wah Heng ah - GOOGLE not scared of PAP whoa

god_zeus

Alfrescian
Loyal
Joined
Oct 26, 2008
Messages
2,247
Points
48
http://www.tremeritus.com/2013/11/15/google-refutes-idas-accusation/

Google refutes IDA’s accusation

Last week, PMO and Istana websites were “compromised”.

In the early hours of Friday (8 Nov), IDA issued a statement saying that a subpage for search on the PMO website was reported to be compromised:

A vulnerability in that subpage was exploited to display pages from other sources. This vulnerability is known as cross-site scripting. The PMO main website is still working, and we are working to restore the page that has been compromised. The matter is under investigation.

However, PMO main site remained working.

At a media briefing in Friday afternoon, IDA then blamed a vulnerability in the Google search bar used by PMO and Istana websites, which allowed the sites to be compromised [Link]:

“THE websites of the Prime Minister’s Office (PMO) and Istana were not hacked but were compromised, the Infocomm Development Authority of Singapore (IDA) said yesterday.

A vulnerability in the Google Search bar embedded on the websites’ subpage had been exploited by unknown parties in two attacks, the IDA said.”

What happened is that online visitors searching within PMO and Istana websites were redirected to view content and messages on another webpage resembling the two sites. The visitors thought that the websites had been defaced when in fact, they continued to work properly.

On Wed (13 Nov), a Google spokesperson refuted IDA’s charges:

“It has come to our attention that the PMO’s website recently experienced an attack in the search functionality of the site run by Google’s Custom Search Engine site-search widget.”

“After investigation, it appears that the code in the Google custom search engine is safe and the vulnerability lies with the coding on the webpage.”

In other words, IDA may have wrongly accused Google. Google said the vulnerability lies with how the webpages of PMO and Istana websites were coded.

Typically, when a visitor enters an input into the Google custom search engine which, in this case, was used by PMO and Istana websites, the web programmer should check and make sure that the search data is validated before proceeding to pass the data to the search engine. Apparently, this was not done for PMO and Istana websites.

In this regard, the lack of input validation allowed the vulnerability to be exploited. It has nothing to do with the Google custom search engine.

It’s not known who is doing the coding for the government websites. The job could be outsourced to programmers outside of the government.

IDA said the vulnerability has since been patched.
 
aiyoh... so got kena hack or not?
 
Really fucked type govt. Its own IT dept buay gan and yet still have the temerity to blame Google.

Thick skinned until can stop bullets. :rolleyes:
 
IDA and all its infernal foreign talents in IT support are out of its depth when swimming in the www with Google.
 
Base on track records of credibility and accountability, I trust and believe Google :D
 
Really fucked type govt. Its own IT dept buay gan and yet still have the temerity to blame Google.

Thick skinned until can stop bullets. :rolleyes:

555 I like the quote thick skin until can stop bullet.
 
compromised but not hacked. simi lanjiao statement.....

so those people kena arrested last week will be charged for "compromise" in court? are the sentences for those convicted of "compromise" the same for those convicted of "hack"?
 
IDA and all its infernal foreign talents in IT support are out of its depth when swimming in the www with Google.

There's a post somewhere on this forum that Pinky's son is currently working at Google HQ.

BTW Pinky has shares in Google, you know....
 
LOL.......if a bald headed lunatic can hack into the govt websites, need we say more?
 
aiyoh... so got kena hack or not?

Looks like the beginning of a good defence against the allegations made by the cheebye govt.....



Now onder they had to send the mama to psychiatric ward la....because he was not confessing so they got no fucking case....what betterer and fasterer way than to oppress an accused person than to prolong his detention for no justifiable reasons!!


Well done singapore police farce....what a bunch of useless statement recording fuckups you all are proving yourselves...a real traffic police force indeed........
 
PMO : Google's webpage caused the vulnerability to my site.

Google : Your fuck up programmer didn't do a good job and you didn't ensure your programmer do a good job, don't blame me if you are using 2nd rated outsource agency to create your site !

Conclusion : You are fucked by the Hacker and Google !! Double penetration !!!
 
Waiting for boy boy to sue-daddy says if you don't sue means they are right.
I say want to take legal action do it in America lah-send your precious Ah Neh and Pinoy talents as experts witness and show how good are these spurs on silliporean hides.
 
Last edited:
Back
Top