Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

'USA TODAY' WEBSITE HACKED; PRANKSTERS MOCK BUSH, CHRISTIANITY...
Drudge Report ^ | 7/12/2002 | Matt Drudge

Posted on 07/11/2002 9:33:43 PM PDT by toupsie

XXXXX DRUDGE REPORT XXXXX THU JUL 11, 2002 23:32:38 ET XXXXX

'USA TODAY' WEBSITE HACKED; PRANKSTERS MOCK BUSH, CHRISTIANITY



The USA TODAY newspaper's website was broken into late Thursday evening by hackers who put up a series of stories blasting George Bush, Sercretary of Defense Donald Rumsfeld and Christianity.



Regular readers of the site could easily be misled because the hackers used the USA TODAY's basic design template, but multiple misspellings and bad grammar give away the prank.

One headline entitled 'Bush proposes another new Cabinet post' linked to an article purportedly filed by the ASSOCIATED PRESS:

Washington D.C. (AP) - Today, George W. Bush has proposed yet another cabinet level position. The Cabinet Minister for Propoganda and Popular Englightenment, will be setup to complement the recent addition of the department of Homeland Defense. It is reported that, if approved, Bush would appoint Dr. Joseph Goebbels to the post.

In recent weeks Tom Ridge has complained that his department has lacked the proper authority to keep terrorists from infiltrating the american mind. 95% of Americans, in a Gallop poll, agree that we have to do all we can to rid the country of terrorists, showing the public still strongly supports president Bush in his campaign against terrorism.

If the move is succesful, people close to the Whitehouse think there could be a turf war between Goebbels and White House Press Secretary Ari Fleischer. Since September 11th, Fleischer has come to enjoy controling public opinion and has expressed dissatisfaction with the idea of a Popular Englightement Minister. There was a constant flow of customers buying everything.



Headlines 'Opps says the Pope; Christianity a Sham!' and

'Donald Rumsfeld: An American Beauty?' also linked to mock articles. The Rumsfeld article alleged that the Secretary of Defense is homosexual.

At of 11 pm EDT USA TODAY could no longer be accessed by the public.

Developing...

-----------------------------------------------------------
Filed by Matt Drudge
Reports are moved when circumstances warrant
http://www.drudgereport.com for updates
(c)DRUDGE REPORT 2001
Not for reproduction without permission of the author



TOPICS: Breaking News; Crime/Corruption; News/Current Events; Technical
KEYWORDS: tech; usatoday; websitehack
Navigation: use the links below to view more comments.
first previous 1-2021-4041-57 last
Comment #41 Removed by Moderator

To: Incorrigible
Of course, UNIX systems are also vulnerable as Bush2000 has pointed out numerous times but that doesn't seem to get the press about Microsoft.

From SecurityFocus, a list of vulns by product for the last 4 years:

Apache 2.0

 2002-06-17:  Apache Chunked-Encoding Memory Corruption Vulnerability

One vuln.

One vuln in 4 years

.

Now, Microsoft IIS 5.0:

 2002-05-27:  Microsoft IIS 5.0 Denial Of Service Vulnerability
 2002-05-27:  Microsoft IIS HTR Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-18:  Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability
 2002-04-16:  Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
 2002-04-10:  Microsoft IIS Help File Search Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Heap Overflow Variant Vulnerability
 2002-04-10:  Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Header Field Delimiter Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
 2002-04-10:  Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
 2002-03-05:  Microsoft IIS Authentication Method Disclosure Vulnerability
 2002-02-19:  Multiple Vendor HTTP CONNECT TCP Tunnel Vulnerability
 2002-01-31:  Microsoft MSDTC Service Denial of Service Vulnerability
 2002-01-16:  Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
 2001-12-11:  Microsoft IIS False Content-Length Field DoS Vulnerability
 2001-08-15:  Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS 5.0 In-Process Table Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
 2001-08-15:  Microsoft IIS MIME Header Denial of Service Vulnerability
 2001-08-08:  MS IIS Internal IP Address/Internal Network Name Disclosure Vulnerability
 2001-07-04:  Microsoft IIS Device File Local DoS Vulnerability
 2001-07-04:  Microsoft IIS Device File Remote DoS Vulnerability
 2001-05-17:  IIS WebDav Lock Method Memory Leak DoS Vulnerability
 2001-05-15:  MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
 2001-05-14:  Microsoft IIS Various Domain User Account Access Vulnerability
 2001-05-06:  Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
 2001-05-01:  Microsoft IIS 5.0 .printer ISAPI Extension Buffer Overflow Vulnerability
 2001-03-16:  Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
 2001-03-08:  Microsoft IIS WebDAV Denial of Service Vulnerability
 2001-03-01:  Microsoft IIS Multiple Invalid URL Request DoS Vulnerability
 2001-03-01:  Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
 2001-01-29:  Microsoft IIS File Fragment Disclosure Vulnerability
 2000-12-22:  Microsoft IIS Front Page Server Extension DoS Vulnerability
 2000-11-06:  Microsoft IIS Executable File Parsing Vulnerability
 2000-10-23:  Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability
 2000-10-17:  Microsoft IIS and PWS Extended Unicode Directory Traversal Vulnerability
 2000-10-04:  Microsoft IIS 5.0 Indexed Directory Disclosure Vulnerability
 2000-08-21:  Microsoft FrontPage/IIS Cross Site Scripting shtml.dll Vulnerability
 2000-08-21:  Microsoft IIS Cross Site Scripting .shtml Vulnerability
 2000-08-14:  Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability
 2000-08-10:  Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
 2000-07-17:  Microsoft IIS 4.0/5.0 Source Fragment Disclosure Vulnerability
 2000-07-14:  Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
 2000-07-13:  Microsoft IIS Internal IP Address Disclosure Vulnerability
 2000-05-14:  Microsoft IIS FTP Denial of Service Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed File Extension DoS Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed Filename Request Vulnerability
 2000-05-10:  Microsoft IIS 4.0/5.0 Malformed .htr Request Vulnerability
 2000-05-06:  Microsoft Frontpage Server Extensions Path Disclosure Vulnerability
 2000-04-12:  Microsoft IIS 4.0/5.0 Escaped Characters Vulnerability
 2000-03-30:  Microsoft IIS UNC Mapped Virtual Host Vulnerability
 2000-03-08:  Microsoft IIS UNC Path Disclosure Vulnerability
 2000-02-09:  NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability
 1999-01-26:  NT IIS IISAPI Extension Enumerate Root Web Server Directory Vulnerability

It is, in my opinion, professional incompetence to use MS IIS for any mission-critical web work.

42 posted on 07/12/2002 7:58:30 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 38 | View Replies]

To: Incorrigible
Of course, UNIX systems are also vulnerable as Bush2000 has pointed out numerous times but that doesn't seem to get the press about Microsoft.

From SecurityFocus, a list of vulns by product for the last 4 years:

Apache 2.0

 2002-06-17:  Apache Chunked-Encoding Memory Corruption Vulnerability

One vuln.

One vuln in 4 years

.

Now, Microsoft IIS 5.0:

 2002-05-27:  Microsoft IIS 5.0 Denial Of Service Vulnerability
 2002-05-27:  Microsoft IIS HTR Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-18:  Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability
 2002-04-16:  Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
 2002-04-10:  Microsoft IIS Help File Search Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Heap Overflow Variant Vulnerability
 2002-04-10:  Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Header Field Delimiter Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
 2002-04-10:  Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
 2002-03-05:  Microsoft IIS Authentication Method Disclosure Vulnerability
 2002-02-19:  Multiple Vendor HTTP CONNECT TCP Tunnel Vulnerability
 2002-01-31:  Microsoft MSDTC Service Denial of Service Vulnerability
 2002-01-16:  Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
 2001-12-11:  Microsoft IIS False Content-Length Field DoS Vulnerability
 2001-08-15:  Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS 5.0 In-Process Table Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
 2001-08-15:  Microsoft IIS MIME Header Denial of Service Vulnerability
 2001-08-08:  MS IIS Internal IP Address/Internal Network Name Disclosure Vulnerability
 2001-07-04:  Microsoft IIS Device File Local DoS Vulnerability
 2001-07-04:  Microsoft IIS Device File Remote DoS Vulnerability
 2001-05-17:  IIS WebDav Lock Method Memory Leak DoS Vulnerability
 2001-05-15:  MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
 2001-05-14:  Microsoft IIS Various Domain User Account Access Vulnerability
 2001-05-06:  Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
 2001-05-01:  Microsoft IIS 5.0 .printer ISAPI Extension Buffer Overflow Vulnerability
 2001-03-16:  Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
 2001-03-08:  Microsoft IIS WebDAV Denial of Service Vulnerability
 2001-03-01:  Microsoft IIS Multiple Invalid URL Request DoS Vulnerability
 2001-03-01:  Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
 2001-01-29:  Microsoft IIS File Fragment Disclosure Vulnerability
 2000-12-22:  Microsoft IIS Front Page Server Extension DoS Vulnerability
 2000-11-06:  Microsoft IIS Executable File Parsing Vulnerability
 2000-10-23:  Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability
 2000-10-17:  Microsoft IIS and PWS Extended Unicode Directory Traversal Vulnerability
 2000-10-04:  Microsoft IIS 5.0 Indexed Directory Disclosure Vulnerability
 2000-08-21:  Microsoft FrontPage/IIS Cross Site Scripting shtml.dll Vulnerability
 2000-08-21:  Microsoft IIS Cross Site Scripting .shtml Vulnerability
 2000-08-14:  Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability
 2000-08-10:  Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
 2000-07-17:  Microsoft IIS 4.0/5.0 Source Fragment Disclosure Vulnerability
 2000-07-14:  Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
 2000-07-13:  Microsoft IIS Internal IP Address Disclosure Vulnerability
 2000-05-14:  Microsoft IIS FTP Denial of Service Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed File Extension DoS Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed Filename Request Vulnerability
 2000-05-10:  Microsoft IIS 4.0/5.0 Malformed .htr Request Vulnerability
 2000-05-06:  Microsoft Frontpage Server Extensions Path Disclosure Vulnerability
 2000-04-12:  Microsoft IIS 4.0/5.0 Escaped Characters Vulnerability
 2000-03-30:  Microsoft IIS UNC Mapped Virtual Host Vulnerability
 2000-03-08:  Microsoft IIS UNC Path Disclosure Vulnerability
 2000-02-09:  NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability
 1999-01-26:  NT IIS IISAPI Extension Enumerate Root Web Server Directory Vulnerability

It is, in my opinion, professional incompetence to use MS IIS for any mission-critical web work.

43 posted on 07/12/2002 8:01:53 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 38 | View Replies]

To: All
Ooops, sorry about that -- I did *not* mean to post that twice.
44 posted on 07/12/2002 8:02:38 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 41 | View Replies]

To: ELS; Dominic Harr
Hi ELS,

I'm sorry if my rant cast an aspersions on your abilities.  Unintended.

The Nimba and Code Red viruses could have been prevented if the patch that Microsoft released months earlier had been installed.  In fact, it was the description of the problem on Microsoft's site that gave the hackers the idea.  :-(

The original goal was to make administration and all features of the server web enabled and other features open by default.  Though this makes computing easier for those trying to implement solutions (like running executables in Outlook), it also makes it easier for hackers.  Thus, Microsoft will be shipping OSes in the future without installing software and keeping ports closed.  Safer yes.  Less functional for users, yes.

The above is the default for UNIX implementations and thus, fewer hack attacks.  Microsoft has reconciled itself to the fact that there people who are unfairly against Microsoft and wish it harm (Dominic???  :-)  ).

45 posted on 07/12/2002 8:24:44 AM PDT by Incorrigible
[ Post Reply | Private Reply | To 40 | View Replies]

To: Incorrigible
Microsoft has reconciled itself to the fact that there people who are unfairly against Microsoft and wish it harm (Dominic??? :-) ).

