 |
Monday, September 24, 2001 |
Will Knight, New Scientist, 20 Sep 01
http://www.newscientist.com/news/news.jsp?id=ns99991329
A computer security expert has revealed how he altered news articles posted
to Yahoo!'s web site without permission. The incident highlights the danger
of hackers posting misleading information to respected news outlets.
Freelance security consultant Adrian Lamo demonstrated that, armed only with
an ordinary Internet browser, he could access the content management system
used by Yahoo!'s staff use to upload daily news. He added the false quotes
to stories to prove the hole was real to computer specialist site Security
Focus. Yahoo! has issued a statement saying the vulnerability has been
fixed and security is being reviewed. But experts say that the incident
demonstrates a serious risk. "Just think how much damage you could do by
changing the quarterly results of a company in a story," says J J Gray, a
consultant with computer consultants @Stake.
Gary Stock, CIO & Technical Compass, Nexcerpt, Inc. 1-616.226.9550
gstock@nexcerpt.com [Gary Stock via risks-digest Volume 21, Issue 67]
0:00
#
G!
| |
Maximillian Dornseif, 2002.
|
|
|