<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Congressional Web Site Defacements Follow the State of the Union</title>
	<atom:link href="http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Tue, 15 May 2012 11:55:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Dcsc govhttp &#124; UsDatingAcademy</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-29838</link>
		<dc:creator>Dcsc govhttp &#124; UsDatingAcademy</dc:creator>
		<pubDate>Mon, 07 Mar 2011 08:05:28 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-29838</guid>
		<description>&lt;p&gt;[...] Praetorian Prefect &#124; Congressional Web Site Defacements Follow theShortly after President Obama&#8217;s State of the Union address, constituents visiting the web sites of Congressional representatives like Charles Gonzalez (20th District of Texas), &#8230; All of the sites affected are in the house.gov domain, but not every &#8230; The sites were defaced to simply show the following line of text&#8230;   Filed in Uncategorized    &#171; Dessa birdsall [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Praetorian Prefect | Congressional Web Site Defacements Follow theShortly after President Obama&#8217;s State of the Union address, constituents visiting the web sites of Congressional representatives like Charles Gonzalez (20th District of Texas), &#8230; All of the sites affected are in the house.gov domain, but not every &#8230; The sites were defaced to simply show the following line of text&#8230;   Filed in Uncategorized    &laquo; Dessa birdsall [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressman Steny Hoyer Twitter impersonation attack &#124; ITtalker.COM</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-25522</link>
		<dc:creator>Congressman Steny Hoyer Twitter impersonation attack &#124; ITtalker.COM</dc:creator>
		<pubDate>Wed, 26 Jan 2011 09:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-25522</guid>
		<description>&lt;p&gt;[...] timing of the attack is reminiscent of last year’s mass defacement of congressional web sites following the State of the Union address by the Brazilian defacement team the Red Eye [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] timing of the attack is reminiscent of last year’s mass defacement of congressional web sites following the State of the Union address by the Brazilian defacement team the Red Eye [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressman Steny Hoyer Twitter impersonation attack &#124; ZDNet</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-25494</link>
		<dc:creator>Congressman Steny Hoyer Twitter impersonation attack &#124; ZDNet</dc:creator>
		<pubDate>Wed, 26 Jan 2011 06:59:11 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-25494</guid>
		<description>&lt;p&gt;[...] timing of the attack is reminiscent of last year&#8217;s mass defacement of congressional web sites following the State of the Union address by the Brazilian defacement team the Red Eye [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] timing of the attack is reminiscent of last year&#8217;s mass defacement of congressional web sites following the State of the Union address by the Brazilian defacement team the Red Eye [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: routeraccess</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-18396</link>
		<dc:creator>routeraccess</dc:creator>
		<pubDate>Fri, 19 Nov 2010 00:22:08 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-18396</guid>
		<description>&lt;p&gt;@infosec pro - curious, both websites list the EXACT same employees on their about us pages, have the same site look and feel (down to the site navigation/font choice for logos), and link to the same &quot;client login&quot; page at https://thewdg.basecamphq.com/login.&lt;/p&gt;

&lt;p&gt;GovTrends &quot;about&quot; page:
http://webcache.googleusercontent.com/search?q=cache:7fXLO2uwPF0J:switch2govtrends.com/about/+http://switch2govtrends.com/about/&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a&lt;/p&gt;

&lt;p&gt;WDG&#039;s &quot;about us&quot; page&lt;/p&gt;

&lt;p&gt;http://webcache.googleusercontent.com/search?q=cache:iwaddRf1PBIJ:webdevelopmentgroup.com/about-web-development-group/+http://webdevelopmentgroup.com/about-web-development-group/&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us&amp;client=firefox-a&lt;/p&gt;

&lt;p&gt;As is apparently prudent for them, each company is either incorporated separately or otherwise delineated as a separate entity for the sake of House and Senate contracts, but the management, employees, and general corporate attitudes appear to be exactly the same per the above publicly available information.&lt;/p&gt;

&lt;p&gt;Unfortunately I do know what I am talking about; even more unfortunate for you personally is that your diction and cadence give away your identity, buddy.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@infosec pro &#8211; curious, both websites list the EXACT same employees on their about us pages, have the same site look and feel (down to the site navigation/font choice for logos), and link to the same &#8220;client login&#8221; page at <a href="https://thewdg.basecamphq.com/login." rel="nofollow">https://thewdg.basecamphq.com/login.</a></p>

<p>GovTrends &#8220;about&#8221; page:
<a href="http://webcache.googleusercontent.com/search?q=cache:7fXLO2uwPF0J:switch2govtrends.com/about/+http://switch2govtrends.com/about/&#038;cd=1&#038;hl=en&#038;ct=clnk&#038;gl=us&#038;client=firefox-a" rel="nofollow">http://webcache.googleusercontent.com/search?q=cache:7fXLO2uwPF0J:switch2govtrends.com/about/+http://switch2govtrends.com/about/&#038;cd=1&#038;hl=en&#038;ct=clnk&#038;gl=us&#038;client=firefox-a</a></p>

