Skip to content
safemode.space
All incidents
2011-04-17 (approximate)
data exposure

ESA FTP server compromise and credential disclosure (TinKode, 2011)

Confidence in this reading:
high

What happened

In mid-April 2011 a Romanian grey-hat researcher using the handle TinKode published the results of an intrusion into European Space Agency web infrastructure, timed to the anniversary of the return of Apollo 13. According to ESA's IT department the access was obtained through SQL injection. The published material comprised credentials for a set of ESA FTP servers in the esrin.esa.int and esa.it domains in clear text, a list of database users with hashed passwords, the hashed server root password, and administrator and editor account credentials, together with email addresses and passwords belonging to website user accounts. An ESA spokesman stated that the compromise reached only several internet-facing FTP servers dedicated to sharing data between the agency and its partners. ESA took the affected FTP servers offline, reset the compromised passwords and notified the users. No cited source reports that the main ESA website, mission systems or spacecraft data were reached.

One edge. What is well established is that valid credentials to ESA-operated servers were taken and published, and ESA confirmed it. What is not established is anything about mission data: ESA's own statement bounds the compromise to internet-facing FTP servers used for partner data sharing. Two of SPARTA's three citing techniques are rejected for that reason, and the third, REC-0001.03, is rejected as a keyword match rather than a scope match: leaked password hashes are not information about a spacecraft's cryptographic algorithms, key lifecycles or authentication scheme. That is the same failure mode the project's decision sub-category vocabulary calls wrong-scope-acronym. Specific credentials published by the attacker are not reproduced in this record.

Attack vector

SQL injection against ESA web infrastructure, per ESA's IT department, yielding access to internet-facing FTP servers used for data sharing with partners.

Operational impact

None reported against missions or spacecraft. ESA took the affected FTP servers offline, reset the compromised passwords and notified affected users.

Data compromised

Clear-text credentials for a set of ESA FTP servers, a list of database users with hashed passwords, the hashed server root password, administrator and editor account credentials, and email addresses and passwords for website user accounts. Specific credential values are recorded in the cited sources and are deliberately not reproduced here.

Disclosed

2011-04-17

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The published material was, in the main, working credentials to ESA-operated infrastructure: FTP account credentials in clear text, administrator and editor accounts, database users, and the server root password hash. REC-0003.04's subject is any credential letting an adversary authenticate as a legitimate actor in space, ground or supporting networks, and it names service accounts, station control credentials and maintenance accounts among the targets. Confidence is moderate rather than high because ESA's statement bounds the compromised hosts to internet-facing partner data-sharing servers, so these are credentials to ESA infrastructure without any cited source establishing that they reach mission systems.

    https://www.helpnetsecurity.com/2011/04/19/european-space-agency-website-and-ftp-servers-hacked/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Requires residence in mission ground infrastructure and siphoning telemetry streams, recorder playbacks, payload products or command histories. ESA's own statement is the obstacle: the compromise reached only internet-facing FTP servers for partner data sharing, and no cited source reports mission data of any kind leaving. Mapping it would assert more than the operator does.

  • Considered because the affected servers existed to share data with ESA's partners. EXF-0009's subject is leveraging a third party's infrastructure connected to the mission. Here the compromised infrastructure was ESA's own; the partners were counterparties, not victims.

  • SPARTA's IMP-0006 is theft of data gathered, processed and sent from the victim spacecraft. Credentials and account records are neither. The theft that did occur is carried by the REC-0003.04 edge, at the technique whose subject actually is credentials.

  • Credentials were exposed, but no cited source reports that any were used, before or after publication. ESA reset them and notified users. Exposure is not use.

  • The clearest scope error in this batch. REC-0001.03 is about the spacecraft's crypto picture: algorithms and modes, key types and lifecycles, authentication schemes, counter and time-tag handling, anti-replay windows. What leaked was a SHA1 password hash and a list of database users with hashed passwords. The only thing connecting the two is the word cryptographic. This is the wrong-scope-acronym pattern the project's decision sub-category vocabulary already names.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.