Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

'USA TODAY' WEBSITE HACKED; PRANKSTERS MOCK BUSH, CHRISTIANITY...
Drudge Report ^ | 7/12/2002 | Matt Drudge

Posted on 07/11/2002 9:33:43 PM PDT by toupsie

XXXXX DRUDGE REPORT XXXXX THU JUL 11, 2002 23:32:38 ET XXXXX

'USA TODAY' WEBSITE HACKED; PRANKSTERS MOCK BUSH, CHRISTIANITY



The USA TODAY newspaper's website was broken into late Thursday evening by hackers who put up a series of stories blasting George Bush, Sercretary of Defense Donald Rumsfeld and Christianity.



Regular readers of the site could easily be misled because the hackers used the USA TODAY's basic design template, but multiple misspellings and bad grammar give away the prank.

One headline entitled 'Bush proposes another new Cabinet post' linked to an article purportedly filed by the ASSOCIATED PRESS:

Washington D.C. (AP) - Today, George W. Bush has proposed yet another cabinet level position. The Cabinet Minister for Propoganda and Popular Englightenment, will be setup to complement the recent addition of the department of Homeland Defense. It is reported that, if approved, Bush would appoint Dr. Joseph Goebbels to the post.

In recent weeks Tom Ridge has complained that his department has lacked the proper authority to keep terrorists from infiltrating the american mind. 95% of Americans, in a Gallop poll, agree that we have to do all we can to rid the country of terrorists, showing the public still strongly supports president Bush in his campaign against terrorism.

If the move is succesful, people close to the Whitehouse think there could be a turf war between Goebbels and White House Press Secretary Ari Fleischer. Since September 11th, Fleischer has come to enjoy controling public opinion and has expressed dissatisfaction with the idea of a Popular Englightement Minister. There was a constant flow of customers buying everything.



Headlines 'Opps says the Pope; Christianity a Sham!' and

'Donald Rumsfeld: An American Beauty?' also linked to mock articles. The Rumsfeld article alleged that the Secretary of Defense is homosexual.

At of 11 pm EDT USA TODAY could no longer be accessed by the public.

Developing...

-----------------------------------------------------------
Filed by Matt Drudge
Reports are moved when circumstances warrant
http://www.drudgereport.com for updates
(c)DRUDGE REPORT 2001
Not for reproduction without permission of the author



TOPICS: Breaking News; Crime/Corruption; News/Current Events; Technical
KEYWORDS: tech; usatoday; websitehack
Navigation: use the links below to view more comments.
first 1-5051-57 next last
Wow! Shows to levels that the anti-Bush crowd will sink too.
1 posted on 07/11/2002 9:33:43 PM PDT by toupsie
[ Post Reply | Private Reply | View Replies]

To: toupsie
Wow. How original and true (sarcasm on): Naziism being equated with Christianity. Most, if not all leftists are beyond immaturity. It makes me sick.
2 posted on 07/11/2002 9:35:25 PM PDT by Pyro7480
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
Just how is one to differentiate these stories from the usual ones already issued by the leftist media daily???
3 posted on 07/11/2002 9:38:23 PM PDT by E=MC<sup>2</sup>
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
...Sercretary...

Drudge has been hacked, too!

4 posted on 07/11/2002 9:42:57 PM PDT by Senator Pardek
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
...and THIS CRAP is big news to Matt Drudge? Why?

It is just another waste of bandwidth by Drudge for recognition in a world of internet news that he is now being recognized as

"THE INCREDIBLE SHRINKING Drudge MAN!"

5 posted on 07/11/2002 9:44:25 PM PDT by Vidalia
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
Hacked? I accept this conclusion with grave reservation.
6 posted on 07/11/2002 9:45:07 PM PDT by nullsumme
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
... and this varies from usa today's standard editorial viewpoint in what way?...
7 posted on 07/11/2002 9:45:55 PM PDT by glock rocks
[ Post Reply | Private Reply | To 1 | View Replies]

To: Senator Pardek
Drudge is a Hack
8 posted on 07/11/2002 9:58:43 PM PDT by MJY1288
[ Post Reply | Private Reply | To 4 | View Replies]

To: toupsie
Anybody have a mirror?
Should be posted to http://defaced.alldas.org/ soon.
9 posted on 07/11/2002 9:59:19 PM PDT by sigSEGV
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
I enjoy how the Liberals hate Rumsfeld.
Liberal wishful thinking on the gay thing, "He's mean but sooo entitled!"
10 posted on 07/11/2002 9:59:57 PM PDT by PRND21
[ Post Reply | Private Reply | To 1 | View Replies]

To: glock rocks
Sounds as though James Carville worked out a perfect cover story for USA Today.
11 posted on 07/11/2002 10:19:47 PM PDT by billhilly
[ Post Reply | Private Reply | To 7 | View Replies]

To: Pyro7480
"Naziism being equated with Christianity."

