BRIAN ROSS REPORTS
- Like Jay-Z + the Beatles, But Worse
- Update: Help for Homeless Children
- Bush Era, Revised -- and with More Barbeque
- The Tax Woman Cometh
- Paging Mr. Stanford: Antigua Called
- Who Are You Calling Partisan?
- Update: IRS Won't Use Private Debt Collectors
- But Is It Art?
- PMA Scandal a Sore Point for Dems in 2010?
- Down in Flames
- A New Mystery for RNC Chief
- PMA Clients Were Big Givers
- Raided Lobby Firm Still a Force on Capitol Hill
- Stanford Update: Another $143 Mil Found
- Cheney, Hooked on Controversy
TOP BLOTTER CATEGORIES
- Abramoff Lobbying Scandal
- American Al Qaeda
- Avian Flu
- Beirut Hospital Out of Gas
- Cheney
- CIA
- CIA Secret Prisons
- D.C. Madam Affair
- FBI
- Federal Air Marshal Service
- Homeland Security
- Hurricane Katrina
- IRS
- Mark Foley Internet Scandal
- Millionaire Sex Scandal
- Nigerian E-mail Scams
- Norman Hsu, Clinton Fundraiser
- NSA: Wiretapping
- Osama bin Laden
- Payola
- Pharmacy Investigation
- PMA
- Speaker of the House Dennis Hastert
- Stanford
- Steele
- Terror
- Troopergate
- U.K. Airline Terror Plot
- U.K. Bombing Attempts
- Wen Ho Lee
- William Jefferson
- Zarqawi
« Previous | Main | Next »
Hackers Penetrate Water System Computers
October 30, 2006 3:15 PM
A foreign hacker who penetrated security at a water filtering plant near Harrisburg, Pa., is under investigation by the FBI for planting malicious software capable of affecting the plant's water treatment operations, ABC News has learned.
The hacker tried to covertly use the computer system as its own distribution system for e-mails or pirated software, officials told ABC.
"The concern was high because it is a computer that controls an important infrastructure system, and if, for some reason, it caused it to fail, it would have disrupted service," said Special Agent Jerri Williams of the FBI's Philadelphia field office.
THE BLOTTER RECOMMENDS
The Columbus Day weekend intrusion is the fourth recorded cyber-attack on a U.S. water supply in the past four years, according to the records of WaterISAC, an industry information sharing and analysis center with members from among more than 1,000 drinking water and wastewater systems in the United States.
The hacker operating on the Internet tapped into an employee's laptop and then used an employee's remote access as the point of entry and installed a virus and spyware in the water plant computer system. Following the intrusion, the plant changed all passwords to the system and eliminated home access to the system.
"This is very common...computer hackers try to gain control of systems to use them as a resource to distribute e-mails, pirated software. It does not appear that this particular computer was hacked into for any other reason," said Special Agent Williams.
In one of three past attacks cited by WaterISAC, hackers used a Korea-based telecom to launch a denial of service attack on one water supply. In a second, they penetrated a top-level data control and acquisition system on a California irrigation district wastewater treatment plant. And in a third, they announced their entry into the computer system with a message, "I enter in your server like you in Iraq."
"We are seeing an increase in reporting," said WaterISAC Executive Director Diane Van De Hei. Prior to Sept. 11, 2001, most of the incidents were managed locally, she said.
WaterISAC was established in December 2002. The private sector group uses "push" e-mail technology to distribute information from the Department of Homeland Security, EPA and other government agencies to more than 10,000 clients in the water utility sector.
According to a 2006 Computer Crime and Security Survey by the San Francisco-based Computer Security Institute, 52 percent of 616 survey respondents reported unauthorized use of their computer systems in the past 12 months.
October 30, 2006 | Permalink | User Comments (39)
You can follow this conversation by subscribing to the comment feed for this post.
When you fine the person, since he likes to play with water systems, let's do some waterboarding with him. Maybe his fondness for playing with water will change.
Posted by: ruben lopez | Oct 30, 2006 3:56:36 PM
This is absolutely the most outrageous & scariest report I have every seen since the public water system virtually reaches every household & citizen in America. And human beings are 80% water!!! How smart is it America that George Bush, Richard Cheney, Donald Rumsfeld, Paul Wolfawitz, and Michael Hayden are allowed to continue to commit epic criminal deceptions to further a NEO-CON REPUBLICAN Agenda, further irritate a Hornet's Nest in The Middle East while personally pocketing trillions that could be spent on a Perfect, Pure, and Secure National Water System. I believe that Water System Security is "The Most Urgent & Important" infrastructure project in the United States of America that we should spend those trillions on perfecting and securing since that is one of the few systems that enters into every U.S. citizen's home and whose product enters into every U.S. citizen's body. My fellow Americans, you have 7 days to make up your mind: If you want to continue spending trillions on IRAQ while enriching George Bush Sr., George Bush Jr., Richard Cheney, Donald Rumsfeld, Paul Wolfowitz, and Michael Hayden then vote 100% REPUBLICAN. If you want to stop spending trillions on IRAQ while enriching the Military Industrial "FAT CATS" and spend those trillions on AMERICA FIRST to perfectly upgrade, purify, protect, and secure the United States of America's Water Supply Infrastructure System then vote 100% Democratic for AMERICA FIRST. IT REALLY IS THAT SIMPLE!!!!
