27 February 2009

Information Leakage from Public Information Systems

The first stage of attack is reconnaissance. Therefore don't give the enemy information they shouldn't have.

I photographed this public information screen at the weekend. It looks like it's part-way through being commissioned, but it was displaying important network information.

Photograph of a plasma display screen with the words 'Information - This appliance is not yet configured' followed by the IP address, host name and domain

In this case I suspect the information isn't particularly helpful to someone who wants to display their own messages instead of the official ones, but it is leaking information about how the system works. This particular installation probably isn't part of the critical national infrastructure, but is any more case being taken there?

Web sites often give away too much information in their error messages, filenames, source code, headers and cookies. This information can be used to help compromise the site.

Posted on: 27 February 2009 at 06:38 hrs

Comments Comments (3) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Is this a hack or something? People are getting smarter and smarter for worst.
1 Added by UPrinting Brochure Printing Posted on 04 March 2009 at 04:48 hrs
I don't believe this was a hack. It did look like the system had just been installed and left unattended with this system information displayed.
2 Added by Clerkendweller Posted on 04 March 2009 at 15:54 hrs
Oh, I see. But it is possible that they did it on purpose, right?
3 Added by Uprinting Brochure Printing Posted on 06 March 2009 at 03:09 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Information Leakage from Public Information Systems
http://www.clerkendweller.com/2009/2/27/Information-Leakage-from-Public-Information-Systems
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/2/27/Information-Leakage-from-Public-Information-Systems
Requested by 38.107.179.221 on Saturday, 4 February 2012 at 22:43 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2012 clerkendweller.com