BugTraq
Major hack attack on the U.S. Senate Jan 22 2004 05:25PM
Richard M. Smith (rms computerbytesman com) (2 replies)
Re: Major hack attack on the U.S. Senate Jan 23 2004 03:28PM
Brian C. Lane (bcl brianlane com) (2 replies)
Re: [work] Re: Major hack attack on the U.S. Senate Jan 24 2004 06:46PM
opticfiber (opticfiber topsight net) (1 replies)
Re: [work] Re: Major hack attack on the U.S. Senate Jan 24 2004 08:27PM
Jonathan A. Zdziarski (jonathan nuclearelephant com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 08:59PM
Kevin Reardon (Kevin Reardon oracle com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 03:29AM
~Kevin Davis³ (computerguy cfl rr com) (3 replies)
Re: Major hack attack on the U.S. Senate Jan 24 2004 05:16AM
rsh idirect com
Re: Major hack attack on the U.S. Senate Jan 23 2004 07:58PM
Kirk Spencer (kspencer ngrl org) (1 replies)
Agreed this was not a "hack attack" as usually considered. However, I would
raise two points. The first is simple - If someone starts reading files on a
computer to which they are not supposed to have access, do we not consider
this an attack? Even if the reason they got in is configuration errors?

Second, there is a question of which side's position is easier to believe.
You said: " Additionally the Republicans allegedly 'in the summer of 2002,
their computer technician informed his Democratic counterpart of the glitch.'
You cut off the next sentence which says: " Other staffers, however, denied
that the Democrats were told anything about it before November 2003." The
article does not state whether it was Democrat or Republican staffers.

I'll ask a simple question which indicates why I think the latter is more
probable: Can you think of a sysadmin who wouldn't act when told that _all_
his clients' passwords were invalid because the permissions were misapplied?

I think that the word "hack" is wrong. Otherwise, yes, I think the tenor of
the article has validity.

Kirk Spencer

On Thursday 22 January 2004 10:29 pm, ~Kevin Davis³ wrote:
> This was clearly not a "hack attack". The title and opening content of
> this article is quite intentionally misleading. The phrases
> "infiltration", "monitoring secret memos", "exploited computer glitch",
> "hack attack" are used. If you read the entire article you will find out
> the following:
>
> First, "A technician hired by the new judiciary chairman, Patrick Leahy,
> Democrat of Vermont, apparently made a mistake that allowed anyone to
> access newly created accounts on a Judiciary Committee server shared by
> both parties -- even though the accounts were supposed to restrict access
> only to those with the right password."
>
> Which means the Democrats screwed up setting up their own share point and
> allowed public access to it. There was no "computer glitch" which was
> "exploited". This was completely a human screw-up. And there was no
> hacking ("exploitation of a computer glitch") done by the Republicans.
> Unless you wish to call clicking on a share point configured with public
> access and opening it up "hacking".
>
> Additionally the Republicans allegedly "in the summer of 2002, their
> computer technician informed his Democratic counterpart of the glitch".
>
> The Republicans knew that the share was supposed to be protected (why else
> would they inform the Democrats of the misconfiguration?) so they certainly
> did something wrong despite (supposedly) warning the Democrats of the
> problem, but not to the extent that the article - in the way that it was
> written - would like you to believe.
(snip)

[ reply ]
Re: Major hack attack on the U.S. Senate Jan 25 2004 02:06AM
Crispin Cowan (crispin immunix com)
Re: Major hack attack on the U.S. Senate Jan 23 2004 06:48PM
Daniel Capo tco net br (2 replies)
Re: Major hack attack on the U.S. Senate Jan 29 2004 04:09PM
Mariusz Woloszyn (emsi ipartners pl) (3 replies)
RE: Major hack attack on the U.S. Senate Feb 03 2004 04:17PM
David Schwartz (davids webmaster com)
Re: Major hack attack on the U.S. Senate Feb 03 2004 02:56PM
Christian Vogel (chris obelix hedonism cx) (2 replies)
Re: Major hack attack on the U.S. Senate Feb 03 2004 08:06PM
Ron DuFresne (dufresne winternet com)
Re: Major hack attack on the U.S. Senate Feb 03 2004 04:13PM
Daniel Capo tco net br (1 replies)
Re: Major hack attack on the U.S. Senate Feb 04 2004 04:39PM
Thomas M. Payerle (payerle physics umd edu)
Re: [security] Re: Major hack attack on the U.S. Senate Feb 03 2004 04:02AM
rsh idirect com (1 replies)
Re: [security] Re: Major hack attack on the U.S. Senate Feb 03 2004 10:08PM
Bernie, CTA (cta hcsin net) (1 replies)
RE: [security] Re: Major hack attack on the U.S. Senate Feb 05 2004 11:41AM
Larry Seltzer (larry larryseltzer com)
Re: Major hack attack on the U.S. Senate Jan 24 2004 07:11PM
Dinesh Nair (dinesh alphaque com) (1 replies)
Re: Major hack attack on the U.S. Senate Jan 24 2004 08:32PM
ed the7thbeer com


 

Privacy Statement
Copyright 2010, SecurityFocus