Posted by: Todd Restelli | Oct 30, 2006 4:40:24 PM
um i have a well in a very deep aquifer so let them play their games....lol
Posted by: WELLBOY | Oct 30, 2006 4:48:59 PM
What did this story have to do with the Republicans or George Bush? Absolutely nothing.
Posted by: SamJ | Oct 30, 2006 6:06:10 PM
Mandrake, there's a reason the Russkies drink vodka - they won't risk polluting their own precious bodily fluids.
-- Jack T. Ripper, in launching a NORAD attack in "Dr. Strangelove"
Posted by: Van Diesel | Oct 30, 2006 6:27:15 PM
This story has to do with protecting Americans against "REAL THREATS" and allocation of trillions of dollars of the Citizens of The United States of America. The current NEO-CON controlled White House, Senate, and Congress has failed to address & nullify "REAL THREATS" to America and all of humanity and they have de-frauded Congress and the United States of America and its citizens and have spent 3 trillion dollars in five years on what? just when 1/3 of our population (baby boomers) will start retiring. In the "REAL WORLD" when employees fail to perform their job after 1 year (it has now been 5) they are FIRED!!! In the "REAL WORLD" when citizens commit crimes they are arrested, indicted, tried, and either aquitted or convicted. George Bush Jr., Richard Cheney, Dennis Hastert, Donald Rumsfeld, Paul Wolfawiwitz, and Michael Hayden have not performed their jobs and have committed TREASON, MURDER, FRAUD, CONSPIRIACY, and some have lied to the FBI (a FELONY).
Posted by: Todd Restelli | Oct 30, 2006 7:50:34 PM
This is kind of hyped. It is likely that the intruder didn't know or care that it was a water filtering plant. The fact that the cracker installed code on the server that could have crashed it and "affected the plant's water treatment operations" is true, but hype. All this points out is that systems can be cracked, and that allowing remote VPN access into a company's network is just asking for this type of intrusion. The weakest link was the employee's laptop. We all know the only way to truly secure a system from remote attack is to unplug it.
Posted by: Hugh Jourbe | Oct 30, 2006 8:04:45 PM
At-a-boy Todd. You've nailed them. The republican political ads here in Texas are going naked.
Meaning, there is never a reference or identification of party affilitation if they are Republican. It's hillarious!!!
Posted by: Phyllis Culbert | Oct 30, 2006 8:15:38 PM
this hacker is smart.Water is important
Posted by: Waterboi | Oct 30, 2006 10:39:25 PM
Hi Phyllis if the REPUBLICANS have had TOTAL and UNACCOUNTABLE POWER for 5 years and are proud of their track record then why would they need to campaign naked??? You know what astonishes me is how easily these men manipulated & deceived CONGRESS, THE UNITED STATES OF AMERICA and its Citizens, and the whole world. I mean come on wouldn't you rather spend 3 trillion on AMERICA instead of IRAQ??? or even better yet since 1/3 of our population will start retiring shouldn't we have used those trillions to prepare for that????
Posted by: Todd Restelli | Oct 30, 2006 10:45:06 PM
WATER IS THE MOST IMPORTANT!!!! SECURITY & QUALITY FOR THE WATER SYSTEM SHOULD EQUAL THAT OF ANY NATIONAL CRITICAL INFRASTRUCTURE, ESPECIALLY SINCE THIS SYSTEM "ENTERS INTO" EVERY U.S. CITIZEN'S HOME & WORKPLACE AND "ENTERS INTO" EVERY U.S. CITIZEN'S BODY. HELLO, WE, AS HUMANS, ARE 80% WATER. SINCE YOUR BODY USES WATER TO CREATE ENERGY WOULDN'T YOU LIKE TO KNOW THAT THE LIFE FORCE IN WATER IS OF THE HIGHEST QUALITY, PERFECTLY PURE, AND ABSOLUTELY UNADULTERATED BY HOSTILE PARTIES. ANYONE WHO DISREGARDS THIS AS UNIMPORTANT AND WORKS IN GOVERNMENT SHOULD BE FIRED!!!!
Posted by: Todd Restelli | Oct 30, 2006 10:51:38 PM
What a joke - "Korean" infiltrators. Sure.
Next thing we know Korea will be harboring terrorists. Or do they already? LoL
Sounds more to me like the City of Harrisburg needs a new IT person with a brain. I mean, if a "hacker" can get past a security point from "Korea", even using a remote login through an employees laptop, then they have a lot more problems then kiddie hackers.
I wouldn't be drinking the water in Harrisburg.
Posted by: Take Back the Capitol | Oct 31, 2006 12:46:31 AM
we are living in a REAL world, facing a mountain of threats coming from VIRTUAL world! The development ad nauseam of hi-techs are somtimes dangerous! be wary!
Posted by: Le Ngoc Anh | Oct 31, 2006 5:05:39 AM
Todd,
I read your response to the article about a water treatement facility compromised by a hacker, and was a bit taken aback at the position you adopted. A FOREIGN HACKER penetrates a domestic water treatment facility and its somehow Bush's fault? I happen to be a security researcher and I will tell you first hand that this is not a failure of our government, or of the laws, or the economy, or anything else like that. It is a failure of the COMPANY that owns the water facility, and the TECHNOLOGY VENDORS that create such vulnerabilities in our products. Now, don't let that stear your attacks at them, a deteremined hacker will ALWAYS get in somehow. Anyone that wants to go after a target will have no problem doing it, its only a matter of determination and time, and not a greater political issue.
While I can agree with you that some things going on in the government are not ideal, we can't blame the Republicans and Bush for every hang nail out there. Bush hatred and blaming people that are not responsible for petty criminal acts is no way so solve the problem. You obviously have a lot of passion, put it to good use at dozens of industry events I go to every year, the hundreds of customer meetings, and the thousands of emails that I have to go through all the time as someone that is truly trying to wake up the country and the world to the danger that exists within our critical infrastructure. Understanding the problem and then targeting the areas where you can actually do some good is the only way to go. Blaming without full understanding or without taking some kind of responsible action helps no one.
I can certainly appreciate your passion about the subject, I happen to be very passionate about this one as well, but I believe that throwing blame is no way to solve the problem, there are a number of us out there that are putting our blood, sweat, and lives into protecting everyone, including you, out there.
Posted by: Bryan Singer | Oct 31, 2006 8:08:35 AM
Looks like Tod Reselli needs to find something to occupy his time.
Posted by: Wes | Oct 31, 2006 10:15:40 AM
It's the Internet folks. If we did away with the Internet, we could prevent this type of attack.
No, wait, I like my Internet access too much. How else could I blame the Republicans for this debacle.
Oops, maybe it's the Democrats. I read someplace that Clinton's neglect of security in the 1990s caused the current state of affairs.
But come to think of it, this could be North Korea. Mind you, I didn't know anything about North Korea when my only source of knowledge was the old-fashioned book. Now with the Internet, though, I am an expert...at least in this blog.
By golly, I just said Internet. Isn't that what we have to blame? Or is it Al Gore who invented the Internet?
Posted by: gus | Oct 31, 2006 10:15:50 AM
Get a Life! to all those Bush hating people who think everything is a federal issue. Who use blogs to push their outdated liberal "I'll take your money in taxes" and grow the economy. Your time is better spent gonig to scholl and taking Economics 101!
Posted by: it's getting old | Oct 31, 2006 11:58:00 AM
Oh yes, blame Bush and the Republicans. How idiotic. Yes, and also the high prices for Gas is Bush's fault and the failing economy.
Guess what people? We are responsible for ourselves. Don't scapegoat. Fix it.
BTW, no one blames the Pres when gas prices fall and the economy booms...LIKE NOW.
Posted by: Josh | Oct 31, 2006 12:06:05 PM
It's guys like Todd that make politics so despicable. In your minds, anything that happens is a good chance to attack your political opponents in a sorry attempt to further your own political agenda, be it nomination or just winning favor for a particular political party.
And also, don't be so quick to assume that spending a ridiculous amount of money on computer systems will make them untouchable. There is no such thing as a perfectly safe computer system. Period. If it transfers data, there is a way to take control of it. This does not mean I am supporting the war in Iraq, nor am I claiming to be against it. That is a totally separate matter, and has NOTHING to do with a cyber miscreant trying to spread spam and pirated software.
And turn off your damned caps lock key. YOU DON'T NEED TO YELL EVERYTHING THAT GOES THROUGH YOUR MIND!!! That's just annoying.
Posted by: Zach West | Oct 31, 2006 12:27:48 PM
I think the easiest way to solve this type of hacker problem is to simply have a SEAL team give them a 'bon voyage' party.
Any type of attack on a security asset such as a water treatment plant should be handled as a terrorist activity. Intended or not, these hackers could have done some serious damage, and as a society we cannot allow them to get the impression that such attacks will be tolerated.
Once hackers realize the stakes involved, I think most of these pimple faced geeks will decide to put their talents to better use (such as hacking the RIAA website).
Posted by: e | Oct 31, 2006 12:51:02 PM
Post a comment