Strange, since Hitler was a Pagan who destroyed every Christian value in German society.

12 posted on 07/11/2002 10:21:55 PM PDT by BlessingInDisguise
[ Post Reply | Private Reply | To 2 | View Replies]

To: BlessingInDisguise
You're absolutely right, but just don't tell that to the lefitsts. They won't believe you. ;-)
13 posted on 07/11/2002 10:27:54 PM PDT by Pyro7480
[ Post Reply | Private Reply | To 12 | View Replies]

To: toupsie
How would we know it was a hoax?
14 posted on 07/11/2002 10:38:08 PM PDT by OldFriend
[ Post Reply | Private Reply | To 1 | View Replies]

To: BlessingInDisguise
Not only was he a pagan, but many of his high ranking officers were homosexuals.
15 posted on 07/11/2002 10:38:16 PM PDT by Carry_Okie
[ Post Reply | Private Reply | To 12 | View Replies]

To: OldFriend
How would we know it was a hoax?

As with any headline in USA Today, odds are it's a hoax!

16 posted on 07/11/2002 10:47:31 PM PDT by Dominic Harr
[ Post Reply | Private Reply | To 14 | View Replies]

To: toupsie
Shows to levels that the anti-Bush crowd will sink too.

The article reads as if it were written by dyslexic 8th graders as a term project for their liberal social studies teacher.

17 posted on 07/11/2002 10:50:59 PM PDT by pariah
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dominic Harr
USA Today - "The USAToday web site is currently unavailable. Service to the site will be restored as soon as possible."

Netcraft - "The site www.usatoday.com is running Microsoft-IIS/5.0 on Windows 2000"

18 posted on 07/11/2002 10:52:09 PM PDT by HAL9000
[ Post Reply | Private Reply | To 16 | View Replies]

To: Dominic Harr
USA Today quickly reaching NYTimes proportions.
19 posted on 07/11/2002 10:54:23 PM PDT by OldFriend
[ Post Reply | Private Reply | To 16 | View Replies]

To: Vidalia
"THE INCREDIBLE SHRINKING Drudge MAN!"

4 million daily hits and rising, not withstanding.

20 posted on 07/11/2002 11:01:41 PM PDT by Diplomat
[ Post Reply | Private Reply | To 5 | View Replies]

To: toupsie
A little education can be a dangerous thing and these dumbasses appear to have as little as they could escape public school with.
21 posted on 07/11/2002 11:02:29 PM PDT by Wondervixen
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
Netcraft - "The site www.usatoday.com is running Microsoft-IIS/5.0 on Windows 2000"

:-D

22 posted on 07/11/2002 11:02:59 PM PDT by Dominic Harr
[ Post Reply | Private Reply | To 18 | View Replies]

To: Diplomat
...according to HIS site figures?

With radio and TV stations, we have definitive figures ...

Who has seen his logs? Who has verified his logs?
23 posted on 07/11/2002 11:07:45 PM PDT by Vidalia
[ Post Reply | Private Reply | To 20 | View Replies]

To: Dominic Harr
You haven't pinged that Tacoma MS worshipper yet?
24 posted on 07/11/2002 11:11:51 PM PDT by SoDak
[ Post Reply | Private Reply | To 22 | View Replies]

To: Vidalia
The guy drove the television press for years during the klintoon administration. He consistantly published reports that became the news staple 2 day later. The guy is a gossip monger and definitely has inside connections to some news sources. What's a matter, he not Woodard and Bernstien enough for you?
25 posted on 07/11/2002 11:14:17 PM PDT by Diplomat
[ Post Reply | Private Reply | To 23 | View Replies]

To: HAL9000
Hal,
Interesting Post. More from Netcraft...

www.usatoday.com web server history:


