Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

DoD offering admin privileges on .mil Web sites
The Register ^ | January 24, 2003 | Thomas C Greene

Posted on 01/24/2003 9:34:25 PM PST by HAL9000

Care to register a .mil Web site of your own for free? The DoD has gone out of its way to make it a snap. An unbelievably badly-protected admin interface welcomes you to register whatever domain you please (http://Rotten.mil anyone?), or edit anything they've already got. The interface is so ludicrously unprotected that it's been cached by Google and fails to mention that you must be authorized to muck about with it. Incredibly, default passwords are cheerfully provided on the page.

Following an anonymous tip from an observant Reg reader, we've encountered the page in question in the Google cache, and after a bit of our own poking about have also discovered an equally unprotected (and Google-cached) admin interface encouraging us to add a new user, like ourselves, say, which requires no authentication.

All you have to do is find that page and you can set yourself up with a user account, manage your new .mil Web site, fiddle about with other people's .mil Web sites, and generally make an incredible nuisance of yourself. We are, of course, straining against every natural, journalistic impulse in our beings by neglecting to mention any useful search strings with which to find it.

Another unprotected and cached page, this one discovered by our tipster, lists traffic to a major DoD Web site by URL/IP address. This worries us because it may list .mil sites and networked DoD machines that are not public, not hotlinked anywhere, and which might contain (or be networked with other machines that contain) sensitive data. Merely knowing that all those URLs and IP addys are valid and owned by DoD would give a significant advantage to attackers by narrowing their target area dramatically.

We have e-mailed the person who manages these sites - twice in fact - but so far have not been graced with a reply. We were hoping that they might be inclined to fix this mess quickly so that we could safely include the details in our report. Unfortunately we have to withhold them until we're confident that these security snafus are under control.

Ironically, US Defense Secretary Donald Rumsfeld recently ordered DoD to purge military Web sites of information that might benefit evildoers. That's all well and good, but it might behoove the DoD to stop offering them admin privileges first. ®



TOPICS: Crime/Corruption; Extended News; Foreign Affairs; News/Current Events
KEYWORDS: dod; internet; mil
Some heads are going to roll over this one.
1 posted on 01/24/2003 9:34:25 PM PST by HAL9000
[ Post Reply | Private Reply | View Replies]

To: HAL9000
I am laughing so hard... my side hurts...

unbelievable.
2 posted on 01/24/2003 10:11:16 PM PST by Robert_Paulson2 (clintonsgotusbytheballs?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
http://sites.defenselink.mil/servlet/DataEntry
3 posted on 01/24/2003 10:15:57 PM PST by chnsmok (Mussel men rock! http://www.freerepublic.com/focus/news/828114/posts)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
And it was people like this that were going to be incharge of TIA security.


4 posted on 01/24/2003 10:24:16 PM PST by Karsus (TrueFacts=GOOD, GoodFacts=BAD))
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
The DoD has gone out of its way to make it a snap. An unbelievably badly-protected admin interface welcomes you to register whatever domain you please (http://Rotten.mil anyone?),...

I smell a honeypot.

5 posted on 01/24/2003 10:52:01 PM PST by The Duke
[ Post Reply | Private Reply | To 1 | View Replies]

To: The Duke
Interesting.
6 posted on 01/24/2003 10:58:41 PM PST by HAL9000
[ Post Reply | Private Reply | To 5 | View Replies]

To: chnsmok
LOL!
7 posted on 01/25/2003 11:28:46 PM PST by swarthyguy
[ Post Reply | Private Reply | To 3 | View Replies]

Comment #8 Removed by Moderator

Comment #9 Removed by Moderator

To: seamole
I sure wasn't about to try it.
10 posted on 01/25/2003 11:51:19 PM PST by chnsmok (Dware vs. 100 mussels! Pay per mussel! http://www.freerepublic.com/focus/news/829652/posts?page=1)
[ Post Reply | Private Reply | To 9 | View Replies]

To: chnsmok
google cached page: http://216.239.57.100/search?q=cache:fbpd-4b2KmsC:sites.defenselink.mil/servlet/DataEntry+&hl=en&ie=UTF-8
11 posted on 01/26/2003 9:42:00 AM PST by LandOfTheFreeHomeOfTheBrave
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson