Operation TIPS

From: George Imburgia (gtiat_private)
Date: Wed Jul 17 2002 - 07:50:48 PDT

  • Next message: Jeremy Junginger: "Smashing the Stack?"

    Recently, the federal government started a program to recruit utility
    workers, postal employees, truck drivers and such into an informant
    program;
    
    http://www.citizencorps.gov/tips.html
    
    When you choose to join, it takes you to;
    
    https://www.citizencorps.gov/citizen/jsp/volunteerform.jsp?programName=5
    
    After looking at the source code of this url, it became apparent that
    sanity checking of user input is done on the client. Testing confirmed
    that this is exploitable.
    
    In other words, it's easy to retrieve a list of their volunteer
    informants.
    
    Apparently they plan to address issues like this the easy way, by locking
    up people that exploit it for life. This is a FEMA site, which would
    qualify for a life sentence under the "Cyber Security Enhancement Act of
    2002".
    
    
    George Imburgia
    Senior Network Security Engineer
    Capitol Networking
    gtiat_private
    



    This archive was generated by hypermail 2b30 : Wed Jul 17 2002 - 10:30:05 PDT