Foxnews File Disclosure.
Publicated on :
1185192330
Fox news has been all over the news, as ironic as this might sound. It is quite true. Another case of scattered files, no intrusion detection and sleeping sys admins. This hole has been open all day, has been digged some thousand times now and no one at Fox seems to notice. At least we don't sleep. Update: According to Jeff Misenti, General Manager and VP of Fox News Digital,It was a server communications error which was fixed immediately and steps were taken to make sure it does not happen again.
Sure, these things can happen but it's a little strange someone else found it first. We all do make mistakes because we are human. But, they cannot escape the fact they made some errors, that could have been avoided with a clever and well thought security policy. Instead of complaining only, I show you a couple of measures I would have taken:
1. Never store those sensitive files in a publicly accessible folder, always below.
2. Audit the server weekly on scattered files by others.
3. Options -Indexes
This was found by Gordon Lowrey, and the Digg community.