CIA Freedom of Information – Publish Your Own

CIA sealThe CIA Freedom of Information website had the dumbest security hole in it.  With all the recent hoo har about the “Family Jewels” documents, you’d expect they’d do a quick once over on this stuff.  All the textual content on the document view pages is generated directly from variables passed in the url – with no input validation.

This opens them up to cross site scripting attacks (XSS) and really is just stupid.  Lucky they aren’t the GUARDIANS OF THE LARGEST CACHE OF SENSITIVE INFORMATION IN THE WORLD or anything – *phew*.

Anyway, using this bug, I made a website where you can write your own documents and publish them on the CIA FOIA website:

http://geekz.co.uk/cia-foia/

I guess that from tomorrow, any mail for me should be addressed to Guantanamo Bay.

Actually, technically you’re the ones doing the exploiting by using the links my site provides – so, you know, at your own risk and all that.

An example here.

This entry was posted in Politics, Tech. Bookmark the permalink.

2 Responses to CIA Freedom of Information – Publish Your Own

  1. Pingback: Spook Links - The Ultimate Black Hat Link Building Technique ::

  2. AD2101 says:

    It’s broken. (Thank goodness the ***GUARDIANS OF THE LARGEST CACHE OF EXTREMELY SENSITIVE INFORMATION IN THE FREE WORLD*** fixed that simple exploit.)

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>