Home
South African Technology Weblog

User login

Projects and Services hosted on div0

Syndicate

Syndicate content

Aggregation





I shmaak SA Blogs, sorted with Amatomu.com

Afrigator

Add to Technorati Favorites

SATS

eNaTIS hack indeed "laughable"

enatis
As those following local online news media might know, the eNaTIS website, enatis.com, was recently defaced. Soon after, a torrent of "eNaTIS hacked!" sensationalism swept South African internet news sites spreading FUD (fear, uncertainty, doubt) like a bad flu. Certainly online media writers are not so clueless as to think that a simple Joomla defacement has anything to do with the actual eNaTIS system whatsoever? This google search seems say otherwise: http://www.google.co.za/search?q=enatis+hacked

South African hackers everywhere flinch as the media once again defiles their most sacred of titles. For those who do not understand how defacements work, here is a short summary:
Many websites use publicly available web-software (like Joomla in eNaTIS's case), produced by communities of open-source developers.
This software is released for free and with all source code available.
Since many people use this free software, hackers inspect the source and find holes or "vulnerabilities" that could allow them administrative access to an installed version.
They then trade these "exploits" with other hackers or make them publicly available online, after which far less experienced people, without any programming knowledge (like the eNaTIS "hacker") may then obtain it.

Perhaps eNaTIS should have looked at a more professional website presentation solution, or perhaps they should have simply kept their website up to date...