<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Congressional Web Site Defacements Follow the State of the Union</title>
	<atom:link href="http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 29 Jul 2010 21:18:11 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bob Smith</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6561</link>
		<dc:creator>Bob Smith</dc:creator>
		<pubDate>Tue, 02 Feb 2010 01:25:05 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6561</guid>
		<description>&lt;p&gt;i can shed some light on the debacle. i used to work for said company side-by-side with their former frontend developer who built those exact sites that were hacked. i heard him stress time and time again that they needed to be updated to no avail due to the owner, who wasn&#039;t the brightest bulb in the bunch and knew nothing about joomla. i left before the frontend dev decided to leave in 2009 due to a breach of contract by the owner and the frontend dev. that&#039;s only the tip of the iceberg for the incompetence and arrogance of the company and its owner. so, yes, the company is clearly in the wrong here and shouldn&#039;t be allowed in the house imo.&lt;/p&gt;

&lt;p&gt;regarding okomo: it isn&#039;t even a cms. it&#039;s just a ‘really’ basic platform built on django masquerading as a cms, but definitely not a cms as the company states.&lt;/p&gt;

&lt;p&gt;while, yes, i think a response is necessary on joomla&#039;s part, this company deserves no help whatsoever from the joomla community when they&#039;re not willing to accept it. it&#039;s a shame that such companies are allowed to represent joomla to the federal govt when so many people dedicate their time to the project. i can only hope the house blocks them from doing business there and that they learn a valuable lesson.&lt;/p&gt;

&lt;p&gt;joomla should write a response and perform some positive pr to recoup what this company cost their brand.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>i can shed some light on the debacle. i used to work for said company side-by-side with their former frontend developer who built those exact sites that were hacked. i heard him stress time and time again that they needed to be updated to no avail due to the owner, who wasn&#8217;t the brightest bulb in the bunch and knew nothing about joomla. i left before the frontend dev decided to leave in 2009 due to a breach of contract by the owner and the frontend dev. that&#8217;s only the tip of the iceberg for the incompetence and arrogance of the company and its owner. so, yes, the company is clearly in the wrong here and shouldn&#8217;t be allowed in the house imo.</p>

<p>regarding okomo: it isn&#8217;t even a cms. it&#8217;s just a ‘really’ basic platform built on django masquerading as a cms, but definitely not a cms as the company states.</p>

<p>while, yes, i think a response is necessary on joomla&#8217;s part, this company deserves no help whatsoever from the joomla community when they&#8217;re not willing to accept it. it&#8217;s a shame that such companies are allowed to represent joomla to the federal govt when so many people dedicate their time to the project. i can only hope the house blocks them from doing business there and that they learn a valuable lesson.</p>

<p>joomla should write a response and perform some positive pr to recoup what this company cost their brand.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: InfoSec Daily &#187; Episode 58 &#8211; Hiding in the Noise</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6558</link>
		<dc:creator>InfoSec Daily &#187; Episode 58 &#8211; Hiding in the Noise</dc:creator>
		<pubDate>Mon, 01 Feb 2010 23:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6558</guid>
		<description>&lt;p&gt;[...] researchers at Praetorian Security Group, a managed security services and consultancy, wrote in a blog post Thursday. News item 7:  [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] researchers at Praetorian Security Group, a managed security services and consultancy, wrote in a blog post Thursday. News item 7:  [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: The TechList: 30.Jan.2010</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6446</link>
		<dc:creator>The TechList: 30.Jan.2010</dc:creator>
		<pubDate>Sat, 30 Jan 2010 16:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6446</guid>
		<description>&lt;p&gt;[...] US Congress. Sites defaced by Brazilian hackers. See what happens when you let a non-American socialist take supreme [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] US Congress. Sites defaced by Brazilian hackers. See what happens when you let a non-American socialist take supreme [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6410</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Fri, 29 Jan 2010 20:10:44 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6410</guid>
		<description>&lt;p&gt;Thanks!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: InfoSec Pro</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6409</link>
		<dc:creator>InfoSec Pro</dc:creator>
		<pubDate>Fri, 29 Jan 2010 18:47:31 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6409</guid>
		<description>&lt;p&gt;@routeraccess - totally wrong, GovTrends != &quot;Website Development Group in the Senate&quot;&lt;/p&gt;

