You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Home Front: Politix
Hackers, Probing Clinton Server, Cite Security Lapses
2015-03-13
[FoxNews] Stirred by the controversy surrounding Hillary Clinton's use of a private email server when she was secretary of state, a determined band of hackers, IT bloggers, and systems analysts have trained their specialized talents and state-of-the-art software on clintonemail.com, the domain under which Clinton established multiple private email accounts, and uncovered serious lapses in security, according to data shared with Fox News.

The findings call into question Clinton's confident declaration, at a hastily arranged news conference in New York on Tuesday, that "there were no security breaches" in her use of a private server. One prominent figure in the hacker community, bolstered by long experience in the U.S. intelligence community, has undertaken to build a virtual "replica" of Clinton's server configuration in a cyberlab, and has begun testing it with tools designed to probe security defenses. This individual has shared details of the Clinton system not disclosed publicly but legally obtainable.

Among other things, outside experts have managed to trace the most recent location of Clinton's server -- something she did not specify during her news conference and a subject of much speculation, as the server's physical placement would provide early clues about whether the data stored on it was adequately secured against compromise by private-sector hackers and foreign intelligence services.

Fox News has previously reported that, with the aid of software named Maltego, experts had established that the server is up and running, receiving connectivity to the Internet through an Atlanta-based firm called Internap Network Services Corporation. Clinton's stern insistence at her news conference that her server "will remain private" would appear to rest, then, at least in part, on the inviolability of Internap.

Now, working with publicly available tools that map network connectivity, experts have established that the last "hop" before the mail server's Internet Protocol, or IP, address (listed as 64.94.172.146) is Internap's aggregator in Manhattan (listed as 216.52.95.10).

"This is a very strong indication that the clintonemail.com server is in Manhattan," the source told Fox News.

By entering the IP address for the Internap aggregator into existing databases, the experts obtained the exact geolocation coordinates for the aggregator -- revealed to be on lower Broadway, at the intersection with Chambers Street, some two blocks north of City Hall. This in turn suggests that the Clinton server itself lies within close proximity -- most likely former President Clinton's Harlem office, and not as far away as the Clintons' home in Chappaqua, N.Y.

That outside experts could so swiftly unearth such information left them convinced that the server remains, as presently configured, highly "vulnerable" to unauthorized intrusion -- even if, as most observers suspect, the server, with so much publicity now attendant on it, is no longer in active use. The hackers further concluded that Clinton's email operation was likely not much better secured when she was secretary of state.

To test that proposition, they took the relatively simple step of examining the source code on the front page of clintonemail.com. This yielded the discovery, sources told Fox News, that the Clintons have not been using the latest version of Microsoft Outlook Web Application (OWA) to send and receive emails. The most recent version of OWA is listed as 14.3.224.2, whereas tests show clintonemail.com to be using the older 14.2.390.1.

"[It's] an indication they're not keeping up with software upgrades," one hacker told Fox News. "If I were a bad guy, I'd start looking for any vulnerabilities in that older version they're using."

Work on the "replica" of the Clinton system also determined that the certificate for its TLS, or Transport Layer Security, is invalid -- a lapse that "makes the site less secure," the source said. A screen-grab provided to Fox News and shown here, illustrating the results of this test, showed the word "FAIL" appearing twice in a multifaceted stress-test for the security defenses of clintonemail.com.

Perhaps most concerning, private analysts determined that clintonemail.com has been running an older model of Microsoft Internet Information Services, or IIS -- specifically version 7.5, which has been documented to leave users exposed on multiple fronts. The website CVEDetails.com, which bills itself as "the ultimate security vulnerability datasource," is awash with descriptions of serious security vulnerabilities associated with version 7.5, including "memory corruption," "password disclosure vulnerability," and the enabling of "remote attackers to execute arbitrary code or cause a denial of service."
This article goes on with more security vulnerabilities. I am sure the hard drive will "crash" soon but hackers most likely have copies of the emails to show their kids and grand kids.
Posted by:Ebbomosh Hupemp2664

#9  Clueless Clinton’s Email Server Was Unencrypted For Three Months, Researchers Say
Posted by: Hupineger Glomomp52169    2015-03-13 19:55  

#8  And people want her to become President?

Who cares! Coming soon: Security Smecurity - Hillary's going to pay my mortgage! Hillary's going to pay my Gas! And my Rent! And my groceries!

The democrats know how to win elections. Promises and Boodle!

(And the GOP knows how to lose them!)
Posted by: CrazyFool   2015-03-13 13:47  

#7  analyst with experience in the intelligence community told Fox News: “If we learned that the foreign minister of a major foreign country was using her own private server to send and receive emails, and was relying on outdated commercial software to operate and protect it, that’d be a hallelujah moment for us.”

And people want her to become President?

Al
Posted by: frozen al   2015-03-13 12:53  

#6  Like I said a week ago, the server is online, and every Tom, Dick, and Harry is hacking on it.

Hillary claimed the SS was protecting the server. If it's in NYC, how likely is that?

When the crackers manage to extract the server contents, we may find that the email related to Clinton political machinations is far more interesting and damaging than anything related to Foggy Bottom.
Posted by: KBK   2015-03-13 11:43  

#5  The reason is that you don't kill the goose while she's laying golden eggs.

Or may lay even larger ones as President Clinton.
Posted by: CrazyFool   2015-03-13 10:58  

#4  No, Bobby. The reason no one has revealed her emails is that the server is so secure. /sarcasm

Of course, I am willing to bet some foreign/hostile intelligence service has cracked it. Russia, Israel, China, Iran, CIA, ... The list goes on.
Posted by: Rambler in Virginia   2015-03-13 09:16  

#3  Why can't some Bradlee Manning or Eddie Snowden get ahold of all her e-mails and leak them to the public?

'Cuz they're afraid of The Wrath of Hillary?
Posted by: Bobby   2015-03-13 07:25  

#2  I think they got it in time. A few years ago that server was hacked from an address in Ukraine before the conflict back in 2013 or something. Also some addys in the Caribbean.

There are other servers too. Most hacked, some not yer but I AM assured they are trying.

In either case, she believes the work she was paid for for US as a Public Servant belongs only to her.

Her basic view of things are we are here to support her.

I know at the point of HER election, the whore of Babylon, there is left no hope for this Nation that I AM hopeless for.

If, after all this time, this is what it comes to making her IT,
You must pack out of DC, not because it is a wasteland now, but for what it will end in.

FIRE.

This place is over
Posted by: newc   2015-03-13 01:01  

#1  This in turn suggests that the Clinton server itself lies within close proximity -- most likely former President Clinton's Harlem office, and not as far away as the Clintons' home in Chappaqua, N.Y.


Which 'could' mean that the server is actually hardware of the Clinton Foundation vs a private, home-based system supporting the State Department as the Hildebeest has repeatedly indicated.

We may be needing the plunger soon. The blockage does not appear to be going away.
Posted by: Besoeker   2015-03-13 00:24  

00:00