HomeSecurityIs the FBI's Plone CMS hack a Hoax?

Is the FBI's Plone CMS hack a hoax?

The developer of Plone CMS, which is often cited as the most secure content management system (CMS) on the market, says that recent reports of a hack into FBI systems are very likely fake.

Hacker CyberZeist, acting on behalf of Anonymous, revealed that in late December he managed to hack the CMS software used by the FBI, managing to intercept more than 150 accounts, with hashed passwords.

CyberZeist reported that he used an exploit on a security flaw present in the Plone CMS, which is used by the FBI, and that the zero-day is still being sold on the black market.

In a very long post today, Plone says that the FBI's system hack is unlikely, noting that the company is not aware of any zero-day flaws in its software.Is the FBI's Plone CMS hack a hoax?

“Security patch announcements are typically issued with two weeks' notice. If the Plone security team receives reports of a zero-day exploit that is already in circulation, a security update will be released immediately,” Plone says.

Describing the hack claim as a hoax, Plone is attempting to debunk the hack, pointing out that some of the details CyberZeist provided are inaccurate, such as the server operating system, which the hacker stated was FreeBSD 6.2-RELEASE.

"It is highly unlikely that the FBI is running such an old version of FreeBSD. Furthermore, FreeBSD 6.2 ships with Python 2.4, while Plone runs with Python 2.5 and will not run on older versions of Python," Plone said.

So what was the hacker's purpose in claiming to have compromised the FBI's website?
According to Plone, which describes its software as "a highly secure content management system," the hacker is most likely trying to sell a fake exploit and needs media publicity to drive up the price.

At the moment, however, it is very difficult to say what happened to the FBI CMS, but CyberZeist has promised to provide more information about the breach once the sale of the zero-day stops.

Either way, we'll find out who's lying..

PS: I will have to install this particular CMS, the company's claims that it is the most secure on the market have piqued my curiosity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS