Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Attacker Infects Healthcare.gov Test Server

Federal officials say no consumer data was impacted and second open enrollment period on HealthCare.gov will not be affected.

Hackers breached a test server supporting the Obama administration's HealthCare.gov website, but did not make off with any consumer data, according to federal officials.

Security experts long have been concerned about potential security vulnerabilities in the Obama Administration's HealthCare.gov site, which got off to a rocky start last year after its launch.

In a prepared statement, Aaron Albright, a spokesperson for the Department of Health and Human Services' Centers for Medicare and Medicaid Services (CMS), says the agency's review indicates the compromised server did not contain consumers' personal information, and no data was stolen. In addition, it does not appear that the HealthCare.gov website was specifically targeted, he says.

A Wall Street Journal report says the server was compromised in July. The attacker was able to upload malware to server -- an infection that was discovered in August when the CMS security team uncovered an anomaly via the system security logs of one of the servers on the system. Further investigation found malicious files on the test server.

The malware was described as "commonplace," and was designed to launch a denial-of-service attack against other sites, as opposed to exfiltrating data. Additionally, an analysis of network traffic revealed no evidence information was sent to an external IP address.

A source with the Department of Health and Human Services reportedly told The Wall Street Journal  that the test server was protected by a default password and was never meant to be connected to the Internet.

"Like a lot of the other breaches that have made headlines over the past few months, this was the result of simple, compounded mistakes," says Eric Cowperthwaite, vice president of advanced security and strategy at Core Security. "A basic security flaw went overlooked, and it was assumed that because the system in question wasn’t supposed to be connected to the internet, it wasn’t high priority and didn’t warrant continuous monitoring. But accidently connecting a system like this to the Internet happens all the time. Complex enterprise systems are susceptible to mistakes."

Even though federal officials say no data was stolen, there are still reasons to be concerned, argues Trey Ford, global security strategist at Rapid7.

"We do not have clarity in regard to the lack of change control on the firewall, and how or why this test server was exposed to the Internet," Ford tells Dark Reading. "Finally, we do not know how many daily scans went un-reviewed -- it seems like several weeks, so this also points to a lack of attention to the Internet exposed edge of this data center."

Auditors will find production data in test environments more frequently than they’ll want to admit, he adds.

"I am very interested in learning more about how the test environment reflects production -- while we hope and trust that production systems no longer have default credentials, we also want to know that live production data is carefully managed, and does not live on a neglected test network," he says.

No matter the size of the organization, ensuring total visibility and understanding security risks is critical to protecting users, says Brad Hibbert, vice president of product strategy and operations at BeyondTrust. This includes both internal and external risks.

"Many of the latest attacks we have seen in the news target these lower priority systems where hackers gain a foothold in the environment," he says.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/8/2014 | 12:00:32 PM
Re: An infection you hope to avoid
I agree with this. It created the additional damage in reputation and people would not hear test servers aspect of it, they will simply hear "the breach".
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/8/2014 | 11:58:48 AM
Re: Is it believable?
I agree, it is connected somewhere, such as database server, web server, application server, or any other third part interfaces to be tested. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/8/2014 | 11:56:53 AM
No internet no security
 

Enjoyed reading the article. Thanks for sharing it. As article points out no internet does not mean no security. There is lots of other threats coming from internal environment, more threats from inside than outside actually, we do not hear most for the inside threats and breaches.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
9/8/2014 | 9:36:28 AM
Re: An infection you hope to avoid
-- "a headline that you never want to see"

Unlikely that the headlines are going to get less frequent and the problem less critical.
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
9/8/2014 | 9:10:42 AM
Re: Is it believable?
I absolutely agree.  Just because it was a test server that wasn't supposed to connect to the internet, it doesn't change the fact that it didn't have the security controls in place.  What if it had indeed been connected to the internet and could have data siphoned off.  Or even yet, despite being a test server, I am sure it was connected to other systems.  All it takes is one server to be overlooked from a security perspective for the whole infrastructure to potentially become at risk for a breach.
PaulS681
50%
50%
PaulS681,
User Rank: Apprentice
9/6/2014 | 1:36:01 PM
Is it believable?
Is it believable that no consumer data was impacted? How do they know for sure?

Are we to just believe them that because this was a test server it had no real data on it? Many test systems use real data to properly test things out. While it is possible that there was none it still troublesome.
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Ninja
9/5/2014 | 6:46:17 PM
An infection you hope to avoid
Damage was minimal but this is still a headline that you never want to see.
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...