Interesting People mailing list archives

IP: Hackers invade Justice Dept - inside job, or just


From: Dave Farber <farber () central cis upenn edu>
Date: Mon, 19 Aug 1996 18:28:00 -0400

Date: Mon, 19 Aug 96 18:25:21 +0100
From: "Dave Wilson" <dave () wilson net>




Hackers invade Justice
Department Web site





The alleged DOJ prank was almost certainly the result of a faulty CGI script
which gave the intruders the ability to modify certain aspects of the pages.
This problem is not at all uncommon, and even shows up on sites with
"experienced" security administrators. For instance, if you don't have
certain restrictions set up on what people can do at your site via the
script, and you have a page that asks me to fill out certain information
(such as my address) using such a script, the data I send you can direct the
host computer to reformat its hard drive. This sort of thing happens all the
time, but to the best of my recollection last time it got publicity was last
summer when somebody allegedly broke into the site for a movie called
"Hackers" and altered the images of the stars (goatees and horns, that sort
of thing) and trashed the film using text. I've got GIF's of this stored
somewhere if anybody wants them; which reminds me, did anybody actually
*see* the altered DOJ site, and do you have peechers?


-dave
Dave Wilson
"Well-meaning but dull-witted media dupe of the One World Government."


You can also send mail to dave.wilson () chronicle com
No, it doesn't matter which address you use.


Current thread: