Information Security News mailing list archives
Re: FTC, FBI sites leave opening for hacker access
From: Kitetoa <kitetoa () kitetoa com>
Date: Mon, 11 Dec 2000 10:12:48 +0100
Hello, Richard Smith has not discovered anything. The bug on the FBI server has been there for years and if you look for it, you'll find posts on Bugtraq about it. Many Netscape servers are vulnerable to this problem. Read this paper (in french) about the FBI ant the NIPC published on dec 4(http://www.transfert.net/fr/cyber_societe/article.cfm?idx_rub=87&idx_art=2 845 ) after they warned about supposed DDoS attacks... And look at the screenshots. For both of them, you can load a java applet called Web Publisher for remote admin of the server. The funny thing is that the Web Publisher applet will load the site's content even if you don't enter a login. The Netscape servers are vulnerable to many other tricks that will let you browse through the directories... Best, K. -----Message d'origine----- De : William Knowles <wk () C4I ORG> À : ISN () SECURITYFOCUS COM <ISN () SECURITYFOCUS COM> Date : lundi 11 décembre 2000 08:56 Objet : [ISN] FTC, FBI sites leave opening for hacker access
http://www.infoworld.com/articles/hn/xml/00/12/08/001208hnfbiftc.xml?p=br&s
=9
By James Evans and Joris Evers Friday, Dec. 8, 2000 2:50 pm PT A EUROPEAN INFORMATION security specialist says that he discovered a potential security hazard in two U.S. government Web sites that use Netscape Communications Enterprise Server, including the online home of the U.S. Federal Bureau of Investigation (FBI). The specialist, once a hacker and now a member of HIT2000 Information Security, discovered a Web page that offers potential access to the U.S. Federal Trade Commission (FTC) Web site: www.ftc.gov. The IDG News Service later learned that a similar page exists on the FBI Web site: www.fbi.gov. Although it is not exactly clear what can be accessed from the apparent holes, the ex-hacker discovered he was able to access the FBI's Web site manager directory, showing a full directory listing of the FBI Web server. Security experts suggest any hint of a vulnerability can make the sites a target for hackers. "The less you give out to the public, the better," said Richard Smith, an Internet security consultant based in Brookline, Mass. "You really
ISN is hosted by SecurityFocus.com --- To unsubscribe email LISTSERV () SecurityFocus com with a message body of "SIGNOFF ISN".
Current thread:
- FTC, FBI sites leave opening for hacker access William Knowles (Dec 11)
- <Possible follow-ups>
- Re: FTC, FBI sites leave opening for hacker access Kitetoa (Dec 12)