The Register® — Biting the hand that feeds IT

Feeds

Angry Brazilian whacks NASA to put a stop to ... er, the NSA

'Facepalm' doesn't even begin to describe this one

Supercharge your infrastructure

Multiple NASA websites were defaced last week by a Brazilian hacktivist who may have misread the sites' URLs, because he wasn't protesting about the US space agency giving joyrides to inhuman stowaways – he was protesting against NSA spying.

“BMPoC” hit kepler.arc.nasa.gov and 13 other sites with messages protesting against US spying on Brazil, as well as a possible US military intervention in Syria.

It's hard to believe anyone would confuse the NSA spy agency with NASA, the space agency, except for satirical purposes or to mock script kiddies in some way, so we can only guess that the hackers behind the attack hit NASA because it's a US government agency whose systems are noted for being insecure.

NASA is at one level a scientific research agency with numerous links to universities. The notoriously weak security practices in much of academia have spilled over to the space agency. NASA's less than stellar information security practices have been repeatedly criticised by government auditors.

The defacement messages themselves are all over the place, grammatically, and less than coherent logically.

NASA HACKED! BY #BMPoCWe! Stop spy on us! The Brazilian population do not support your attitude! The Illuminati are now visibly acting!

Obama heartless! Inhumane! you have no family? the point in the entire global population is supporting you. NOBODY! We do not want war, we want peace!!! Do not attack the Syrians.

A list of the defaced domains along with links to entries on defacement archive Zone-h can be found on Pastebin.

The hacked domains are maintained by various scientific missions within NASA such as the Kepler Mission, Ames Academy for Space Exploration and NASA’s Office of Planetary Protection, Virtual Astrobiology, a NASA recruitment domain, NASA Lunar Science Institute among others, CyberWarZone reports. Brief checks suggest most of the domains were returned to service by Monday morning.

A NASA spokesman played down the significance of the digital graffiti attacks, telling Fox News that everything was under control.

"A Brazilian hacker group posted a political message on a number of NASA websites. ... Within hours of the initial posting, information technology staff at the Ames Research Center discovered the message and immediately started an investigation, which is ongoing," he said. "At no point were any of the agency’s primary websites, missions or classified systems compromised."

The same hacker/hacking group also hit NASA back in April, HackRead reports. Last time around the defacement had no politically-related content.

"NASA might be picked on simply because it represents low-hanging fruit," writes Lisa Vaas, in a commentary on the hacking on Sophos' Naked security blog. "Somebody ought to tell BMPoC that he/she/they are bullies kicking sand in the face of rocket scientists who have better things to do than mop up after an attack that's spurred by a head-scratcher of a so-called rationale that's unrelated to NASA's mission." ®

5 ways to prepare your advertising infrastructure for disaster

Whitepapers

5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.

More from The Register

next story
Chaos Computer Club: iPhone 5S finger-sniffer COMPROMISED
Anyone can touch your phone and make it give up its all
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
Would you hire a hacker to run your security? 'Yes' say Brit IT bosses
We don't have enough securo bods in the industry either, reckon gloomy BOFHs
UK's Get Safe Online? 'No one cares' - run the blockbuster ads instead
Something like Jack Bauer's 24 ... whatever it'll take to teach kids how to bat away hackers
London schoolboy cuffed for BIGGEST DDOS ATTACK IN HISTORY
Bet his parents wish he'd been playing computer games
RSA: That NSA crypto-algorithm we put in our products? Stop using that
Encryption key tool was dodgy in 2007, and still dodgy now
The NSA's hiring - and they want a CIVIL LIBERTIES officer
In other news, the Spanish Inquisition want an equal opprtunities officer
'Occupy' affiliate claims Intel bakes SECRET 3G radio into vPro CPUs
Tinfoil hat brigade say every PC is on mobile networks, even when powered down
prev story