Trump's cyber-guru Giuliani runs ancient 'easily hackable website'

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Stunned security experts tear strips off president-elect pick hours after announcement
US president-elect Donald Trump's freshly minted cyber-tsar Rudy Giuliani runs a website with a content management system years out of date and potentially utterly hackable.

Former New York City mayor and Donald loyalist Giuliani was today unveiled by Trump's transition team as the future president's cybersecurity adviser – meaning Giuliani will play a crucial role in the defense of America's computer infrastructure.

Giulianisecurity.com, the website for the ex-mayor's eponymous infosec consultancy firm, is powered by a roughly five-year-old build of Joomla! that is packed with vulnerabilities. Some of those bugs can be potentially exploited by miscreants using basic SQL injection techniques to compromise the server.

This seemingly insecure system also has a surprising number of network ports open – from MySQL and anonymous LDAP to a very out-of-date OpenSSH 4.7 that was released in 2007.

Security gurus are right now tearing strips off Trump's cyber-wizard pick. Top hacker Dan Tentler was first to point out the severely out-of-date Joomla! install.

"It speaks volumes," Tentler told The Register, referring to Giuliani's computer security credentials, or lack of, and fitness for the top post.

"Seventy-year-old luddite autocrats who often brag about not using technology are somehow put in charge of technology: it's like setting our country on fire and giving every extranational hacker a roman candle – or, rather, not setting on fire, but dousing in gasoline."

...more in the link above...
 

In2an3_PpG

Level 18
Verified
Top Poster
Content Creator
Well-known
Nov 15, 2016
867
Well were not gonna necessarily agree with Trump 100% of the time. In my eyes Giuliani should of been named US AG instead of Sessions. Not the cyber role.
 
  • Like
Reactions: LASER_oneXM

LASER_oneXM

Level 37
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
..here is another article about Guliani's security firm:
Trump's New Cyber-Security Advisor Runs a Very, Very Insecure Website

...and some quotes from the article... .....couldn't believe this...: :D

Giuliani's company using three-year-old Joomla version

According to Phonos Group founder Dan Tentler, Giuliani's security company website runs a very, very old Joomla distribution, an open-source, free-to-use CMS.

That's Joomla 3.1.1, released in April 2013. Since then, two major zero-days have plagued Joomla, so grave that they could allow attackers to take full control over a Joomla installation. Those are CVE-2016-9838 and CVE-2015-8562.

Running an end-of-life PHP version on a nine-year-old OS

Security researcher Michael Fienen also noticed that the underlying server, where the website is hosted, also uses PHP 5.4.45, now a deprecated version of PHP.

The server, which runs a nine-year-old FreeBSD 6 version, also allows for remote SSH connections, which usually should be allowed only to a limited set of IPs. In fact, lots of server services seem to be open to remote connections.
 

Vipersd

Level 6
Verified
Dec 14, 2014
285
Honey pot for what?

It is more logical that honey pot is set on government sites rather then private company in this case.
 
  • Like
Reactions: Zero Knowledge

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top