Oper.Sys      Web Server               Date Changed

Windows 2000  Microsoft-IIS/5.0        31-Mar-2002
Windows 2000  Microsoft-IIS/5.0        16-Jan-2002
Windows 2000  Microsoft-IIS/5.0        15-Jan-2002
Windows 2000  Microsoft-IIS/5.0        9-Jan-2002
Windows 2000  Microsoft-IIS/5.0        7-Jan-2002
Windows 2000  Microsoft-IIS/5.0        4-Jan-2002
Solaris       Netscape-Enterprise/3.6  12-Nov-2001
unknown       Netscape-Enterprise/3.6  5-Oct-2001
Solaris       Netscape-Enterprise/3.6  27-Aug-2001
Solaris       unknown                  26-Aug-2001

Will be interesting to see how their web server history looks 6 months from now. :-)

26 posted on 07/11/2002 11:21:19 PM PDT by TheEngineer
[ Post Reply | Private Reply | To 18 | View Replies]

To: toupsie
Sounds like USA Today needs to update the security programs for their website.
27 posted on 07/11/2002 11:31:42 PM PDT by Salvation
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
The Rumsfeld article alleged that the Secretary of Defense is homosexual.

Let's cut to the chase, shall we?....

Homosexuals hate Christians because they are the only group left that refuses to back down in their criticism of what they do. Bush, and many in his administration, are practicing, committed Christians as well.

Whoever coined the phrase, "Hell hath no fury like a woman scorned" never met a group of homosexuals who were suddenly told that it is a vile act.

28 posted on 07/11/2002 11:36:16 PM PDT by SkyPilot
[ Post Reply | Private Reply | To 1 | View Replies]

To: Diplomat
What's a matter, he not Woodard and Bernstien enough for you? ..."during the klintoon administration"

That administration is long over.....

He is a One Trick Pony

What has Drudge "broken" to the world that the rest of the dullard news agencies have not?

The internet news services have passed him by.

He is an arrogant SOB much like Orsen Wells became after "The War of the Worlds" radio success.

Fox News Channel has verifiable stories before he can even "source".

Drudge is an outdated Carousel
29 posted on 07/11/2002 11:55:52 PM PDT by Vidalia
[ Post Reply | Private Reply | To 25 | View Replies]

To: toupsie
I didn't realize Little Katie Communist of the NBC Today Show knew how to hack a website. Finally something impressive from the little wimp.
30 posted on 07/12/2002 4:05:54 AM PDT by jrlc
[ Post Reply | Private Reply | To 1 | View Replies]

To: pariah
The article reads as if it were written by dyslexic 8th graders as a term project for their liberal social studies teacher.

Boy, I really miss eighth grade. What memories. ;-)

31 posted on 07/12/2002 4:31:15 AM PDT by Aquinasfan
[ Post Reply | Private Reply | To 17 | View Replies]

To: toupsie
"Pranksters" is an inappropriate designation. How about criminals. Hacking needs to be defined seriously not as childish hi-jinks.
32 posted on 07/12/2002 5:35:11 AM PDT by zip
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
"The site www.usatoday.com is running Microsoft-IIS/5.0 on Windows 2000"

It figures.

33 posted on 07/12/2002 5:49:27 AM PDT by ELS
[ Post Reply | Private Reply | To 18 | View Replies]

To: SkyPilot
That picture needs a hurl-alert!!
34 posted on 07/12/2002 5:49:40 AM PDT by meyer
[ Post Reply | Private Reply | To 28 | View Replies]

To: TheEngineer
Interesting, I wonder why they switched from Solaris/Netscape to W2K/IIS? IIS is terrible! Personally if I had a Web server, I would probably use some version of Unix with Apache.
35 posted on 07/12/2002 5:52:01 AM PDT by ELS
[ Post Reply | Private Reply | To 26 | View Replies]

To: Incorrigible
See reply #26.
36 posted on 07/12/2002 5:53:22 AM PDT by ELS
[ Post Reply | Private Reply | To 26 | View Replies]

To: SkyPilot
*SPIT* so much for my cup of coffee.
and Gay (I mean) Good Morning to you all! ha ha
37 posted on 07/12/2002 5:58:44 AM PDT by NWOhioGirl7O7
[ Post Reply | Private Reply | To 28 | View Replies]

To: ELS; Bush2000
Et tu, ELS?

My heart, it breaks!

It doesn't take much to lock down IIS. 

Security Operations Guide for Windows 2000 Server

Of course, UNIX systems are also vulnerable as Bush2000 has pointed out numerous times but that doesn't seem to get the press about Microsoft. 

Companies that hire incompetent web managers get hacked no matter what.

38 posted on 07/12/2002 6:23:38 AM PDT by Incorrigible
[ Post Reply | Private Reply | To 36 | View Replies]

To: toupsie
Who would have guessed that Carvile knew how to crack into computers?
39 posted on 07/12/2002 6:34:12 AM PDT by steve-b
[ Post Reply | Private Reply | To 1 | View Replies]

To: Incorrigible
Companies that hire incompetent web managers get hacked no matter what.

Yes, that is the essential truth.

I had been using IIS on WinNT at work for development purposes, which to my knowledge, no hackers were trying to get into. A version of the Nimda virus found the instance of IIS on my computer and proceeded to modify all sorts of files on my computer. Real nice. Granted the network ops guys were asleep on the job, but this virus doesn't make its home in Apache which I promptly switched to.

40 posted on 07/12/2002 6:58:52 AM PDT by ELS
[ Post Reply | Private Reply | To 38 | View Replies]

Comment #41 Removed by Moderator

To: Incorrigible
Of course, UNIX systems are also vulnerable as Bush2000 has pointed out numerous times but that doesn't seem to get the press about Microsoft.

From SecurityFocus, a list of vulns by product for the last 4 years:

Apache 2.0

 2002-06-17:  Apache Chunked-Encoding Memory Corruption Vulnerability

One vuln.

One vuln in 4 years

.

Now, Microsoft IIS 5.0:

 2002-05-27:  Microsoft IIS 5.0 Denial Of Service Vulnerability
 2002-05-27:  Microsoft IIS HTR Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-18:  Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability
 2002-04-16:  Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
 2002-04-10:  Microsoft IIS Help File Search Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Heap Overflow Variant Vulnerability
 2002-04-10:  Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Header Field Delimiter Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
 2002-04-10:  Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
 2002-03-05:  Microsoft IIS Authentication Method Disclosure Vulnerability
 2002-02-19:  Multiple Vendor HTTP CONNECT TCP Tunnel Vulnerability
 2002-01-31:  Microsoft MSDTC Service Denial of Service Vulnerability
 2002-01-16:  Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
 2001-12-11:  Microsoft IIS False Content-Length Field DoS Vulnerability
 2001-08-15:  Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS 5.0 In-Process Table Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
 2001-08-15:  Microsoft IIS MIME Header Denial of Service Vulnerability
 2001-08-08:  MS IIS Internal IP Address/Internal Network Name Disclosure Vulnerability
 2001-07-04:  Microsoft IIS Device File Local DoS Vulnerability
 2001-07-04:  Microsoft IIS Device File Remote DoS Vulnerability
 2001-05-17:  IIS WebDav Lock Method Memory Leak DoS Vulnerability
 2001-05-15:  MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
 2001-05-14:  Microsoft IIS Various Domain User Account Access Vulnerability
 2001-05-06:  Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
 2001-05-01:  Microsoft IIS 5.0 .printer ISAPI Extension Buffer Overflow Vulnerability
 2001-03-16:  Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
 2001-03-08:  Microsoft IIS WebDAV Denial of Service Vulnerability
 2001-03-01:  Microsoft IIS Multiple Invalid URL Request DoS Vulnerability
 2001-03-01:  Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
 2001-01-29:  Microsoft IIS File Fragment Disclosure Vulnerability
 2000-12-22:  Microsoft IIS Front Page Server Extension DoS Vulnerability
 2000-11-06:  Microsoft IIS Executable File Parsing Vulnerability
 2000-10-23:  Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability
 2000-10-17:  Microsoft IIS and PWS Extended Unicode Directory Traversal Vulnerability
 2000-10-04:  Microsoft IIS 5.0 Indexed Directory Disclosure Vulnerability
 2000-08-21:  Microsoft FrontPage/IIS Cross Site Scripting shtml.dll Vulnerability
 2000-08-21:  Microsoft IIS Cross Site Scripting .shtml Vulnerability
 2000-08-14:  Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability
 2000-08-10:  Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
 2000-07-17:  Microsoft IIS 4.0/5.0 Source Fragment Disclosure Vulnerability
 2000-07-14:  Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
 2000-07-13:  Microsoft IIS Internal IP Address Disclosure Vulnerability
 2000-05-14:  Microsoft IIS FTP Denial of Service Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed File Extension DoS Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed Filename Request Vulnerability
 2000-05-10:  Microsoft IIS 4.0/5.0 Malformed .htr Request Vulnerability
 2000-05-06:  Microsoft Frontpage Server Extensions Path Disclosure Vulnerability
 2000-04-12:  Microsoft IIS 4.0/5.0 Escaped Characters Vulnerability
 2000-03-30:  Microsoft IIS UNC Mapped Virtual Host Vulnerability
 2000-03-08:  Microsoft IIS UNC Path Disclosure Vulnerability
 2000-02-09:  NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability
 1999-01-26:  NT IIS IISAPI Extension Enumerate Root Web Server Directory Vulnerability

