Intermarkets' Privacy Policy
Support


Donate to Ace of Spades HQ!


Contact
Ace:
aceofspadeshq at gee mail.com
Buck:
buck.throckmorton at protonmail.com
CBD:
cbd at cutjibnewsletter.com
joe mannix:
mannix2024 at proton.me
MisHum:
petmorons at gee mail.com
J.J. Sefton:
sefton at cutjibnewsletter.com


Recent Entries
Absent Friends
Bandersnatch 2024
GnuBreed 2024
Captain Hate 2023
moon_over_vermont 2023
westminsterdogshow 2023
Ann Wilson(Empire1) 2022
Dave In Texas 2022
Jesse in D.C. 2022
OregonMuse 2022
redc1c4 2021
Tami 2021
Chavez the Hugo 2020
Ibguy 2020
Rickl 2019
Joffen 2014
AoSHQ Writers Group
A site for members of the Horde to post their stories seeking beta readers, editing help, brainstorming, and story ideas. Also to share links to potential publishing outlets, writing help sites, and videos posting tips to get published. Contact OrangeEnt for info:
maildrop62 at proton dot me
Cutting The Cord And Email Security
Moron Meet-Ups






















« Black, Hispanic Democratic Congressional Aides Paid Far, Far Less Than White Counterparts | Main | Lean Forward: MSNBC Goes Right Back to Its Comfort Zone of Feces »
December 20, 2013

IG: Treasury Dept was wide open to our ethical hackers

Nothing could possibly go wrong if the US Treasury's IT systems were penetrated and disrupted, right? Un-possible. The Treasury is a veritable fortress of security and stability, right?

TOP MEN baby, top men.

We found that default factory-preset administrative usernames and passwords were present in OCC’s systems. In one test we conducted, we discovered a default username and password of an internal service account on an OCC server which had local administrator privileges. We used those privileges and deployed our penetration test tool’s agents to the host server. That server contained password hashes for local and domain administrator accounts. Using these hashes, we obtained a domain administrator’s password, which we then used to log on to the network domain controller. With full access given to a typical domain administrative account, we created a domain administrator account and thereby had full control of OCC’s
network.
In accordance with our Rules of Engagement, we did not attempt to perform actions that would disrupt OCC’s operations, such as deleting data, powering off servers or other resources, locking out accounts, and similar activities, any of which could have resulted in interruption or shutdown of devices or services. However, malicious attackers would have no such restrictions against performing these actions
Because systems and devices connected to OCC’s internal
network could freely communicate between one another, with very little internal partitioning, we successfully attacked multiple OCC systems in a very short amount of time from a single workstation.
It just gets worser and worser as you go deeper and deeper into the report. I think you get the idea. The IG's hacking crew seems pretty good. Treasury staff? maybe not so much.


digg this
posted by Purp at 03:22 PM

| Access Comments




Recent Comments
[/i][/b]andycanuck (hovnC)[/s][/u]: "Maral Salmassi @MaralSalmassi Despite claims made ..."

jimmymcnulty: "Are Australian pizzas served upside down. Asking ..."

Viggo Tarasov: "Hey, that tweezer thing can really pluck someone u ..."

Eromero: "322 German police valiantly confiscating a Swiss A ..."

Anna Puma: "BOLO Rowdy the kangaroo has jumped his fence an ..."

fd: "You can't leave Islam. They won't let you. ..."

[/b][/s][/u][/i]muldoon, astronomically challenged: "German police valiantly confiscating a Swiss Army ..."

Cicero (@cicero43): "Hamas clearly recognises that when the cultural es ..."

Ace-Endorsed Author A.H. Lloyd: "The only way you can defend this position is to ei ..."

Ciampino - See you don't solve it by banning guns: "303 BMW pretty low to ground ... at least it wasn ..."

NaCly Dog: "I had a UPS package assigned to a woman in another ..."

Dr. Not The 9 0'Clock News: "One high school history teacher I remember well, a ..."

Recent Entries
Search


Polls! Polls! Polls!
Frequently Asked Questions
The (Almost) Complete Paul Anka Integrity Kick
Top Top Tens
Greatest Hitjobs

The Ace of Spades HQ Sex-for-Money Skankathon
A D&D Guide to the Democratic Candidates
Margaret Cho: Just Not Funny
More Margaret Cho Abuse
Margaret Cho: Still Not Funny
Iraqi Prisoner Claims He Was Raped... By Woman
Wonkette Announces "Morning Zoo" Format
John Kerry's "Plan" Causes Surrender of Moqtada al-Sadr's Militia
World Muslim Leaders Apologize for Nick Berg's Beheading
Michael Moore Goes on Lunchtime Manhattan Death-Spree
Milestone: Oliver Willis Posts 400th "Fake News Article" Referencing Britney Spears
Liberal Economists Rue a "New Decade of Greed"
Artificial Insouciance: Maureen Dowd's Word Processor Revolts Against Her Numbing Imbecility
Intelligence Officials Eye Blogs for Tips
They Done Found Us Out, Cletus: Intrepid Internet Detective Figures Out Our Master Plan
Shock: Josh Marshall Almost Mentions Sarin Discovery in Iraq
Leather-Clad Biker Freaks Terrorize Australian Town
When Clinton Was President, Torture Was Cool
What Wonkette Means When She Explains What Tina Brown Means
Wonkette's Stand-Up Act
Wankette HQ Gay-Rumors Du Jour
Here's What's Bugging Me: Goose and Slider
My Own Micah Wright Style Confession of Dishonesty
Outraged "Conservatives" React to the FMA
An On-Line Impression of Dennis Miller Having Sex with a Kodiak Bear
The Story the Rightwing Media Refuses to Report!
Our Lunch with David "Glengarry Glen Ross" Mamet
The House of Love: Paul Krugman
A Michael Moore Mystery (TM)
The Dowd-O-Matic!
Liberal Consistency and Other Myths
Kepler's Laws of Liberal Media Bias
John Kerry-- The Splunge! Candidate
"Divisive" Politics & "Attacks on Patriotism" (very long)
The Donkey ("The Raven" parody)
Powered by
Movable Type 2.64