[iwar] [fc:Three.GAO.Machines.Defaced]

From: Fred Cohen (fc@all.net)
Date: 2001-12-13 06:35:16


Return-Path: <sentto-279987-4052-1008254076-fc=all.net@returns.groups.yahoo.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 [204.181.12.215] by localhost with POP3 (fetchmail-5.7.4) for fc@localhost (single-drop); Thu, 13 Dec 2001 06:37:08 -0800 (PST)
Received: (qmail 32063 invoked by uid 510); 13 Dec 2001 14:34:50 -0000
Received: from n22.groups.yahoo.com (216.115.96.72) by all.net with SMTP; 13 Dec 2001 14:34:50 -0000
X-eGroups-Return: sentto-279987-4052-1008254076-fc=all.net@returns.groups.yahoo.com
Received: from [216.115.97.191] by n22.groups.yahoo.com with NNFMP; 13 Dec 2001 14:34:36 -0000
X-Sender: fc@red.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_1_2); 13 Dec 2001 14:34:36 -0000
Received: (qmail 53517 invoked from network); 13 Dec 2001 14:34:35 -0000
Received: from unknown (216.115.97.171) by m5.grp.snv.yahoo.com with QMQP; 13 Dec 2001 14:34:35 -0000
Received: from unknown (HELO red.all.net) (12.232.125.69) by mta3.grp.snv.yahoo.com with SMTP; 13 Dec 2001 14:34:35 -0000
Received: (from fc@localhost) by red.all.net (8.11.2/8.11.2) id fBDEZG400752 for iwar@onelist.com; Thu, 13 Dec 2001 06:35:16 -0800
Message-Id: <200112131435.fBDEZG400752@red.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL3]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Thu, 13 Dec 2001 06:35:16 -0800 (PST)
Subject: [iwar] [fc:Three.GAO.Machines.Defaced]
Reply-To: iwar@yahoogroups.com
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

On December 12, a group known as AIC compromised and defaced three General
Accounting Office (GAO) machines. Despite mail from various mail lists
that keep track of such defacements, it appears that only three machines
were compromised. As with many setups, a few of the machines had aliases
for easy functionality. 

Machine/URL                           IP Address        Aliases
-----------                           ----------        -------
<a href="http://titan.gao.gov">http://titan.gao.gov>                  161.203.16.6	ftp.gao.gov
<a href="http://gao-cp.gao.gov">http://gao-cp.gao.gov>                 161.203.16.1	mail.goa.gov
<a href="http://gaoweb2.gao.gov">http://gaoweb2.gao.gov>                161.203.16.4


Mirror: http://defaced.alldas.de/mirror/2001/12/10/titan.gao.gov/
Mirror: http://defaced.alldas.de/mirror/2001/12/10/gaoweb2.gao.gov/



-
The information and commentary is Copyright 2001, by the individual author.
Permission is granted to quote, reprint or redistribute provided the text is not
altered, and the author and attrition.org is credited. The opinions expressed
in this mail are not necessarily the opinion of all Attrition staff members.

Commentary Archive: http://www.attrition.org/security/commentary/
The Attrition Mirror: http://www.attrition.org/mirror/attrition/
Country/TLD Statistics: http://www.attrition.org/mirror/attrition/country.html
Attrition Defacement Statistics: http://www.attrition.org/mirror/attrition/stats.html
Operating System Graphs: http://www.attrition.org/mirror/attrition/os-graphs.html

Other Web Defacement Mailing Lists: http://www.attrition.org/security/lists.html
Contacting Attrition Staff: <a href="mailto:staff@attrition.org?Subject=Re:%20[defaced-commentary]%20Three%20GAO%20Machines%20Defaced%2526In-Reply-To=%2526lt;Pine.LNX.3.96.1011213002945.13033D-100000@forced.attrition.org">staff@attrition.org</a>

To subscribe to Defaced Commentary, send mail to <a href="mailto:majordomo@attrition.org?Subject=Re:%20[defaced-commentary]%20Three%20GAO%20Machines%20Defaced%2526In-Reply-To=%2526lt;Pine.LNX.3.96.1011213002945.13033D-100000@forced.attrition.org">majordom
o@attrition.org</a>
with "subscribe defaced-commentary" in the BODY of the mail (without
quotes). To unsubscribe, include "unsubscribe defaced-commentary" in
the BODY of the mail.

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Need new boots for winter? Looking for a perfect gift for your shoe loving friends?
Zappos.com is the perfect fit for all your shoe needs!
http://us.click.yahoo.com/ltdUpD/QrSDAA/ySSFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-12-31 21:00:00 PST