If the above list didn't prove something about the quality of the product to you, then by all means continue using it.

I don't wish MS harm, anymore than I wish 'Brittney Spears' wrong. I just think it's devastating for our tech industry to have a company using illegal means to force inferior products on the market, and want the illegalities to stop.

Other than stopping MS's illegalities, I wish them no harm at all.

46 posted on 07/12/2002 8:33:04 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 45 | View Replies]

To: Incorrigible
No offense taken. Most of my work is with an application server (Opentext Livelink) and the Web server is merely a conduit between the browser and the app server. I could have switched to NS ES, but they charge a fee :-) whereas I was able to download Apache for free, install it, and get back to work.

I'm not really a strong partisan for any particular OS. I have used the major ones (DOS/Win, Mac, Unix) and they all have pros and cons, IMHO.

47 posted on 07/12/2002 10:03:00 AM PDT by ELS
[ Post Reply | Private Reply | To 45 | View Replies]

To: toupsie
Hmmmm. Bad spelling? Didn't know Jesse Jackson was a hacker.
48 posted on 07/12/2002 11:01:34 AM PDT by Democratic_Machiavelli
[ Post Reply | Private Reply | To 1 | View Replies]

To: Carry_Okie
They were also heavily into occultism/satanism. Nice bunch of boys, huh?
49 posted on 07/12/2002 12:02:25 PM PDT by Marysecretary
[ Post Reply | Private Reply | To 15 | View Replies]

To: meyer
yeah, I thought the same thing...barf!
50 posted on 07/12/2002 12:04:02 PM PDT by Marysecretary
[ Post Reply | Private Reply | To 34 | View Replies]

To: Marysecretary
Just like the mucky-mucks in the UN.

The same people. The same beliefs. The same goals. And...

The same means.
51 posted on 07/12/2002 12:29:10 PM PDT by Carry_Okie
[ Post Reply | Private Reply | To 49 | View Replies]

To: Vidalia
I disagree. Drudge is relevant.
52 posted on 07/12/2002 12:29:24 PM PDT by Maedhros
[ Post Reply | Private Reply | To 5 | View Replies]

To: Dominic Harr
I don't wish MS harm, anymore than I wish 'Brittney Spears' wrong.

Surrrrrrre, you don't. You just confuse poor administration with poor product quality.
53 posted on 07/12/2002 12:35:57 PM PDT by Bush2000
[ Post Reply | Private Reply | To 46 | View Replies]

To: Dominic Harr; All
One vuln in 4 years

This, of course, is another one of your whopper lies. Follow the link and lookup Apache Software Foundation. You will find dozens of serious vulnerabilities. But that's not in the script, eh? It depends on how you define "serious", Clinton pretender.
54 posted on 07/12/2002 12:53:55 PM PDT by Bush2000
[ Post Reply | Private Reply | To 53 | View Replies]

To: Bush2000
Posted the list, and link, above.

On vuln in 4 years, for Apache.

And for IIS?

If you can't see the quality difference in those two pieces of software from that list of defects, I can't help you.

55 posted on 07/12/2002 12:57:56 PM PDT by Dominic Harr
[ Post Reply | Private Reply | To 54 | View Replies]

To: Col. Forbin
Thanks for pointing this out. I jumped the gun. The parody were making implications that Bush was Nazi-like, not Christianity. But the accusation that Christianity led to Naziism is a standard leftist lie. They mocked the Pope and Rumsfeld too.
56 posted on 07/12/2002 2:34:00 PM PDT by Pyro7480
[ Post Reply | Private Reply | To 41 | View Replies]

To: toupsie
The USA TODAY newspaper's website was broken into late Thursday evening by hackers who put up a series of stories blasting George Bush, Sercretary of Defense Donald Rumsfeld and Christianity.

It's gotta be Algore, he has the secret Web password that allows him to hack any website-- he installed on the day he invented the Internet.

57 posted on 07/12/2002 4:45:24 PM PDT by RobFromGa
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-57 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson