White hat hackers reveal holes in NSA website
Although now reported and fixed, a report found that there were cross-site scripting (XSS) vulnerabilities on the main NSA forward facing web server. The report claimed that two vulnerabilities were found in "shoddily outsourced third party software written in ColdFusion", which Rustle Research researcher Horace Grant said could be used to impersonate NSA personnel and web traffic.
He said: “Why are unreliable third parties creating the software that guards our national secrets?"
One of the NSA vulnerabilities that was exploited by ethical white hat hackers exists in the ‘Careers' section of the NSA website. It said that internet users who enter data into the ‘Feedback' fields were treated to a visual representation of their data reflected back at them.