All your base are belong to us (Well at least your FTP servers)
The AP reports today on a rather stunning display of internet idiocy by various DoD entities and military contractors. Posting and leaving sensitive information on unsecured anonymous FTP servers.
GREENSBORO, N.C. - Detailed schematics of a military detainee holding facility in southern Iraq. Geographical surveys and aerial photographs of two military airfields outside Baghdad. Plans for a new fuel farm at Bagram Air Base in Afghanistan.
The military calls it “need-to-know” information that would pose a direct threat to U.S. troops if it were to fall into the hands of terrorists. It’s material so sensitive that officials refused to release the documents when asked.
But it’s already out there, posted carelessly to file servers by government agencies and contractors, accessible to anyone with an Internet connection.
In a survey of servers run by agencies or companies involved with the military and the wars in Iraq and Afghanistan, The Associated Press found dozens of documents that officials refused to release when asked directly, citing troop security.
Such material goes online all the time, posted most often by mistake. It’s not in plain sight, unlike the plans for the new American embassy in Baghdad that appeared recently on the Web site of an architectural firm. But it is almost as easy to find.
And experts said foreign intelligence agencies and terrorists working with al-Qaida likely know where to look.
Yeah guys lets not make an effort to secure our servers against people who have already shown bot that they know how to use the internet and are willing to do so. I’m not talking downloading camel porn either. Al Qaeda routinely communicates via the web, and a number of cyber attacks have been reported on anti-jihadi websites.
And it’s not like the military was unaware of the risk, in 2003 Timothy L. Thomas published an article in Paramaters, the US Army War College Quarterly, which specifically mentioned intelligence gathering and the stealing of information as a risk associated with internet use by extremist groups.
Some more examples of security brilliance:
61 pages of photos, graphics and charts map out the security features at Tallil Air Base, a compound outside of Nasiriyah in southeastern Iraq, and depict proposed upgrades to the facility’s perimeter fencing. several sensitive documents, including aerial surveys of military airfields near Balad and Al Asad, Iraq, on its server. aerial photographs and detailed schematics of Camp Bucca, a U.S.-run facility for detainees in Iraq. One of the documents was password-protected, but the password was printed in an unsecure document stored on the same server. They showed where U.S. forces keep prisoners and fuel tanks, as well as the locations of security fences, guard towers and other security measures.
OK to give the Devil his due the holes were plugged when AP pointed them out, and so far no actual attacks resulting from this information have been reported, but you would think people would be a little more careful with it.
Read the article, even if you aren’t worried about terrorist attacks it’s an eye opener on some basic network security issues.
Similar Independent Sources posts:
- Michigan’s problem isn’t a lack of money, it’s an excess of idiocy: So says the Detroit News in response to the state legislature's plan to purchase an iPod for every schoolchild in Michigan. We have come to the c ...
- Ukrainian Army’s secret weapon? Supermodels!: I'm betting they can stick those stiletto heels in a bullseye at 400 yds. Maybe we need a cage match between the women of the IDF, including ...
- Daddy, What Was A “NBC,” Anyway?: A new factoid should add to broadcast network paranoia about the internet. An online poll of internet users found that "only one in four 12- to 34- ...
- Republican Porker: Senator John Thune, R-SD, has introduced a bill that would delay any base closings until the return of substantially all U.S. forces from Iraq. Thu ...
- The Alcohol and Adult Industries Ask: When’s the Next Hurricane?: Your home has been destroyed by a hurricane. You're living on an Air National Guard base on Cape Cod, a thousand miles from home. The U.S. government ...










July 12th, 2007 at 6:49 am
[…] House Link to Article iraq All your base are belong to us (Well at least your FTP servers) » Posted […]