Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

How secure are Bush and Kerry web sites: An Analysis

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion: Presidential (Through Nov 2009) Donate to DU
 
zulchzulu Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jun-27-04 09:31 PM
Original message
How secure are Bush and Kerry web sites: An Analysis
I got this letter from someone analyzing both web sites. It's a bit geeky for some. Open Source (Kerry) vs. Microsoft (Bush).

Rating the Bush and Kerry Web sites on security

To rate George Bush and John Kerry on the Homeland Security issue, I
just completed two quick security audits of the official Bush
(http://www.georgewbush.com/) and Kerry (http://www.johnkerry.com/)
campaign Web sites.

Unfortunately, I found problems at both Web sites.

Here are the results of my testing so far:

1. Both the Bush and the Kerry Web sites have cross-site scripting
errors (XSS). These errors can allow a prankster to create fake Web pages which load from the Bush or Kerry Web sites but additional content can be supplied from a different Web server belonging to a prankster. A prankster could then say anything they want on a Bush or Kerry Web page using a XSS error.

Examples include fake news stories, slogans telling visitors to vote
for the other candidate, and doctored photos of a candidate.

2. Error trapping at the Kerry Web site isn't very good. Typing
unusual characters into Web forms at the Kerry Web site causes Web server applications to fail and a visitor is shown very cryptic error pages.

These problems might be a sign of SQL injection errors which can be quite serious. An SQL injection error can sometimes be used by an outsider to break into a backend database at a Web site and then to make off with private information from the database.

3. The Bush Web site has hired a company called Omniture to track
users at the Bush Web site. Omniture uses hidden Web bugs to do this tracking. Perhaps this Web site feature was requested by John Ashcroft? ;-) This relationship with Omniture is not spelled out in the Bush Web site privacy policy. For more about information about Omniture, check out their Web site at http://www.omniture.com/company.html.

4. Both the Bush and Kerry Web sites encourage visitors to add banner
ads for the candidates to their own Web pages. The Bush banner ad uses JavaScript supplied from the Bush Web server (See
http://www.georgewbush.com/WStuff/BPAdFeed.aspx).

The Kerry banner ads
use an embedded IFRAME (See http://www.johnkerry.com/download/promos.html).

Both banner ad schemes allow the campaigns to track visitors to any Web pages where the banner ads appear. In addition, the Bush JavaScript scheme allows the Bush Web server to run any script code inside of other people's Web pages. This scheme doesn't strike me as a very good idea from a security standpoint.

5. Both candidates have good Web site privacy policies. For some odd
reason, the Kerry Web site privacy policy is also certified by Truste
and BBBOnline.

6. It appears that the open source vs. closed source debate has also
entered the presidential campaign. The Kerry home page comes from an
Apache Web server running on a Red Hat Linux box. The Bush Web site on the other hand is hosted on a more corporate Microsoft-powered IIS 5.0 server and uses ASP.NET. I did not check to see if this IIS server is up to date with Microsoft security patches.

If anyone else runs across anything interesting at these two Web sites, please let me know.

Richard M. Smith
http://www.ComputerBytesMan.com
Printer Friendly | Permalink |  | Top
realcountrymusic Donating Member (999 posts) Send PM | Profile | Ignore Sun Jun-27-04 10:03 PM
Response to Original message
1. Cool info, thanks!

Not too geeky for me. I found your post fascinating. Now how about we form sysadmins for Kerry and give him some free consulting services?

RCM
Printer Friendly | Permalink |  | Top
 
zulchzulu Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jun-27-04 10:15 PM
Response to Reply #1
3. SysadminsforKerry.com!
Great idea. Would it have OS wars too within the discussion. :->
Printer Friendly | Permalink |  | Top
 
LiberalBushFan Donating Member (831 posts) Send PM | Profile | Ignore Sun Jun-27-04 10:12 PM
Response to Original message
2. number 6 is interesting
woulda been funny if Bush's site was running on Linux
Printer Friendly | Permalink |  | Top
 
bklyncowgirl Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-28-04 06:06 AM
Response to Original message
4. Spyware
I always run Adaware and clear out my cache after visiting the Bush site just to be safe. I swear it once messed up my computer. I thought I was being paranoid but this confirms it.
Printer Friendly | Permalink |  | Top
 
Protected Donating Member (618 posts) Send PM | Profile | Ignore Mon Jun-28-04 12:33 PM
Response to Original message
5. Bush's site crashes my browser every time.
Mozilla 1.6 on Windows XP. Best denial of service ever!
Printer Friendly | Permalink |  | Top
 
Tim_in_HK Donating Member (544 posts) Send PM | Profile | Ignore Mon Jun-28-04 12:36 PM
Response to Reply #5
6. That's funny . . .
Because i've never been able to access Bush's website! I always get "cannot find server" on IE. Don't know why.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 10:16 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion: Presidential (Through Nov 2009) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC