Skip to main content

White hat hackers reveal holes in NSA website

posted onJuly 2, 2013
by l33tdawg

Although now reported and fixed, a report found that there were cross-site scripting (XSS) vulnerabilities on the main NSA forward facing web server. The report claimed that two vulnerabilities were found in "shoddily outsourced third party software written in ColdFusion", which Rustle Research researcher Horace Grant said could be used to impersonate NSA personnel and web traffic.

He said: “Why are unreliable third parties creating the software that guards our national secrets?"

One of the NSA vulnerabilities that was exploited by ethical white hat hackers exists in the ‘Careers' section of the NSA website. It said that internet users who enter data into the ‘Feedback' fields were treated to a visual representation of their data reflected back at them.

Source

Tags

NSA Security

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th