&lt;p&gt;Senate and House are totally separate, and GovTrends is a corporate (private-sector) contractor offering services to the House membership.&lt;/p&gt;

&lt;p&gt;If you don&#039;t know what you are talking about, don&#039;t post!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@routeraccess &#8211; totally wrong, GovTrends != &#8220;Website Development Group in the Senate&#8221;</p>

<p>Senate and House are totally separate, and GovTrends is a corporate (private-sector) contractor offering services to the House membership.</p>

<p>If you don&#8217;t know what you are talking about, don&#8217;t post!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Elin Waring</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6408</link>
		<dc:creator>Elin Waring</dc:creator>
		<pubDate>Fri, 29 Jan 2010 15:56:47 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6408</guid>
		<description>&lt;p&gt;What the defaced sites all had in common is that they were operated by the same vendor and all were using software  versions that are at least 6 months behind the current releases and some that is so old that it is no longer receiving support. No sites with vendors other than Gov Trends were impacted because those sites had up to date software. It is imperative that people managing websites keep their software up to date since new releases almost always include security improvements.&lt;/p&gt;

&lt;p&gt;This is not something that happened because of doing an update; it happened because of NOT doing updates on a routine basis therefore allowing criminals to exploit known vulnerabilities.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>What the defaced sites all had in common is that they were operated by the same vendor and all were using software  versions that are at least 6 months behind the current releases and some that is so old that it is no longer receiving support. No sites with vendors other than Gov Trends were impacted because those sites had up to date software. It is imperative that people managing websites keep their software up to date since new releases almost always include security improvements.</p>

<p>This is not something that happened because of doing an update; it happened because of NOT doing updates on a routine basis therefore allowing criminals to exploit known vulnerabilities.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Portuguese speaker</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6407</link>
		<dc:creator>Portuguese speaker</dc:creator>
		<pubDate>Fri, 29 Jan 2010 14:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6407</guid>
		<description>&lt;p&gt;Actually, the worlds &quot;O RESTO E HACKER&quot; should probably be read as &quot;O resto É hacker&quot; (an &quot;e&quot; with an accent mark). That&#039;s a colloquial form of saying &quot;The rest are hackers&quot;.&lt;/p&gt;

&lt;p&gt;They are probably bragging about that defacement as making them the only real &quot;crackers&quot;, while &quot;the rest&quot; [the ones who can&#039;t crack a website of such importance] are mere &quot;hackers&quot;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Actually, the worlds &#8220;O RESTO E HACKER&#8221; should probably be read as &#8220;O resto É hacker&#8221; (an &#8220;e&#8221; with an accent mark). That&#8217;s a colloquial form of saying &#8220;The rest are hackers&#8221;.</p>

<p>They are probably bragging about that defacement as making them the only real &#8220;crackers&#8221;, while &#8220;the rest&#8221; [the ones who can't crack a website of such importance] are mere &#8220;hackers&#8221;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressional Web Site Defacements Follow the State of the Union &#171; All Things MadTek</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6406</link>
		<dc:creator>Congressional Web Site Defacements Follow the State of the Union &#171; All Things MadTek</dc:creator>
		<pubDate>Fri, 29 Jan 2010 14:00:52 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6406</guid>
		<description>&lt;p&gt;[...] Congressional Web Site Defacements Follow the State of the Union. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Congressional Web Site Defacements Follow the State of the Union. [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Alberto Bartoli</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6404</link>
		<dc:creator>Alberto Bartoli</dc:creator>
		<pubDate>Fri, 29 Jan 2010 10:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6404</guid>
		<description>&lt;p&gt;I am trying to have a more detailed idea about how long the defacements have been in place (for research purposes). Any idea about that ? The news states from &quot;shortly after the President State of the Union address&quot; and &quot;at 4 AM&quot; they were still in place. Perhaps somebody might have more details...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I am trying to have a more detailed idea about how long the defacements have been in place (for research purposes). Any idea about that ? The news states from &#8220;shortly after the President State of the Union address&#8221; and &#8220;at 4 AM&#8221; they were still in place. Perhaps somebody might have more details&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Congressional Web sites hacked near Obama speech &#171; Kotak Infotech</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6403</link>
		<dc:creator>Congressional Web sites hacked near Obama speech &#171; Kotak Infotech</dc:creator>
		<pubDate>Fri, 29 Jan 2010 07:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6403</guid>
		<description>&lt;p&gt;[...] the attacks have been recorded by Zone-H, a Web site that keep tracks of defacements, according to the blog of the Praetorian Security Group. The latest attacks had not been listed by Zone-H [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] the attacks have been recorded by Zone-H, a Web site that keep tracks of defacements, according to the blog of the Praetorian Security Group. The latest attacks had not been listed by Zone-H [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6397</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Fri, 29 Jan 2010 00:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6397</guid>
		<description>&lt;p&gt;Reasonable minds think alike ;)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Reasonable minds think alike ;)</p>]]></content:encoded>
	</item>
	<item>
		<title>By: routeraccess</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6396</link>
		<dc:creator>routeraccess</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:50:39 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6396</guid>
		<description>&lt;blockquote&gt;
  &lt;p&gt;what possible update were they performing that caused the sites to be defaced?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Instead of answering your question, I will pose another: even if GT was performing an update in some manner, how did this compromise the House firewall and allow &quot;hackers&quot; the ability to post over the Joomla!-generated homepage code?&lt;/p&gt;

&lt;p&gt;From a simple ping (before HIR took over the sites today) you can see GovTrends&#039; House servers are assigned IP addresses within AS1999, which presumably is behind the same House firewall that protects HIR and other vendors&#039; systems in the same class C.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<blockquote>
  <p>what possible update were they performing that caused the sites to be defaced?</p>
</blockquote>

<p>Instead of answering your question, I will pose another: even if GT was performing an update in some manner, how did this compromise the House firewall and allow &#8220;hackers&#8221; the ability to post over the Joomla!-generated homepage code?</p>

<p>From a simple ping (before HIR took over the sites today) you can see GovTrends&#8217; House servers are assigned IP addresses within AS1999, which presumably is behind the same House firewall that protects HIR and other vendors&#8217; systems in the same class C.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6395</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6395</guid>
		<description>&lt;p&gt;The upgrading systems excuse is lame without further information to back it up.&lt;/p&gt;

&lt;p&gt;One point on the timing: the defacements happened after the State of the Union, perfect timing for constituents to review the &quot;reaction statements&quot; by their congressional representatives.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The upgrading systems excuse is lame without further information to back it up.</p>

<p>One point on the timing: the defacements happened after the State of the Union, perfect timing for constituents to review the &#8220;reaction statements&#8221; by their congressional representatives.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Not A Security Guy</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6394</link>
		<dc:creator>Not A Security Guy</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6394</guid>
		<description>&lt;p&gt;Why is the timing odd? Like many of us, techies at GovTrends probably work around the clock. Also, if the timing was intentional, they may have thought most politically-minded people would be watching the State of the Union on TV and not looking at congressional websites. Just a hunch.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Why is the timing odd? Like many of us, techies at GovTrends probably work around the clock. Also, if the timing was intentional, they may have thought most politically-minded people would be watching the State of the Union on TV and not looking at congressional websites. Just a hunch.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6393</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:08:10 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6393</guid>
		<description>&lt;p&gt;For me that would beg the question, what possible update were they performing that caused the sites to be defaced?&lt;/p&gt;

&lt;p&gt;Doesn&#039;t make sense as a theory without more detail. The response to this problem has been lacking, but as you can see they won&#039;t even respond to their customers (Representative Bachus) when a problem happens.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>For me that would beg the question, what possible update were they performing that caused the sites to be defaced?</p>

<p>Doesn&#8217;t make sense as a theory without more detail. The response to this problem has been lacking, but as you can see they won&#8217;t even respond to their customers (Representative Bachus) when a problem happens.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6392</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:06:20 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6392</guid>
		<description>&lt;p&gt;You know that&#039;s not the point we were making, don&#039;t argue against a point we didn&#039;t make.&lt;/p&gt;

&lt;p&gt;Joomla&#039;s CMS is only a possible entry point, anyone walking away from the story with &quot;Joomla is insecure&quot; missed the point.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You know that&#8217;s not the point we were making, don&#8217;t argue against a point we didn&#8217;t make.</p>

<p>Joomla&#8217;s CMS is only a possible entry point, anyone walking away from the story with &#8220;Joomla is insecure&#8221; missed the point.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6391</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Thu, 28 Jan 2010 23:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6391</guid>
		<description>&lt;p&gt;Sure, the story is not a Joomla vulnerability (we don&#039;t even have confirmation that&#039;s what it is, we just say that&#039;s where we&#039;d start looking).&lt;/p&gt;

&lt;p&gt;I don&#039;t know if I believe the &quot;default password&quot; story from last August, the defacement doesn&#039;t line up neatly with that theory, the only one saying that is the vendor, and they wouldn&#039;t let anyone check their work.&lt;/p&gt;

&lt;p&gt;We have the source code, its just this:&lt;/p&gt;

&lt;p&gt;&lt;pre&gt;&lt;code&gt;FUCK OBAMA!! Red Eye CREW !!!!! O RESTO E HACKER !!! by HADES; m4V3RiCk; T4ph0d4 -- FROM BRASIL
&lt;/code&gt;&lt;/pre&gt;&lt;/p&gt;

&lt;p&gt;The story is GovTrends, and by extension the HIR&#039;s management of these web sites.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Sure, the story is not a Joomla vulnerability (we don&#8217;t even have confirmation that&#8217;s what it is, we just say that&#8217;s where we&#8217;d start looking).</p>

<p>I don&#8217;t know if I believe the &#8220;default password&#8221; story from last August, the defacement doesn&#8217;t line up neatly with that theory, the only one saying that is the vendor, and they wouldn&#8217;t let anyone check their work.</p>

<p>We have the source code, its just this:</p>

<p><pre><code>FUCK OBAMA!! Red Eye CREW !!!!! O RESTO E HACKER !!! by HADES; m4V3RiCk; T4ph0d4 -- FROM BRASIL
</code></pre></p>

<p>The story is GovTrends, and by extension the HIR&#8217;s management of these web sites.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: routeraccess</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6390</link>
		<dc:creator>routeraccess</dc:creator>
		<pubDate>Thu, 28 Jan 2010 22:20:59 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6390</guid>
		<description>&lt;p&gt;The latest from the AP/Politico indicates:&lt;/p&gt;

&lt;p&gt;&quot;the working theory is that the penetration happened during an upgrade that GovTrends was making to its own system.&quot;&lt;/p&gt;

&lt;p&gt;Which begs the question, why was GovTrends upgrading their system near the time or during a State of the Union news event?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The latest from the AP/Politico indicates:</p>

<p>&#8220;the working theory is that the penetration happened during an upgrade that GovTrends was making to its own system.&#8221;</p>

<p>Which begs the question, why was GovTrends upgrading their system near the time or during a State of the Union news event?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: routeraccess</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6389</link>
		<dc:creator>routeraccess</dc:creator>
		<pubDate>Thu, 28 Jan 2010 22:15:00 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6389</guid>
		<description>&lt;p&gt;In all likelihood this has &lt;em&gt;nothing&lt;/em&gt; to do with Joomla! exploits and &lt;em&gt;everything&lt;/em&gt; to do with GovTrends/WDG/DCS/DialogueConcepts dropping the ball similar to last August (externally available page to update the website). One guess would be that the &quot;hackers&quot; used CSS to display:none !important; everything but their message window. Wish someone had the site code instead of just screenshots.&lt;/p&gt;

&lt;p&gt;Given Joomla!&#039;s heritage, I doubt this particular incident will be seen as a Joomla! specific issue as much as it is a GovTrends specific security problem. At least the GovTrends website lightbox pop-over assures us that &quot;We are true artists, experienced web developers &amp; not beginners.&quot;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>In all likelihood this has <em>nothing</em> to do with Joomla! exploits and <em>everything</em> to do with GovTrends/WDG/DCS/DialogueConcepts dropping the ball similar to last August (externally available page to update the website). One guess would be that the &#8220;hackers&#8221; used CSS to display:none !important; everything but their message window. Wish someone had the site code instead of just screenshots.</p>

<p>Given Joomla!&#8217;s heritage, I doubt this particular incident will be seen as a Joomla! specific issue as much as it is a GovTrends specific security problem. At least the GovTrends website lightbox pop-over assures us that &#8220;We are true artists, experienced web developers &amp; not beginners.&#8221;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: herdboy</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6388</link>
		<dc:creator>herdboy</dc:creator>
		<pubDate>Thu, 28 Jan 2010 22:14:13 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6388</guid>
		<description>&lt;p&gt;The blame for this lies squarely at the feet of the Site Owners and their Web Support Teams.&lt;/p&gt;

&lt;p&gt;Any website is only as safe as the protection you put in place&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The blame for this lies squarely at the feet of the Site Owners and their Web Support Teams.</p>

<p>Any website is only as safe as the protection you put in place</p>]]></content:encoded>
	</item>
	<item>
		<title>By: zaridan</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6387</link>
		<dc:creator>zaridan</dc:creator>
		<pubDate>Thu, 28 Jan 2010 21:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6387</guid>
		<description>&lt;p&gt;http://osvdb.org/vendor/4358-joomla/1&lt;/p&gt;

&lt;p&gt;Tell me where there are Joomla exploits listed there that are core Joomla 1.5 issues???&lt;/p&gt;

&lt;p&gt;Joomla 1.0 had it&#039;s share of vulnerabilities, however that version of Joomla is very old and now completely obsolete!
Even so, Joomla devs have always done a good job of updating core files when exploits are found, and 99.9% of the time an &#039;exploited site&#039; can be traced to some extension or other server exploit.&lt;/p&gt;

&lt;p&gt;Bottom line is the people who were responsible for those sites fell asleep on the job.  An unfortunate circumstance for the one&#039;s who trusted their sites to be managed by them, and for the reputation of Joomla, which will no doubt be the butt of finger pointing over this one.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><a href="http://osvdb.org/vendor/4358-joomla/1" rel="nofollow">http://osvdb.org/vendor/4358-joomla/1</a></p>

<p>Tell me where there are Joomla exploits listed there that are core Joomla 1.5 issues???</p>

<p>Joomla 1.0 had it&#8217;s share of vulnerabilities, however that version of Joomla is very old and now completely obsolete!
Even so, Joomla devs have always done a good job of updating core files when exploits are found, and 99.9% of the time an &#8216;exploited site&#8217; can be traced to some extension or other server exploit.</p>

