BugTraq
Major hack attack on the U.S. Senate Jan 22 2004 05:25PM
Richard M. Smith (rms computerbytesman com) (2 replies)
Re: Major hack attack on the U.S. Senate Jan 23 2004 03:28PM
Brian C. Lane (bcl brianlane com) (2 replies)
Re: [work] Re: Major hack attack on the U.S. Senate Jan 24 2004 06:46PM
opticfiber (opticfiber topsight net) (1 replies)
Re: [work] Re: Major hack attack on the U.S. Senate Jan 24 2004 08:27PM
Jonathan A. Zdziarski (jonathan nuclearelephant com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 08:59PM
Kevin Reardon (Kevin Reardon oracle com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 03:29AM
~Kevin Davis³ (computerguy cfl rr com) (3 replies)
This was clearly not a "hack attack". The title and opening content of this
article is quite intentionally misleading. The phrases "infiltration",
"monitoring secret memos", "exploited computer glitch", "hack attack" are
used. If you read the entire article you will find out the following:

First, "A technician hired by the new judiciary chairman, Patrick Leahy,
Democrat of Vermont, apparently made a mistake that allowed anyone to access
newly created accounts on a Judiciary Committee server shared by both
parties -- even though the accounts were supposed to restrict access only to
those with the right password."

Which means the Democrats screwed up setting up their own share point and
allowed public access to it. There was no "computer glitch" which was
"exploited". This was completely a human screw-up. And there was no
hacking ("exploitation of a computer glitch") done by the Republicans.
Unless you wish to call clicking on a share point configured with public
access and opening it up "hacking".

Additionally the Republicans allegedly "in the summer of 2002, their
computer technician informed his Democratic counterpart of the glitch".

The Republicans knew that the share was supposed to be protected (why else
would they inform the Democrats of the misconfiguration?) so they certainly
did something wrong despite (supposedly) warning the Democrats of the
problem, but not to the extent that the article - in the way that it was
written - would like you to believe.

----- Original Message -----
From: "Richard M. Smith" <rms (at) computerbytesman (dot) com [email concealed]>
To: "BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ (at) securityfocus (dot) com [email concealed]>
Sent: Thursday, January 22, 2004 12:25 PM
Subject: Major hack attack on the U.S. Senate

>
http://www.boston.com/news/nation/articles/2004/01/22/infiltration_of_fi
les_
> seen_as_extensive?mode=PF
>
> Infiltration of files seen as extensive
> Senate panel's GOP staff pried on Democrats
> By Charlie Savage, Globe Staff, 1/22/2004
>
> WASHINGTON -- Republican staff members of the US Senate Judiciary Commitee
> infiltrated opposition computer files for a year, monitoring secret
strategy
> memos and periodically passing on copies to the media, Senate officials
told
> The Globe.
>
> From the spring of 2002 until at least April 2003, members of the GOP
> committee staff exploited a computer glitch that allowed them to access
> restricted Democratic communications without a password. Trolling through
> hundreds of memos, they were able to read talking points and accounts of
> private meetings discussing which judicial nominees Democrats would
fight --
> and with what tactics.
>
> The office of Senate Sergeant-at-Arms William Pickle has already launched
an
> investigation into how excerpts from 15 Democratic memos showed up in the
> pages of the conservative-leaning newspapers and were posted to a website
> last November.
>
> With the help of forensic computer experts from General Dynamics and the
US
> Secret Service, his office has interviewed about 120 people to date and
> seized more than half a dozen computers -- including four Judiciary
servers,
> one server from the office of Senate majority leader Bill Frist of
> Tennessee, and several desktop hard drives.
>
> ...
>
>
>

[ reply ]
Re: Major hack attack on the U.S. Senate Jan 24 2004 05:16AM
rsh idirect com
Re: Major hack attack on the U.S. Senate Jan 23 2004 07:58PM
Kirk Spencer (kspencer ngrl org) (1 replies)
Re: Major hack attack on the U.S. Senate Jan 25 2004 02:06AM
Crispin Cowan (crispin immunix com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 06:48PM
Daniel Capo tco net br (2 replies)
Re: Major hack attack on the U.S. Senate Jan 29 2004 04:09PM
Mariusz Woloszyn (emsi ipartners pl) (3 replies)
RE: Major hack attack on the U.S. Senate Feb 03 2004 04:17PM
David Schwartz (davids webmaster com)
Re: Major hack attack on the U.S. Senate Feb 03 2004 02:56PM
Christian Vogel (chris obelix hedonism cx) (2 replies)
Re: Major hack attack on the U.S. Senate Feb 03 2004 08:06PM
Ron DuFresne (dufresne winternet com)
Re: Major hack attack on the U.S. Senate Feb 03 2004 04:13PM
Daniel Capo tco net br (1 replies)
Re: Major hack attack on the U.S. Senate Feb 04 2004 04:39PM
Thomas M. Payerle (payerle physics umd edu)
Re: [security] Re: Major hack attack on the U.S. Senate Feb 03 2004 04:02AM
rsh idirect com (1 replies)
Re: [security] Re: Major hack attack on the U.S. Senate Feb 03 2004 10:08PM
Bernie, CTA (cta hcsin net) (1 replies)
RE: [security] Re: Major hack attack on the U.S. Senate Feb 05 2004 11:41AM
Larry Seltzer (larry larryseltzer com)
Re: Major hack attack on the U.S. Senate Jan 24 2004 07:11PM
Dinesh Nair (dinesh alphaque com) (1 replies)
Re: Major hack attack on the U.S. Senate Jan 24 2004 08:32PM
ed the7thbeer com


 

Privacy Statement
Copyright 2010, SecurityFocus