ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Political site leaves backdoor open

Published: 25 Aug 2004 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Rock the Vote, a grassroots movement that aims to convince younger Americans to vote, accidentally left its Web site publishing tools accessible to anyone who knew where to look.

While a Google query would not have found the site, a person who knew the address of the site's management pages could have posted news items, events and other information to the Web site. The organisation's list of contacts was also available.

"We have already password-protected those pages," David Pruter, multimedia developer with the group, said of efforts to remedy the problem. "We made sure that nothing was posted that shouldn't have been."

Rock the Vote resecured the site on Tuesday after being notified of the problem by ZDNet UK sister site CNET News.com.

Renewed scrutiny is being placed on political Web sites as the presidential election nears. A Web page misconfiguration in liberal political group MoveOn.org's subscriber pages left dozens of records easily searchable through simple Google queries. Each page included a subscriber's name, email address and the mailing lists to which he or she had subscribed.

The MoveOn information leak was the latest incident of "Google hacking," the practice of using the search engine's advanced features to find private data leaked by Web sites.

Rock the Vote's misconfigured management pages were not much of a privacy leak, said Jeff Link, a student at Bradley University and -- as the Webmaster of the Bradley Student Advocacy Group -- a partner of Rock the Vote. Some partner information could have been found by someone who knew the address, but it was limited to names, organisations and email addresses.

"There wasn't a lot of information on the partners," Link said. "Even if they did get the list, it would just mean that I would get more spam -- but that gets deleted anyway."

Link discovered the unsecured pages when he looked at his site's logs and found that one partner had gone from the Rock the Vote management page to his site. Web site logs usually retain the "referrer link," which points back to the last page a visitor browsed. Link used that address to jump back to the administration page, finding it unprotected.

Rock the Vote's Pruter did not believe that anyone had used the issue to change any of the site's content.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
70 out of 124 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

JUNIOR JAVA DEVELOPER

Responsibilities: Application Development Creation of the following to promote the development of the Net-a-Porter web site: - Front-end JSP pages - ...

C# ASP.NET Developer Required in Warwickshire

My large Public Sector Client in Warwickshire is actively seeking a strong C# ASP.NET developer to undertake a 6 month project. It is imperative that ...

Business Solutions Manager

To be considered for this position, please apply using the link below. Responsibilities: - Identify and address business problems and opportunities ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment