Skip the navigation

NASA Investigating Theft by Hacker

Security gap exposes sensitive documents on plans for future reusable space vehicles

By Dan Verton
August 12, 2002 12:00 PM ET

Computerworld - WASHINGTON


NASA cybercrime investigators are looking into the theft of militarily significant design documents pertaining to the next generation of reusable space vehicles.


The documents, which are restricted by export laws from being shared with foreign nationals or governments and are also strictly controlled under the International Trafficking in Arms Regulations, were obtained by Computerworld last week from a hacker who claims to be based in Latin America. Computerworld broke the story online last Thursday.


The documents were authored by contractors from The Boeing Co. and a joint venture between East Hartford, Conn.-based Pratt & Whitney and Sacramento, Calif.-based Aerojet. All of the vendors had labeled the documents "competition sensitive," and while it is not yet clear exactly what sensitive data on military and commercial technologies may have been compromised, defense and intelligence experts said the incident could have both national security and political ramifications.


Bob Jacobs, a spokesman for NASA, confirmed that the documents contain sensitive military information and should have been stored in a closed database. There is no information on how or from where the documents were stolen, and investigators couldn't confirm whether a hacking incident had taken place.


However, a hacker known only by the nickname RaFa who was formerly a member of the now-defunct World of Hell hacker gang, uploaded to a Web site more than 43MB of documents, including a 15-part PowerPoint presentation that included detailed engineering drawings. The documents also included detailed mechanical design information on the COBRA space shuttle engine design program and the risk-reduction plan for the Boeing TA4 Advanced Checkout, Control & Maintenance System (ACCMS). The ACCMS is essentially the ground control system for the next generation of space shuttles.


Walt Rice, a spokesman for Boeing, said the company doesn't have enough information on the incident to comment. However, Boeing is aware that NASA officials are investigating, and the company will offer any assistance that's requested of it, he said.


Patrick Louden, a spokesman for Pratt & Whitney, said that NASA is taking the lead in the investigation and that the company is deferring to the agency for all comments on the matter.


Military Interests


NASA's 2nd Generation Reusable Launch Vehicle Program (RLV) is part of the agency's long-term Space Launch Initiative, a multibillion-dollar effort to design a safer and more efficient space transportation architecture by 2005. The Department of Defense is a key partner in the effort because of its interest in the RLV program's applicability to military satellite programs and future military space plane designs.


RaFa said he didn't understand the sensitivity of the information he had and acknowledged that he has shared the documents with hackers in France. He also showed Computerworld evidence of a hack into systems at NASA's White Sands Test Facility in New Mexico, producing a list of dozens of user accounts. He claims to have used an anonymous FTP vulnerability to conduct both hacks.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Cybercrime and Hacking White Papers
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
Protecting Point of Sale Systems from Targeted Attack
If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
From the Frontline - Preventing APT
Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
Stop Hackers Before They Attack
Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
The four rules of complete web protection
As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time...
All Cybercrime and Hacking White Papers
Cybercrime and Hacking Webcasts
WikiLeaks: How am I Affected?
The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
All Cybercrime and Hacking Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs