Information Security News mailing list archives

Re: FTC, FBI sites leave opening for hacker access


From: Kitetoa <kitetoa () kitetoa com>
Date: Mon, 11 Dec 2000 10:12:48 +0100

Hello,

Richard Smith has not discovered anything.
The bug on the FBI server has been there for years and if you look for it,
you'll find posts on Bugtraq about it.

Many Netscape servers are vulnerable to this problem.
Read this paper (in french) about the FBI ant the NIPC published on dec
4(http://www.transfert.net/fr/cyber_societe/article.cfm?idx_rub=87&idx_art=2
845 )
after they warned about supposed DDoS attacks... And look at the
screenshots. For both of them, you can load a java applet called Web
Publisher for remote admin of the server. The funny thing is that the Web
Publisher applet will load the site's content even if you don't enter a
login.
The Netscape servers are vulnerable to many other tricks that will let you
browse through the directories...

Best,
K.

-----Message d'origine-----
De : William Knowles <wk () C4I ORG>
À : ISN () SECURITYFOCUS COM <ISN () SECURITYFOCUS COM>
Date : lundi 11 décembre 2000 08:56
Objet : [ISN] FTC, FBI sites leave opening for hacker access


http://www.infoworld.com/articles/hn/xml/00/12/08/001208hnfbiftc.xml?p=br&s
=9

By James Evans and Joris Evers
Friday, Dec. 8, 2000 2:50 pm PT

A EUROPEAN INFORMATION security specialist says that he discovered a
potential security hazard in two U.S. government Web sites that use
Netscape Communications Enterprise Server, including the online home
of the U.S. Federal Bureau of Investigation (FBI).

The specialist, once a hacker and now a member of HIT2000 Information
Security, discovered a Web page that offers potential access to the
U.S. Federal Trade Commission (FTC) Web site: www.ftc.gov. The IDG
News Service later learned that a similar page exists on the FBI Web
site: www.fbi.gov.

Although it is not exactly clear what can be accessed from the
apparent holes, the ex-hacker discovered he was able to access the
FBI's Web site manager directory, showing a full directory listing of
the FBI Web server.

Security experts suggest any hint of a vulnerability can make the
sites a target for hackers.

"The less you give out to the public, the better," said Richard Smith,
an Internet security consultant based in Brookline, Mass. "You really

ISN is hosted by SecurityFocus.com
---
To unsubscribe email LISTSERV () SecurityFocus com with a message body of
"SIGNOFF ISN".


Current thread: