CGISecurity Logo

Fox News Pwned

""While browsing around the Fox News website, I found that directory
indexes are turned on. So, I started following the tree up, until I got
to /admin. Eventually, I found my way into /admin/xml_parser/zdnet/, in
which, there is a shell script. Seeing as it's a shell script, and I
use Linux, I took a peek. Inside, is a username and password to an FTP.
So, of course, I tried to login. The result? Epic fail on Fox's part.
And seriously, what kind of password is T1me Out. This is just
pathetic.""

This sort of stupid mistake is actually more common than you'd think.

Article Link: http://it.slashdot.org/article.pl?sid=07/07/23/1210255