It is, in my opinion, professional incompetence to use MS IIS for any mission-critical web work.

42 posted on 07/12/2002 7:58:30 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 38 | View Replies]

To: Incorrigible
Of course, UNIX systems are also vulnerable as Bush2000 has pointed out numerous times but that doesn't seem to get the press about Microsoft.

From SecurityFocus, a list of vulns by product for the last 4 years:

Apache 2.0

 2002-06-17:  Apache Chunked-Encoding Memory Corruption Vulnerability

One vuln.

One vuln in 4 years

.

Now, Microsoft IIS 5.0:

 2002-05-27:  Microsoft IIS 5.0 Denial Of Service Vulnerability
 2002-05-27:  Microsoft IIS HTR Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-18:  Microsoft IIS CodeBrws.ASP File Extension Check Out By One Vulnerability
 2002-04-16:  Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability
 2002-04-10:  Microsoft IIS Help File Search Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Error Page Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS HTTP Redirect Cross Site Scripting Vulnerability
 2002-04-10:  Microsoft IIS Chunked Encoding Heap Overflow Variant Vulnerability
 2002-04-10:  Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS HTTP Header Field Delimiter Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
 2002-04-10:  Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
 2002-04-10:  Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
 2002-03-05:  Microsoft IIS Authentication Method Disclosure Vulnerability
 2002-02-19:  Multiple Vendor HTTP CONNECT TCP Tunnel Vulnerability
 2002-01-31:  Microsoft MSDTC Service Denial of Service Vulnerability
 2002-01-16:  Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
 2001-12-11:  Microsoft IIS False Content-Length Field DoS Vulnerability
 2001-08-15:  Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS 5.0 In-Process Table Privelege Elevation Vulnerability
 2001-08-15:  Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
 2001-08-15:  Microsoft IIS MIME Header Denial of Service Vulnerability
 2001-08-08:  MS IIS Internal IP Address/Internal Network Name Disclosure Vulnerability
 2001-07-04:  Microsoft IIS Device File Local DoS Vulnerability
 2001-07-04:  Microsoft IIS Device File Remote DoS Vulnerability
 2001-05-17:  IIS WebDav Lock Method Memory Leak DoS Vulnerability
 2001-05-15:  MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
 2001-05-14:  Microsoft IIS Various Domain User Account Access Vulnerability
 2001-05-06:  Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
 2001-05-01:  Microsoft IIS 5.0 .printer ISAPI Extension Buffer Overflow Vulnerability
 2001-03-16:  Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
 2001-03-08:  Microsoft IIS WebDAV Denial of Service Vulnerability
 2001-03-01:  Microsoft IIS Multiple Invalid URL Request DoS Vulnerability
 2001-03-01:  Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
 2001-01-29:  Microsoft IIS File Fragment Disclosure Vulnerability
 2000-12-22:  Microsoft IIS Front Page Server Extension DoS Vulnerability
 2000-11-06:  Microsoft IIS Executable File Parsing Vulnerability
 2000-10-23:  Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability
 2000-10-17:  Microsoft IIS and PWS Extended Unicode Directory Traversal Vulnerability
 2000-10-04:  Microsoft IIS 5.0 Indexed Directory Disclosure Vulnerability
 2000-08-21:  Microsoft FrontPage/IIS Cross Site Scripting shtml.dll Vulnerability
 2000-08-21:  Microsoft IIS Cross Site Scripting .shtml Vulnerability
 2000-08-14:  Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability
 2000-08-10:  Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
 2000-07-17:  Microsoft IIS 4.0/5.0 Source Fragment Disclosure Vulnerability
 2000-07-14:  Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
 2000-07-13:  Microsoft IIS Internal IP Address Disclosure Vulnerability
 2000-05-14:  Microsoft IIS FTP Denial of Service Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed File Extension DoS Vulnerability
 2000-05-11:  Microsoft IIS 4.0/5.0 Malformed Filename Request Vulnerability
 2000-05-10:  Microsoft IIS 4.0/5.0 Malformed .htr Request Vulnerability
 2000-05-06:  Microsoft Frontpage Server Extensions Path Disclosure Vulnerability
 2000-04-12:  Microsoft IIS 4.0/5.0 Escaped Characters Vulnerability
 2000-03-30:  Microsoft IIS UNC Mapped Virtual Host Vulnerability
 2000-03-08:  Microsoft IIS UNC Path Disclosure Vulnerability
 2000-02-09:  NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability
 1999-01-26:  NT IIS IISAPI Extension Enumerate Root Web Server Directory Vulnerability

