WHID 2009-40: SQL injection Hits Sensitive US Army servers

Updated: 
31 May 2009
Attack Information
WHID ID: 
2009-40
Date Occured: 
26 Jan 2009
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Government
Attacked Entity Geography: 
USA
Source Information
Attack Source Geography: 
Turkey

Information Week reports that a well known Turkish hacker penetrated two sensitive US army servers, one at McAlester Ammunition Plant in McAlester, Okla., and the other at the U.S. Army Corps of Engineers' Transatlantic Center in Winchester, Va. The hacks are the currently under criminal investigation by Defense Department officials.

The breaches where not publicly disclosed and the level of exposure is therefore not known. It is known however that web site visitors where redirected to a site protesting against climate change.

The Register speculates that the attack method was SQL injection.