Fox News' FTP Password Anyone?
An anonymous reader writes "While browsing around the Fox News website, I found that directory indexes are turned on. So, I started following the tree up, until I got to /admin. Eventually, I found my way into /admin/xml_parser/zdnet/, in which, there is a shell script. Seeing as it's a shell script, and I use Linux, I took a peek. Inside, is a username and password to an FTP. So, of course, I tried to login. The result? Epic fail on Fox's part. And seriously, what kind of password is T1me Out. This is just pathetic." It's already been changed of course, but that's still pretty amusing.
In all fairness (do they even deserve it?), the password listed in the script is for ZDNet's FTP, not Fox. Still pretty embarrassing, but it's not going to hurt Fox at all (I imagine it could have hurt CNet/ZDNet). And it definitely could've hurt the relationship between both corporations' IT departments.
There seems to be a string of these lately between content aggregators. About a month ago there was that page on MS's site endorsing Linux. Turns out the content was from another site (I think, actually, CNet).
Not to say I'm not totally surprised. In this day when about 50% of someone's site is content from somebody else, it's not surprising there's snafus. I'm just waiting for the day when one of the sites leaves up SSH logins for another.
There was a recent podcast from This American Life (hardly the bastion of conservative thought) where a (former) teenager whose job it was to spread propaganda from Saddam's government said he was afraid about what would happen when the war started because he wasn't sure whether or not his government had chemical weapons, etc. Yes, there's a difference between some teenager (even if he and his father worked for the government) and our intelligence community. Yes, fundamental flaws exist/existed in our intelligence community, partly no doubt due to our administration's tendencies to promote "yes men". Yes, there's a difference between thinking they're there and declaring that you know exactly where they are. However, I'm still going with Hanlon's razor on this one.
Ben Hocking
Need a professional organizer?
I was once visiting the offices of a design firm that was doing some work for Disney. As far as I remember, the procedure for adding new content was:
- Email the admins (with password), requesting an upload opportunity giving detail of content and approval reference
- Admins create FTP account on a purpose-built server
- Admins send back time-sensitive FTP details
- Design company uploads to FTP server
- Committees review content, send authorization to admins
- Admins upload content.
And this was for already-approved work. Kinda puts this level of security to shame...
-1 not first post
Has anyone looked at the development of Dubai over the past 10 years? or the wealth of the royal family in Saudi Arabia? Money is flowing to someone from somewhere over there that is for sure.
Now I'm not saying that Saudi's or UAE citizens are evil by default, simply that there has been absolutely 0 backlash against these regions while the US uses 9/11 to justify everything else it has been doing everywhere else.
Wheres the puzzled slightly-tilted looks of hwhaaa?
Ice Cream has no bones.