Trump's Cyber Security Advisor Rudy Giuliani Runs Ancient, Utterly Hackable Website (theregister.co.uk)
mask.of.sanity writes from a report via The Register: U.S. president-elect Donald Trump's freshly minted cyber tsar Rudy Giuliani runs a website so insecure that its content management system is five years out of date, unpatched and is utterly hackable. Giulianisecurity.com, the website for Giuliani's eponymous infosec consultancy firm, runs Joomla! version 3.0, released in 2012, and since found to carry 15 separate vulnerabilities. More bugs and poor secure controls abound. The Register report adds: "Some of those bugs can be potentially exploited by miscreants using basic SQL injection techniques to compromise the server. This seemingly insecure system also has a surprising number of network ports open -- from MySQL and anonymous LDAP to a very out-of-date OpenSSH 4.7 that was released in 2007. It also runs a rather old version of FreeBSD. 'You can probably break into Giuliani's server,' said Robert Graham of Errata Security. 'I know this because other FreeBSD servers in the same data center have already been broken into, tagged by hackers, or are now serving viruses. 'But that doesn't matter. There's nothing on Giuliani's server worth hacking.'"
"giulianisecurity.com’s DNS address could not be found."
Rick B.
The DNS entry has been removed, but the server continues to run:
http://209.238.99.227/index.ph...
Yeah, remember that clueless Obama cabinet. For example, Steven Chu - a Nobel Prize laureate tapped to lead department of Housing?
Robert Graham explained it succinctly: http://blog.erratasec.com/2017... .
The real story here is that Giuliani is now a goddamn cybersecurity advisor, not that this personal site is crap. The guy was hired not because of competence but because he spent the entire campaign kissing Trump's ass.
"Thus historian Vincent J. Cannato concluded in September 2006, "With time, Giuliani's legacy will be based on more than just 9/11. He left a city immeasurably better off — safer, more prosperous, more confident — than the one he had inherited eight years earlier, even with the smoldering ruins of the World Trade Center at its heart. Debates about his accomplishments will continue, but the significance of his mayoralty is hard to deny."
You might be correct, in that Giuliani was not hired because of competence, but you are completely incorrect implying that Giuliani is wholly without competance.
And once again, I have to ask: is [what you said] this important? Is *why* someone is hired more important than their competence?
And once again again, I have to ask: compared to what? Is hiring Giuliani any worse than the practices of the previous administration or the runner-up candidate?
For contrast, note that Bush appointed a crony as head of FEMA who completely fell on his face during Katrina, and Obama appointed Caroline Kennedy as ambassador to Japan, who was completely outmastered in our recent Japanese treaty negotiations(*).
Is it useful *at all* to just throw throws random aspersions around?
(*) Resulting in a treaty which is beneficial to Japan, but a very bad deal for America. I have no opinion about Ms. Kennedy, good or bad, only note that she was unqualified for the position, was apparently appointed because of her ties to a famous family dynasty, and America was worse off because of it.
Stephen Chu was the Energy Secretary, and was followed by Ernest Moniz, a nuclear physicist from MIT. They understand nuclear physics, unlike Rick Perry who doesn't even remember the name of the department he was recently appointed to lead:
http://abcnews.go.com/blogs/politics/2011/11/rick-perrys-debate-lapse-oops-cant-remember-department-of-energy/
He's not storing mountains of classified emails on his server.
Well, not anymore.
What makes you two think that that screaming gargoyle Rudy Giuliani even knows how to operate an e-mail client? They might as well assign Sarah Palin to oversee the quality inspection of nuclear weapons production.
Remember when asked to describe what undisclosed information he knew, Trump said, "You'll find out on Tuesday or Wednesday." That was last week or the week before. We're still waiting. Maybe he's too busy watching for Hollywood slights to get back to us on that.
And there is this gem talking about the intelligence services, "I think it's unfair if they don't know," he said. "And I know a lot about hacking. And hacking is a very hard thing to prove."
The trick is to bang the rocks together, Trump.
(courtesy of Douglas Adams)