Hackers breach powerful research networks in US
NEW YORK (AP) - Hackers have broken into some of the world's most powerful computer clusters in recent weeks in an apparently coordinated cyberattack targeting research and academic institutions.
Although officials sought Wednesday to play down the seriousness of the threats, some security experts warned that such a break-in could potentially enable a serious attack on the Internet.
Stanford University, the San Diego Supercomputer Center and the University of Illinois' National Center for Supercomputing Applications were among the systems hit.
Also affected was TeraGrid, a government-funded effort to link together several supercomputers, including those at San Diego and NCSA, so scientists can better crunch data for weather forecasting, astronomy and medicine.
"There's been some unauthorized access, but it's not that anything has been damaged or taken over,'' said Catherine Foster of Argonne National Laboratory, home to TeraGrid's coordinator.
"This seems to be part of an effort (by hackers) to gain merit badges.''
Foster said some TeraGrid computers had to be taken offline while security upgrades were made, disrupting research.
She said the attacks began in March and that all systems should be restored by week's end.
Mike Levine, scientific director at TeraGrid member Pittsburgh Supercomputing Center, said the TeraGrid sites performed no classified work so there are "no implications for national security.''
He would not say whether Pittsburgh itself was hit.
But Peter Allor, director of intelligence with the Internet Security Systems' X-Force research unit, said universities and research institutions are prime targets for hacking because they have very powerful computers with plenty of Internet bandwidth.
Those resources, he said, could be tapped to launch so-called denial-of-service attacks that can disrupt major Web sites and e-mail systems around the world, potentially bringing down the Net.
Frank Dwyer, associate director for information technology at San Diego, acknowledged that research networks pose special challenges because they are far more open than corporate networks.
But he said institutions like San Diego have safeguards to protect the most critical systems. Investigations were continuing, and law enforcement authorities have been contacted.
No one could specify how many institutions have been compromised, though officials described the number as large.
At San Diego, hackers managed to penetrate computers at the perimeter, but network managers stopped them before they reached core systems, Dwyer said.
He described the effect on users as minimal.
The NCSA urged all users to change passwords, while Stanford issued a security bulletin last week reminding network administrators to upgrade their systems with the latest security patches.
At Stanford, which is not part of TeraGrid, computers hit were running Solaris and Linux operating systems.
Hackers took advantage of known vulnerabilities for which patches were available but not installed.
Hackers used insecure machines to gain root privileges, which let them make the kinds of changes normally reserved for authorised administrators.
But even computers with the latest patches were used to run password-decoding software after hackers logged on using a compromised account, according to the Stanford bulletin. - AP
For more foreign business news click here
News Poll
- Maid on the run caught during job interview
- Four siblings surviving on biscuits
- Bendera’s empty call
- ISA detainee released after eight years
- Dr Ling applies to declassify PKFZ papers and transfer trial venue (Updated)
- Rules on gated schemes will be imposed with immediate effect
- Ready for the rush
- Consider Cola for pensioners
- Penangites need govt that shows leadership
- Task force to look out for sensitive matter on Internet
- Four siblings surviving on biscuits
- Rules on gated schemes will be imposed with immediate effect
- Maid on the run caught during job interview
- Toll cuts during Raya
- Exciting MAS deals to be offered at Matta Fair
- Task force to look out for sensitive matter on Internet
- Facebook's new security feature: remote logouts
- Ready for the rush
- Indonesian volcano erupts again, this time stronger
- Abducted clinic assistant tells of torture

