Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes |
|---|---|
| Date: | Tue, 28 Sep 2004 08:38:58 -0400 |
Nice call with the MD6 checksums(MD5 might be cracked, as a recent letter to bugtraq demonstrated :) ran on the electronic voting systems. That would be a good way to verify the authenticity of the code, after it was posted on sourceforge. As for the paper trails, does it really matter? An earlier post pointed out that if your code isnt open source, whats to stop you from coding your SW to print one thing while entering another into the database? I know of at least 5 companies I could hire to independently verify anything I would like them to. What scares me most about GEMS is the fact that the systems are networked. If we are going to have an election system that communicates with a central repository, then there will be the chance that 1 person/group of people/company can hijack an election unless there are major steps taken (or any steps taken) to verify and secure the process. Might as well have a website at whitehouse.gov where we can log in and post our vote via PKI authentication if we are going that route :) -JP -----Original Message----- From: Jeremy Epstein [mailto:jeremy.epstein@webmethods.com]
| Previous by Date: | [Full-Disclosure] [FLSA-2004:1581] Updated flim packages fix security vulnerability, Dominic Hargreaves |
|---|---|
| Next by Date: | Re: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes, trh |
| Previous by Thread: | Re: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes, ERACC |
| Next by Thread: | [Full-Disclosure] [ GLSA 200409-29 ] FreeRADIUS: Multiple Denial of Service vulnerabilities, Sune Kloppenborg Jeppesen |
| Indexes: | [Date] [Thread] [Top] [All Lists] |