<p>Bottom line is the people who were responsible for those sites fell asleep on the job.  An unfortunate circumstance for the one&#8217;s who trusted their sites to be managed by them, and for the reputation of Joomla, which will no doubt be the butt of finger pointing over this one.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Bringing Down the House: Hackers Deface U.S. Government Websites - www.Korallenkacke.com</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6379</link>
		<dc:creator>Bringing Down the House: Hackers Deface U.S. Government Websites - www.Korallenkacke.com</dc:creator>
		<pubDate>Thu, 28 Jan 2010 20:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6379</guid>
		<description>&lt;p&gt;[...] the websites of the House of Representatives and those of multiple congressional members were defaced with anti-Obama messages. Among the defaced sites were those of Charles Gonzalez (20th District of [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] the websites of the House of Representatives and those of multiple congressional members were defaced with anti-Obama messages. Among the defaced sites were those of Charles Gonzalez (20th District of [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rum, Romanism and Rebellion &#187; Blog Archive &#187; Mitchell Hacked!</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6378</link>
		<dc:creator>Rum, Romanism and Rebellion &#187; Blog Archive &#187; Mitchell Hacked!</dc:creator>
		<pubDate>Thu, 28 Jan 2010 16:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6378</guid>
		<description>&lt;p&gt;[...] the group of 26 members of the house whose sites were hacked was our own Harry Mitchell. According to the site Praetorian Prefect (Ford&#8217;s brother, I guess), the sites were hacked by a group called Red Eye Crew. Previously, [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] the group of 26 members of the house whose sites were hacked was our own Harry Mitchell. According to the site Praetorian Prefect (Ford&#8217;s brother, I guess), the sites were hacked by a group called Red Eye Crew. Previously, [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: More than Two Dozen Congressional Websites Defaced &#171; AKS-Feel The Change!</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6376</link>
		<dc:creator>More than Two Dozen Congressional Websites Defaced &#171; AKS-Feel The Change!</dc:creator>
		<pubDate>Thu, 28 Jan 2010 16:51:56 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6376</guid>
		<description>&lt;p&gt;[...] Read more &#8211; Praetorian Prefect [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Read more &#8211; Praetorian Prefect [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: More than Two Dozen Congressional Web sites Defaced &#171; AKS-Feel The Change!</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6375</link>
		<dc:creator>More than Two Dozen Congressional Web sites Defaced &#171; AKS-Feel The Change!</dc:creator>
		<pubDate>Thu, 28 Jan 2010 16:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6375</guid>
		<description>&lt;p&gt;[...] Read more &#8211; Praetorian Prefect [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Read more &#8211; Praetorian Prefect [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: TwittLink - Your headlines on Twitter</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6374</link>
		<dc:creator>TwittLink - Your headlines on Twitter</dc:creator>
		<pubDate>Thu, 28 Jan 2010 15:31:55 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6374</guid>
		<description>&lt;p&gt;[...] Tweets about this great post on TwittLink.com [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Tweets about this great post on TwittLink.com [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: routeraccess</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6373</link>
		<dc:creator>routeraccess</dc:creator>
		<pubDate>Thu, 28 Jan 2010 14:55:34 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6373</guid>
		<description>&lt;p&gt;Those are all websites produced and managed by GovTrends, aka Website Development Group in the Senate.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Those are all websites produced and managed by GovTrends, aka Website Development Group in the Senate.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Democrats sites targetted by hackers, Congress hacked near Obama speech. - Technology News - Kalovski Itim Online</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6372</link>
		<dc:creator>Democrats sites targetted by hackers, Congress hacked near Obama speech. - Technology News - Kalovski Itim Online</dc:creator>
		<pubDate>Thu, 28 Jan 2010 14:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6372</guid>
		<description>&lt;p&gt;[...] hacked sites that Praetorian investigated were hosted on a server called &#8220;dcserver1.house.gov,&#8221; but not all sites on that server were hacked. Many of the sites were using Joomla, which [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] hacked sites that Praetorian investigated were hosted on a server called &#8220;dcserver1.house.gov,&#8221; but not all sites on that server were hacked. Many of the sites were using Joomla, which [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Red Eye CREW takes out Two Dozen US Congresional Websites at The Hacker News Network</title>
		<link>http://praetorianprefect.com/archives/2010/01/congressional-web-site-defacements-follow-the-state-of-the-union/comment-page-1/#comment-6371</link>
		<dc:creator>Red Eye CREW takes out Two Dozen US Congresional Websites at The Hacker News Network</dc:creator>
		<pubDate>Thu, 28 Jan 2010 13:23:41 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3236#comment-6371</guid>
		<description>&lt;p&gt;[...] via Praetorian Prefect &#124; Congressional Web Site Defacements Follow the State of the Union. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] via Praetorian Prefect | Congressional Web Site Defacements Follow the State of the Union. [...]</p>]]></content:encoded>
	</item>
</channel>
</rss>