<p>WDG&#8217;s &#8220;about us&#8221; page</p>

<p><a href="http://webcache.googleusercontent.com/search?q=cache:iwaddRf1PBIJ:webdevelopmentgroup.com/about-web-development-group/+http://webdevelopmentgroup.com/about-web-development-group/&#038;cd=1&#038;hl=en&#038;ct=clnk&#038;gl=us&#038;client=firefox-a" rel="nofollow">http://webcache.googleusercontent.com/search?q=cache:iwaddRf1PBIJ:webdevelopmentgroup.com/about-web-development-group/+http://webdevelopmentgroup.com/about-web-development-group/&#038;cd=1&#038;hl=en&#038;ct=clnk&#038;gl=us&#038;client=firefox-a</a></p>

<p>As is apparently prudent for them, each company is either incorporated separately or otherwise delineated as a separate entity for the sake of House and Senate contracts, but the management, employees, and general corporate attitudes appear to be exactly the same per the above publicly available information.</p>

<p>Unfortunately I do know what I am talking about; even more unfortunate for you personally is that your diction and cadence give away your identity, buddy.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Smith</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6561</link>
		<dc:creator>Bob Smith</dc:creator>
		<pubDate>Tue, 02 Feb 2010 01:25:05 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6561</guid>
		<description>&lt;p&gt;i can shed some light on the debacle. i used to work for said company side-by-side with their former frontend developer who built those exact sites that were hacked. i heard him stress time and time again that they needed to be updated to no avail due to the owner, who wasn&#039;t the brightest bulb in the bunch and knew nothing about joomla. i left before the frontend dev decided to leave in 2009 due to a breach of contract by the owner and the frontend dev. that&#039;s only the tip of the iceberg for the incompetence and arrogance of the company and its owner. so, yes, the company is clearly in the wrong here and shouldn&#039;t be allowed in the house imo.&lt;/p&gt;

&lt;p&gt;regarding okomo: it isn&#039;t even a cms. it&#039;s just a ‘really’ basic platform built on django masquerading as a cms, but definitely not a cms as the company states.&lt;/p&gt;

&lt;p&gt;while, yes, i think a response is necessary on joomla&#039;s part, this company deserves no help whatsoever from the joomla community when they&#039;re not willing to accept it. it&#039;s a shame that such companies are allowed to represent joomla to the federal govt when so many people dedicate their time to the project. i can only hope the house blocks them from doing business there and that they learn a valuable lesson.&lt;/p&gt;

&lt;p&gt;joomla should write a response and perform some positive pr to recoup what this company cost their brand.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>i can shed some light on the debacle. i used to work for said company side-by-side with their former frontend developer who built those exact sites that were hacked. i heard him stress time and time again that they needed to be updated to no avail due to the owner, who wasn&#8217;t the brightest bulb in the bunch and knew nothing about joomla. i left before the frontend dev decided to leave in 2009 due to a breach of contract by the owner and the frontend dev. that&#8217;s only the tip of the iceberg for the incompetence and arrogance of the company and its owner. so, yes, the company is clearly in the wrong here and shouldn&#8217;t be allowed in the house imo.</p>

<p>regarding okomo: it isn&#8217;t even a cms. it&#8217;s just a ‘really’ basic platform built on django masquerading as a cms, but definitely not a cms as the company states.</p>

<p>while, yes, i think a response is necessary on joomla&#8217;s part, this company deserves no help whatsoever from the joomla community when they&#8217;re not willing to accept it. it&#8217;s a shame that such companies are allowed to represent joomla to the federal govt when so many people dedicate their time to the project. i can only hope the house blocks them from doing business there and that they learn a valuable lesson.</p>

<p>joomla should write a response and perform some positive pr to recoup what this company cost their brand.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: InfoSec Daily &#187; Episode 58 &#8211; Hiding in the Noise</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6558</link>
		<dc:creator>InfoSec Daily &#187; Episode 58 &#8211; Hiding in the Noise</dc:creator>
		<pubDate>Mon, 01 Feb 2010 23:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6558</guid>
		<description>&lt;p&gt;[...] researchers at Praetorian Security Group, a managed security services and consultancy, wrote in a blog post Thursday. News item 7:  [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] researchers at Praetorian Security Group, a managed security services and consultancy, wrote in a blog post Thursday. News item 7:  [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: The TechList: 30.Jan.2010</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6446</link>
		<dc:creator>The TechList: 30.Jan.2010</dc:creator>
		<pubDate>Sat, 30 Jan 2010 16:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6446</guid>
		<description>&lt;p&gt;[...] US Congress. Sites defaced by Brazilian hackers. See what happens when you let a non-American socialist take supreme [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] US Congress. Sites defaced by Brazilian hackers. See what happens when you let a non-American socialist take supreme [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6410</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Fri, 29 Jan 2010 20:10:44 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6410</guid>
		<description>&lt;p&gt;Thanks!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: InfoSec Pro</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6409</link>
		<dc:creator>InfoSec Pro</dc:creator>
		<pubDate>Fri, 29 Jan 2010 18:47:31 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6409</guid>
		<description>&lt;p&gt;@routeraccess - totally wrong, GovTrends != &quot;Website Development Group in the Senate&quot;&lt;/p&gt;

