HomeInvestigationsEXCLUSIVE: Cyberattack on FORTH - www.ics.forth.gr by GIS!

EXCLUSIVE: Cyberattack on FORTH – www.ics.forth.gr by GIS!

GIS

A cyberattack with a simultaneous data leak against the website of the Institute of Informatics - FORTH www.ics.forth.gr, based in Heraklion, Crete, was carried out, according to secure information, by the GIS (Greek Insane Society)!

The powerful attack, which led, among other things, to the leakage of the Foundation's passwords, is the continuation of a series of cyberattacks launched by GIS, with the aim, as it stated in its previous statement, of highlighting cybersecurity problems in Greece, without causing damage [more in their manifesto here].

GIS

The information sent by an unknown person to the SecNews contact email address suggests a specialized SQL Injection (Blind sql injection), bypassing the Web Application firewall used by the Foundation.

The Institute of Computer Science and Engineering (ICS-FORTH), www.ics.forth.gr is located at the headquarters of the Foundation in Heraklion, Crete, and currently employs approximately 350 people. Since its founding in 1983, it has been internationally competitive and has excelled in all the evaluations of research institutes conducted in Greece by the General Secretariat for Research and Technology, having always been ranked first in the field of Informatics. The Institute conducts basic and applied research in the following areas: Computational Medicine, Bio-Informatics, Computer Vision and Robotics, Computer Architecture and VLSI Systems, Distributed Computing Systems, Information Systems and Cultural Informatics, Human-Computer Interaction, Universal Access and Assistive Technologies, Telecommunications and Networks.

Furthermore, the Institute of Information and Communication Technologies (IICT) co-organizes with the European Agency for Network and Information Security (ENISA) the Annual Summer School on Network and Information Security, which apparently did not prevent the GIS hacker group from carrying out an attack against the Institute! 

The Greek Insane Society hacker group, which has been busy in recent weeks , having carried out high-profile attacks, identified, using available tools on the internet, a SQL Injection vulnerability which, according to their statement, led to the extraction of data from the website https://www.ics.forth.gr. The data includes, among other things, passwords for both the website (administrator rights) and the passwords for the interconnected laboratories of the Foundation. To prove their statements and to inform the responsible administrators, they sent relevant screenshots which we are publishing  (ed. note: data has been hidden from SecNews to protect personal data and prevent the data from being used by malicious users)

GIS
Identifying website weaknesses using a properly configured tool (possibly SQLMap)

 

2-min
Extracting data (tables) from a website database using a known tool.

 

GIS
Extracting data from the ICS database

 

GIS
Leak of administrator passwords & personal user passwords!

The data that has been hidden by SecNews and indicates the existence of the vulnerability is available to any legal/official representative of the FORTH institution if they so wish, so that the vulnerability can be repaired if deemed necessary by the authorities (a fact that was also the goal of the Greek Insane Society, according to their statement to the editors of SecNews).

Risk Percentage of using the vulnerability against FORTH (90%)

[progress size=”90″ variation=”progress-danger” animated=”active”]

GIS

Critical questions to answer

Many questions arise from the GIS cyberattack against the Institute of Information Technology-FORTH. SecNews, in communication with experts on information security issues, found that the cyberattack is POSSIBLY affecting information systems VERY significantly regarding the country's critical infrastructure (a fact that of course must be investigated and answered by the relevant administrators).

Specifically, the questions that require answers and that those responsible should definitely investigate are:

  • Have information/passwords or employee or administrator data been intercepted from institutions collaborating with the FORTH-IT? The FORTH-IT is a pillar of support for multiple information systems in Greece, with all that this entails.
  • It is known that the University of Athens/FORTH, as we read on its main website, is the management body for the service of granting and managing names with the “.gr” suffix in the Greek internet space. Can the leaked data be used to access the .gr name registry or are these completely different networks?
  • Correspondingly, the ForthCert Unit belongs to the Institute of Information Technology (FORTH) and , in collaboration with ENISA, is the leading research institute and Incident Response for cyber breaches. Why, while the Institute of Information Technology (FORTH) has ISO 27001 certification , were the weaknesses not identified in the relevant controls they carry out? Is there a possibility that data from these units has also been exposed?
  • The website has a particularly high traffic according to statistics. Why were strong protection measures not implemented? Since malicious hackers who know about the vulnerability have access, it is possible for unsuspecting users to be affected bywater holing attacks and mass malware distribution.
  • Why were the passwords used absolutely simple and was there no policy in place to create complex passwords?
  • Was the targeted server located in a demilitarized zone (DMZ) separated from the rest of FORTH's services or was it within the institution's internal networks?

GIS

[signoff icon=”icon-target”]Additionally, the fact that FORTH has been certified for secure information management according to the 27001 standard, while the website contains such a significant error that gives access to the passwords of users and employees, raises questions! It should be investigated whether and to what extent the certification process was carried out in the most correct and technically complete manner, as well as whether what is stated in the ISO 27001 standard is applied in practice. All this, at a time when the University of Thessaloniki/FORTH has nursing applications of the Electronic Health Record to the public with sensitive personal data![/signoff]

GIS

In our opinion, administrators must IMMEDIATELY deactivate the server affected by GIS's actions and investigate whether any access has been made to internal systems or cooperating services of the Foundation. We believe that ENISA and ForthCERT as the most specialized and technically qualified bodies to investigate the respective incidents.

Furthermore, due to the nature of the Research Institute of the Hellenic University of Technology/FORTH, we believe that a public response should be given regarding the cyberattack, in line with the standards of statements by foreign institutions, in order to verify the magnitude of the cyberattack from the most official sources.

SecNews thanks GIS for the timely and accurate information.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS