Today a PasteBin appeared with the title FBI.gov hacked. It seems that the FBI.gov domain has been targeted again by hackers. This time the hack is done by Anonymous and Ghost Shell as the Pastebin file claims.
This is not the first time when FBI’s servers have been compromised, in past lulzsec and several other hackers have also gained access of the servers, recently thousands of Apple ids were also hacked because of an official laptop of an FBI officer was hacked.
Below you can find the content of the PasteBin FBI.gov file:
#By Anonymous And Ghost Shell ( Chris Defaulter Valentine )
--------------------------------------------------------------------------
935 Pennsylvania Avenue Northwest Washington, DC 20535
(202) 324-3000
----------
A_RECORD
----------
Server: 8.8.8.8
Address: 8.8.8.8#53 (node - 53)
Address: 209.84.4.105
__________
MX_record
----------
Server: 4.2.2.5
Address: 4.2.2.5#53
Authoritative answers can be found from:
c.footprint.net
origin = admin.nsatc.org
serial = 1319057938
refresh = 10800
retry = 2700
expire = 3600000
minimum = 900
_________
NS_RECORD
---------
a.gov-servers.net -> ns1.fbi.gov
Server:4.2.2.5 Address:4.2.2.5#53
mailbox host =dl-cdn_infrastructure.level3.com serial = 1319057938(Serial Key Registered to Allen Fuller)
________________________________________________________________________
Last System Update - Mon, 16 Apr 2012 11:05:15 UTC (from - 4.69.153.191)
------------------------------------------------------------------------
_________________________________________________________________________________
Login Panel - ae-91-91.csw4.SanJose1.Level3.net (4.69.153.14)
Intercom Manager Login Cookie - user1_1:1NDVHdDfNxvaswzOjQWNLkMRfVrGiJw:xvQHg3EoEowRkxOv
---------------------------------------------------------------------------------
_______________________________________________________________________________
Vulnerable Open Ports in FBI InterCommunication Intranet -
[REALLY GUYS, WHERE'S UR SECURITY]
4.69.153.18 responding on port 118 (sqlserv)
4.69.153.18 responding on port 3209 (asipx-webadmin) - Plaintext Passwords
4.69.153.18 responding on port 4415 (mxxrlogin)
4.69.153.18 responding on port 5613 (directplay6) - Remote Vulnerability
4.69.153.18 responding on port 7429 (openmail-mod)
4.69.153.18 responding on port 7440 (mppolicy-mgr) - Denial of Service
4.69.153.18 responding on port 7495 (x11-ssh-offset)
----------------------------------