Skip to main content


More on the Sans.org Web site hacking by Bob Sullivan for MSNBC

posted onJuly 14, 2001
by hitbsecnews

The home page for one of the nation?s most respected computer security training institutes was defaced Friday morning and the site remains offline. A group identifying itself as ?Fluffi Bunni? managed to break into the Web site for the Networking and Security Institute, which is known as SANS. The institute?s director of research, Alan Paller, said the site would remain offline until forensic work was finished and ?until we figured out how it happened.?

He said the defacement was embarrassing for the organization, but added that SANS is a top target for computer intruders. ?If you sit in the middle of the road long enough, a truck will hit you,? he said. ?We are a target.?..

THE COMPUTER INTRUDERS replaced the normal SANS.org home page with a taunting message that remained on the SANS site for about 27 minutes, Paller said.

SANS offers certification classes and other seminars for computer security professionals. It also publishes a number of popular security mailing lists.

The SANS site includes an e-commerce component, as network security professional can register and pay for conferences at SANS.org. But Paller said no personal data was compromised, as registration information isn?t stored on the computer that was broken into.

?Still, this is not what you want to have happen,? he said.

A group calling itself ?Fluffi Bunni? has struck at popular computer security organizations before. In May, Exodus Communications? security.exodus.net site was defaced and a similar message left behind.

Paller couldn?t say when the SANS.org site would be back up, because he vowed the organization would plug whatever hole the intruders used to break in first ? a standard he said many victimized sites don?t stick to.

A wild guess is that they will wait until Def Con is over... tee hee

?We are losing business every minute, but you?ve got to do it right,? he said.

Actually the lost in business might come when the 'teachers' of security are shown to be unable to secure their own site

The break-in occurred the same morning that the annual DEF CON computer hacker convention began in Las Vegas. Paller said there is no apparent connection between the conference and the defacement

MSNBC.

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th