Vulnerabilities in dozens of Military and Pentagon websites
pastebin.com
pastebin.com
If you're still wary, pick the most unremarkable one, that you think most people are likely to click. That way it seems more normal from their perspective -- you're just one among many in the wide sea. Here, I'll even help you out: https://secureweb.hqda.pentagon.mil/dpo/Details.asp?ID=108
Anyways add a ' to the end of that URL and you'll see clear evidence of a SQL injection bug. But it is just demonstrating that the bug is there. It would take more work to get access to their database.
This sentence makes no sense whatsoever. It seems that you think "unremarkable" means likely to draw a lot of attention.
asp means active server pages (VBScript). Very old.
cfm means cold fusion markup (ColdFusion). Also very old.
These are just very old websites built back in the day when no-one knew what they were doing. One of them even has 'legacyapps' in the address.
ColdFusion, however, isn't "very old". It's an actively supported platform with new versions released within the past year (commercially and 2 open source alternatives). It contains current features such as ESAPI support (for security) and web sockets (for the whiz bang buzzwordians). The fact that it was released in 1995 is irrelevant - similarly aged languages include Java, Ruby, JavaScript, and PHP.
You're correct that the age of the websites has much to do with the vulnerabilities. I think "no-one knew what they were doing" borders on insulting for anyone who's been building web apps for more than a few years, however. Rather, things like SQL injection weren't common then, and older, unsupported apps are thus easily exposed.
I actually remember SQLi becoming a hot topic just when I personally was switching from being a VBScript programmer to C#. When all the APIs were introducing parametrized queries and the debate of them vs stored procs was actually still raging.
It was very easy to do stupid things then because all the APIs encouraged bad code, there wasn't much good advice on the net, there was no stack overflow and the books actually told you to write bad code. I'd look up a couple of classics but I've literally just sent all my old programming books to recycling.
So either you weren't professionally programming back then or are looking back with rose tinted glasses. A lot of apps were vulnerable to SQLi back then.
Look at this article from Jeff Atwood back in 2005:
http://www.codinghorror.com/blog/2005/04/give-me-parameteriz...
Kinda goes without saying these days doesn't it? Would any programmer blog something as basic as this now?
But it looks like these are mostly NIPR Public Affairs types of sites, from what I can tell.
So why should we expect great diligence when it comes to building informational websites. Does anyone remember the ease with which Bradley Manning performed his hack*?
edit: I think I'm getting downvoted because people disagree that Manning "hacked" something. I don't know why there is disagreement here...he himself disclosed the methods he used to get over the "air gap". Just because those methods were trivial doesn't undercut my point, in fact, it underscores my point that the military's information security is not without flaws:
http://en.wikipedia.org/wiki/Bradley_Manning#Diplomatic_cabl...
You're right that the military is hardly going to treat a "Public Affairs" website with any special care, but I wanted to correct you on your description of a Bradley Manning "hack".
There was no hack. There was never a hack. Bradley Manning was the proverbial "insider" threat.
You may remember that in the wake of 9/11 there was a lot of acrimony regarding how poorly the various Federal agencies worked together. They often engaged in turf warfare to maximize the agency's important instead of maximizing the U.S.'s ability to respond to actual threats.
No one shared info with one another, either because they were not sure they could share info, to prevent aiding other agencies getting more powerful, etc. And as a result there were thousands of Americans murdered, not to mention the horrific property losses.
So, one of the "lessons learned" was that the intelligence agencies were going to work together from then on. Not just work together, they were going to share the intel. Counterterrorism would become a real mission goal, with real resources put to it, real organizations aligned around it, etc.
So suddenly, military was working with CIA, FBI, Dept. of State, and more, and working together to prevent another 9/11 happening, prevent IED attacks against deployed troops, etc.
There was never a hack. Manning had access to all of that data quite intentionally, to help him do his f'ing job as an intelligence specialist analyzing the various Islamist threat groups in his area. He even quoted (and was quite proud of) an award citation in his chat logs with Lamo that described how he was aiding the Army in that particular fight.
But not once did he hack anything. He downloaded data he had authorized access to, and exfiltrated it to persons who did not have authorization.
edit: (I mean I agree with the background facts you've stated, but I think it is still a "hack" based on other related facts, and it's my fault for not elaborating in the parent comment)
In any case, I was just pointing out that the military's information infrastructure is not bulletproof, so to speak. This applies to public facing websites and in Manning's case, to secure access protocols (for example, in what other organization would unmonitored, unchecked access to critical files be given to someone barely older than a college senior?).
But I do think that this was a "hack", if an unsophisticated one. He may have had authorized access to those files, but he did not have authorization to transfer those files over the "air gap". Here's how he described his exploits to Adrian Lamo in chat logs:
http://en.wikipedia.org/wiki/Bradley_Manning#Diplomatic_cabl...
...lets just say someone* i know intimately well, has been penetrating US classified networks, mining data like the ones described ... and been transferring that data from the classified networks over the “air gap” onto a commercial network computer ... sorting the data, compressing it, encrypting it, and uploading it to a crazy white haired aussie who can't seem to stay in one country very long =L [...]*
(02:12:23 PM) bradass87: so ... it was a massive data spillage ... facilitated by numerous factors ... both physically, technically, and culturally
(02:13:02 PM) bradass87: perfect example of how not to do INFOSEC
(02:14:21 PM) bradass87: listened and lip-synced to Lady Gaga's Telephone while exfiltratrating [sic] possibly the largest data spillage in american history [...]
(02:17:56 PM) bradass87: weak servers, weak logging, weak physical security, weak counter-intelligence, inattentive signal analysis ... a perfect storm [...]
-----
Yes, this "hack" of Manning's required little more than a USB drive, perhaps, but that was my original point: parts of the military system are relatively untested, allowing such critical oversights...so a SQL vulnerability in a public facing military website is not a huge surprise.
You could argue that the system could have technical measures in place to see that the CD-R was being filled, used repeatedly in a short period of time, etc. but that could be worked around too.
He's exactly right that trusting an insider is a perfect example of how not to do INFOSEC, but that was a risk the military judged was of lower danger than the risk associated with artificial constraints on the ability of the military and government to cooperate on anti-terrorism.
Pretty much any measure the gov't and military put in place in this area to protect against the future Mannings of the world will at least slightly inhibit their ability to detect and prevent future terrorist strikes, I guess we'll have to see what they've chosen to do. :-/