[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ab13993b0505260744384d5f78@mail.gmail.com>
Date: Thu May 26 15:44:57 2005
From: anthrax101 at gmail.com (Aaron Horst)
Subject: Not even the NSA can get it right
On 5/25/05, Castigliola, Angelo <ACastigliola@...mprovident.com> wrote:
> What would XSS on NSA.GOV get a hacker anyways? Steal my NSA.GOV cookie
>
> "CFID
> 756140
> nsa.gov/
> 1024
> 2871474816
> 31895379
> 3010520960
> 29692615
> *
> CFTOKEN
> 41950083
> nsa.gov/
> 1024
> 2871474816
> 31895379
> 3010820960
> 29692615
> *"
>
> Don't think a hacker could do much with this. At best someone could try
> to use the exploit to phish passwords from NSA.GOV employees.
>
> -Angelo Castigliola III
> Security Architect
>
I don't know about you, but I personally think you could do quite a
bit of identity theft by seeing a few NSA applicants' resumes. Who
else would be more willing to give a "recruiter" sensitive personal
information?
https://www.nsa.gov/applyonline/index.html
AnthraX101
Powered by blists - more mailing lists