It is, in my opinion, professional incompetence to use MS IIS for any mission-critical web work.

43 posted on 07/12/2002 8:01:53 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 38 | View Replies]

To: All
Ooops, sorry about that -- I did *not* mean to post that twice.
44 posted on 07/12/2002 8:02:38 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 41 | View Replies]

To: ELS; Dominic Harr
Hi ELS,

I'm sorry if my rant cast an aspersions on your abilities.  Unintended.

The Nimba and Code Red viruses could have been prevented if the patch that Microsoft released months earlier had been installed.  In fact, it was the description of the problem on Microsoft's site that gave the hackers the idea.  :-(

The original goal was to make administration and all features of the server web enabled and other features open by default.  Though this makes computing easier for those trying to implement solutions (like running executables in Outlook), it also makes it easier for hackers.  Thus, Microsoft will be shipping OSes in the future without installing software and keeping ports closed.  Safer yes.  Less functional for users, yes.

The above is the default for UNIX implementations and thus, fewer hack attacks.  Microsoft has reconciled itself to the fact that there people who are unfairly against Microsoft and wish it harm (Dominic???  :-)  ).

45 posted on 07/12/2002 8:24:44 AM PDT by Incorrigible
[ Post Reply | Private Reply | To 40 | View Replies]

To: Incorrigible
Microsoft has reconciled itself to the fact that there people who are unfairly against Microsoft and wish it harm (Dominic??? :-) ).

If the above list didn't prove something about the quality of the product to you, then by all means continue using it.

I don't wish MS harm, anymore than I wish 'Brittney Spears' wrong. I just think it's devastating for our tech industry to have a company using illegal means to force inferior products on the market, and want the illegalities to stop.

Other than stopping MS's illegalities, I wish them no harm at all.

46 posted on 07/12/2002 8:33:04 AM PDT by Dominic Harr
[ Post Reply | Private Reply | To 45 | View Replies]

To: Incorrigible
No offense taken. Most of my work is with an application server (Opentext Livelink) and the Web server is merely a conduit between the browser and the app server. I could have switched to NS ES, but they charge a fee :-) whereas I was able to download Apache for free, install it, and get back to work.

I'm not really a strong partisan for any particular OS. I have used the major ones (DOS/Win, Mac, Unix) and they all have pros and cons, IMHO.

47 posted on 07/12/2002 10:03:00 AM PDT by ELS
[ Post Reply | Private Reply | To 45 | View Replies]

To: toupsie
Hmmmm. Bad spelling? Didn't know Jesse Jackson was a hacker.
48 posted on 07/12/2002 11:01:34 AM PDT by Democratic_Machiavelli
[ Post Reply | Private Reply | To 1 | View Replies]

To: Carry_Okie
They were also heavily into occultism/satanism. Nice bunch of boys, huh?
49 posted on 07/12/2002 12:02:25 PM PDT by Marysecretary
[ Post Reply | Private Reply | To 15 | View Replies]

To: meyer
yeah, I thought the same thing...barf!
50 posted on 07/12/2002 12:04:02 PM PDT by Marysecretary
[ Post Reply | Private Reply | To 34 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-57 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson