Attacks/Breaches
9/4/2007
01:00 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

China Makes 'Most Successful Cyber Attack Ever' on the Pentagon

Chinese military proves its ability to disable US defense systems

China's recent penetration of government systems in Germany raised some eyebrows. Now sources at the Pentagon say that China's army made a similar successful attack back in June -- on American defense systems.

According to a report in today's Financial Times, Pentagon officials are now acknowledging that the People's Liberation Army launched "the most successful cyber attack ever" on U.S. defense systems less than two months ago.

"The PLA has demonstrated the ability to conduct attacks that disable our system... and the ability in a conflict situation to re-enter and disrupt on a very large scale,” according to a former official.

The PLA penetrated the networks of U.S. defense companies and think-tanks after probing for weaknesses for several months, the report states. The Pentagon took the networks down for more than a week while the attack continued.

The Pentagon is still trying to figure out how the hackers got into the network and what data might have been compromised. Most of the downloaded information so far appears to be of the unclassified variety.

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0985
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

CVE-2014-0986
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

CVE-2014-0987
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

CVE-2014-0988
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

CVE-2014-0989
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

Best of the Web
Dark Reading Radio