&lt;p&gt;Senate and House are totally separate, and GovTrends is a corporate (private-sector) contractor offering services to the House membership.&lt;/p&gt;

&lt;p&gt;If you don&#039;t know what you are talking about, don&#039;t post!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@routeraccess &#8211; totally wrong, GovTrends != &#8220;Website Development Group in the Senate&#8221;</p>

<p>Senate and House are totally separate, and GovTrends is a corporate (private-sector) contractor offering services to the House membership.</p>

<p>If you don&#8217;t know what you are talking about, don&#8217;t post!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Elin Waring</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6408</link>
		<dc:creator>Elin Waring</dc:creator>
		<pubDate>Fri, 29 Jan 2010 15:56:47 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6408</guid>
		<description>&lt;p&gt;What the defaced sites all had in common is that they were operated by the same vendor and all were using software  versions that are at least 6 months behind the current releases and some that is so old that it is no longer receiving support. No sites with vendors other than Gov Trends were impacted because those sites had up to date software. It is imperative that people managing websites keep their software up to date since new releases almost always include security improvements.&lt;/p&gt;

&lt;p&gt;This is not something that happened because of doing an update; it happened because of NOT doing updates on a routine basis therefore allowing criminals to exploit known vulnerabilities.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>What the defaced sites all had in common is that they were operated by the same vendor and all were using software  versions that are at least 6 months behind the current releases and some that is so old that it is no longer receiving support. No sites with vendors other than Gov Trends were impacted because those sites had up to date software. It is imperative that people managing websites keep their software up to date since new releases almost always include security improvements.</p>

<p>This is not something that happened because of doing an update; it happened because of NOT doing updates on a routine basis therefore allowing criminals to exploit known vulnerabilities.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Portuguese speaker</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6407</link>
		<dc:creator>Portuguese speaker</dc:creator>
		<pubDate>Fri, 29 Jan 2010 14:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6407</guid>
		<description>&lt;p&gt;Actually, the worlds &quot;O RESTO E HACKER&quot; should probably be read as &quot;O resto É hacker&quot; (an &quot;e&quot; with an accent mark). That&#039;s a colloquial form of saying &quot;The rest are hackers&quot;.&lt;/p&gt;

&lt;p&gt;They are probably bragging about that defacement as making them the only real &quot;crackers&quot;, while &quot;the rest&quot; [the ones who can&#039;t crack a website of such importance] are mere &quot;hackers&quot;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Actually, the worlds &#8220;O RESTO E HACKER&#8221; should probably be read as &#8220;O resto É hacker&#8221; (an &#8220;e&#8221; with an accent mark). That&#8217;s a colloquial form of saying &#8220;The rest are hackers&#8221;.</p>

<p>They are probably bragging about that defacement as making them the only real &#8220;crackers&#8221;, while &#8220;the rest&#8221; [the ones who can't crack a website of such importance] are mere &#8220;hackers&#8221;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressional Web Site Defacements Follow the State of the Union &#171; All Things MadTek</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6406</link>
		<dc:creator>Congressional Web Site Defacements Follow the State of the Union &#171; All Things MadTek</dc:creator>
		<pubDate>Fri, 29 Jan 2010 14:00:52 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6406</guid>
		<description>&lt;p&gt;[...] Congressional Web Site Defacements Follow the State of the Union. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Congressional Web Site Defacements Follow the State of the Union. [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Alberto Bartoli</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6404</link>
		<dc:creator>Alberto Bartoli</dc:creator>
		<pubDate>Fri, 29 Jan 2010 10:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6404</guid>
		<description>&lt;p&gt;I am trying to have a more detailed idea about how long the defacements have been in place (for research purposes). Any idea about that ? The news states from &quot;shortly after the President State of the Union address&quot; and &quot;at 4 AM&quot; they were still in place. Perhaps somebody might have more details...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I am trying to have a more detailed idea about how long the defacements have been in place (for research purposes). Any idea about that ? The news states from &#8220;shortly after the President State of the Union address&#8221; and &#8220;at 4 AM&#8221; they were still in place. Perhaps somebody might have more details&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressional Web sites hacked near Obama speech &#171; Kotak Infotech</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6403</link>
		<dc:creator>Congressional Web sites hacked near Obama speech &#171; Kotak Infotech</dc:creator>
		<pubDate>Fri, 29 Jan 2010 07:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6403</guid>
		<description>&lt;p&gt;[...] the attacks have been recorded by Zone-H, a Web site that keep tracks of defacements, according to the blog of the Praetorian Security Group. The latest attacks had not been listed by Zone-H [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] the attacks have been recorded by Zone-H, a Web site that keep tracks of defacements, according to the blog of the Praetorian Security Group. The latest attacks had not been listed by Zone-H [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6397</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Fri, 29 Jan 2010 00:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6397</guid>
		<description>&lt;p&gt;Reasonable minds think alike ;)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Reasonable minds think alike ;)</p>]]></content:encoded>
	</item>
</channel>
</rss>

