Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Major hack attack on the U.S. Senate

Re: Major hack attack on the U.S. Senate

From: Brian C. Lane <bcl_at_brianlane.com>
Date: Fri, 23 Jan 2004 07:28:23 -0800

On Thu, 2004-01-22 at 09:25, Richard M. Smith wrote:
> http://www.boston.com/news/nation/articles/2004/01/22/infiltration_of_files_
> seen_as_extensive?mode=PF
>
> Infiltration of files seen as extensive
> Senate panel's GOP staff pried on Democrats
> By Charlie Savage, Globe Staff, 1/22/2004
>
> WASHINGTON -- Republican staff members of the US Senate Judiciary Commitee
> infiltrated opposition computer files for a year, monitoring secret strategy
> memos and periodically passing on copies to the media, Senate officials told
> The Globe.
>

[snip]

You left off the most important fact in your snip. The final paragraph
pretty well sums it up:

"A technician hired by the new judiciary chairman, Patrick Leahy,
Democrat of Vermont, apparently made a mistake that allowed anyone to
access newly created accounts on a Judiciary Committee server shared by
both parties -- even though the accounts were supposed to restrict
access only to those with the right password."

I sure wouldn't call this a major hack attack. Someone goofed. Someone
else took advantage of the goof (and according to some reports even
reported it to the bonehead technician).

One one hand you really shouldn't look at someone else's files. On the
other hand if you're cooking up dirty tricks you darn well ought to make
sure your memos are protected, not stored in the clear on a shared
system.

And these are the jokers who want to dictate to us how to secure the
Internet and stop SPAM? Heh!

Brian

---[Office 71.6F]--[Fridge 38.4F]---[Fozzy 88.8F]--[Coaster 71.7F]---
Linux Software Developer http://www.brianlane.com

Received on Jan 23 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos