FBI Unclassified E-mail Network Owned By Virus

The New Acunetix V12 Engine


If the FBI e-mail network can get owned by a virus, what hope does the average joe have when it comes to keeping their e-mail secure?

It must be pretty serious too if it actually forced them to shut down the Internet facing e-mail network, it seems like it was down for at least a week and possible still unavailable to some users.

This demonstrates the problems self-propagating malware can cause to e-mail systems.

A virus has reportedly disrupted Web-based e-mail services at the U.S. Federal Bureau of Investigation.

The FBI confirmed Friday that it had been forced to shut down its Internet-facing unclassified network, but disputed a report that the incident had left the agency unable to e-mail counterparts in other intelligence and law enforcement agencies. “The external, unclassified network was shut down by the FBI as a precautionary measure,” the FBI said in a statement. “Within 48 hours of identifying the issue and mitigating risks, e-mail traffic was largely restored to the external, unclassified network.”

FBI agents can send e-mail on the agency’s more secure internal network or via BlackBerry, but many use this unclassified network to send messages via a Web-based e-mail system, said a source familiar with the situation. That webmail service was down throughout the week and continued to be unavailable for some users, the source said.

Where’s the full disclosure! We want details please, was this a normal virus that going around online? Was it something tailored to attack the FBI network? Was it seeded from inside or did it come in externally?

So many interesting questions, but no answers as usual.

It could be related to the recent QuickTime flaw with the DirectX rendering, the timing is about right – I guess we’ll never know though.

The FBI did not provide details on the security incident, but it looks as though hackers may have used maliciously encoded file attachments to hack into the network. In its statement, the FBI said it was now blocking users from sending or receiving attachments on the unclassified network “to give our technicians time to scan all the attachments that came into the e-mail system to make sure we have identified and mitigated all threats to the network.”

Malicious attachments are a constant security threat for computer users.

Microsoft warned Thursday that attackers are sending malicious QuickTime media files to victims, exploiting an unpatched flaw in Apple’s media format, in order to install malicious software on Windows systems.

It was first reported by NYPost and then later by CBS News.

I’ll be keeping an eye out to see if there are any further developments or news disclosure, if you’ve read anything relevant drop a link the comments.

Source: Network World

Posted in: Exploits/Vulnerabilities, Legal Issues, Malware

,


Latest Posts:


BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.


One Response to FBI Unclassified E-mail Network Owned By Virus

  1. David June 11, 2009 at 11:36 am #

    Latest Quicktime and Adobe Reader vulnerabiltiies are creating a new path to malware and spyware.
    I’m wondering if FBI would release some information about this attack to their email network.