetted by work done by Christopher Freeman, a Greensboro, N.C, resident who has been tracking this practice, downloaded several documents containing classified information that had been stored on FTP (file transfer protocol) servers.

Wealth of Information

These included the following, according to the AP:

  • Several documents on a contractor's server detailed a project to expand the fuel infrastructure at Bagram Air Base in Afghanistan, including a map of the entry point to be used by fuel trucks and the location of pump houses and fuel tanks.
  • A document from the Army Corps of Engineers that contains 61 pages of photos, graphics and charts that map out the security features at Tallil Air Base in southeastern Iraq. It also depicts proposed upgrades to the facility's perimeter fencing.
  • Aerial surveys of military airfields near Balad and Al Asad, Iraq, on the National Geospatial-Intelligence Agency server.
  • Detailed maps of buildings and infrastructure at Fort Sill, Okla., were posted on Benham Companies site.
  • Material from Los Alamos National Laboratory and Sandia National Laboratories.

Most of the agencies shut down the servers in question when contacted by the AP.

Not Surprising

It is not a surprising development.

What most likely happened, speculated Paul Moriarty, director of Internet content security for Trend Micro (Nasdaq: TMIC), is that someone needed to share large data files and they were too big to e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse. "So they used the FTP protocol," he told TechNewsWorld. Setting it up so it requires password protection can be tricky, but opening up for anonymous access, he said, is relatively simple.

"Maybe the person intended to take it down later but forgot," Moriarty added.

Workers tend to take shortcuts that make their jobs easier, he also observed. "That is human nature. What they don't realize is that there are hackers out there that are continually running scanners looking for open FTP sites."

Over the Hump

Secure computing habits or practices do not seem to improve even as government agencies and companies become more sophisticated in their use of computers, Roger Thompson, CTO of Exploit Prevention Labs told TechNewsWorld.

"The number of users that keep increasing is one problem," he noted. "Another problem is that computers have become so much a part of the business environment it is almost impossible to make rules for every action or scenario."

Common sense does not always fill the gap, he added.

Out of Sight, Out of Mind

Also, end users, unless they are directly involved in IT security, do not tend to really believe the worst projections by security analysts unless they can actually see the impact first hand, David Perry, global director of education for Trend Micro, told TechNewsWorld.

"The threats they believe in are the ones they can see -- the damage that spam can cause for instance," he said, pointing to a recent study by the company found that corporate users are more concerned with spam levels than Web threats, despite spam's decline (84 percent in 2005 and 72 percent in 2007) and a 540 percent increase in Web threats, likely due to the silent and invisible nature of new infections.

Yet employees take the security precautions about spam more seriously.

"But try telling them about need for firewall or keeping information off of unsecure severs, and they dismiss the warnings," Perry said.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network