Advertisement
Promo

Security threats Toolkit

Political site leaves backdoor open

Published: 25 Aug 2004 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Rock the Vote, a grassroots movement that aims to convince younger Americans to vote, accidentally left its Web site publishing tools accessible to anyone who knew where to look.

While a Google query would not have found the site, a person who knew the address of the site's management pages could have posted news items, events and other information to the Web site. The organisation's list of contacts was also available.

"We have already password-protected those pages," David Pruter, multimedia developer with the group, said of efforts to remedy the problem. "We made sure that nothing was posted that shouldn't have been."

Rock the Vote resecured the site on Tuesday after being notified of the problem by ZDNet UK sister site CNET News.com.

Renewed scrutiny is being placed on political Web sites as the presidential election nears. A Web page misconfiguration in liberal political group MoveOn.org's subscriber pages left dozens of records easily searchable through simple Google queries. Each page included a subscriber's name, email address and the mailing lists to which he or she had subscribed.

The MoveOn information leak was the latest incident of "Google hacking," the practice of using the search engine's advanced features to find private data leaked by Web sites.

Rock the Vote's misconfigured management pages were not much of a privacy leak, said Jeff Link, a student at Bradley University and -- as the Webmaster of the Bradley Student Advocacy Group -- a partner of Rock the Vote. Some partner information could have been found by someone who knew the address, but it was limited to names, organisations and email addresses.

"There wasn't a lot of information on the partners," Link said. "Even if they did get the list, it would just mean that I would get more spam -- but that gets deleted anyway."

Link discovered the unsecured pages when he looked at his site's logs and found that one partner had gone from the Rock the Vote management page to his site. Web site logs usually retain the "referrer link," which points back to the last page a visitor browsed. Link used that address to jump back to the administration page, finding it unprotected.

Rock the Vote's Pruter did not believe that anyone had used the issue to change any of the site's content.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
71 out of 126 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters