Pennsylvania Web Site Application Exposes Voter Data

A voter in Pennsylvania discovered that the state's Web site was far less than secure. After registering, the voter noticed that a parameter at the end of a URL could be changed, thereby giving him a view of other voter's information.

However, instead of notifying the state, the voter instead registered at Digg with a username of "mtg169" and posted a message about the exploit. The person also posted at least six comments that gave even more information about the extent to which the site could be exploited.

The state of Pennsylvania reportedly didn't shut down the site until it was notified by a news agency about the vulnerability. At the time of this writing the site was still unavailable other than to display a message that reads, "The Commonwealth of Pennsylvania web site that you are trying to reach is either not available or is undergoing maintenance. Please try back later. Thank you for your patience."

Please or Register to post comments.

Upcoming Training

Mastering System Center 2012

During over 6 hours of training you can join John Savill from your computer as he will walk you through the key components and capabilities of System Center 2012, what’s involved in using the components, and the benefit they can bring to your environment.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.