Search WWW Search GoodspeedUpdate.com
MEDIA
Michigan Daily
Ann Arbor News
University Record
Michigan Radio
WCBN, WEMU

AREA BLOGS
Goodspeed Update
Arbor Blogs
Ann Arbor Is Overrated
Black at Michigan
Richard Murphy

Past the College Grounds
Sam Woll
Steven Cherry (Ypsi)
The Bunker (Ypsi)
Larry Kestenbaum
Edward Vielmetti
Chetly Zarko
Airbeagle
Andrew Vanalstyne
Neoliberal Chopping Block
Michigan MBA
Mouse Musings
Jenny Nathan
Matt Hollerbach
Bob Goodsell
Stephen Darwall

Common Sense Liberals
John Honkala: First City (Chicago)
Washington Oculus (D.C.)
Dave Enders (Baghdad)
Jim Secreto (China)
Josh Wickerham (China)
Ben King (Atlanta)
Juan Cole (Mideast)


MORE MEDIA
Moment
Consider
Michigan Review
Mich Magazine
Every Three Weekly
BusinessDirect Weekly

Detroit Free Press
Metrotimes
Detroit News
Crain's Detroit
Michigan Indymedia
Michigan Chronicle
Michigan Citizen
Local 4 - WDIV
DetNow 7 - WXYZ

MLIVE.COM
MI AP Wire - Freep
MI AP Wire - MLive

New York Times
Washington Post
Los Angeles Times
Chicago Tribune

U-M NEWS
Admin News
LSA News
ITCS News
MGoBlue.com
UMHS News
Engineering News

Michigan Today Mag
LSA Mag

CAMPUS LABOR
Borders Readers United
Graduate Employees' Organization
Lecturer's Employee Organization
American Association of University Profs.
Students Organizing for Labor and Economic Equality

WORLD
Reuters
Al Jazeera English
Times of India
The Age (AU)

BBC News
The Guardian (UK)
Times of London
The Independent (UK)

MORE BLOGS
Tom Tomorrow
Jim Hightower
Nathan Newman
Paul Schmelzer
Beyond Brilliance
Ted Rall
Aaron Hawkins
Where is Raed? (Baghdad)
Matt Drudge
Jim Romenesko

Michigan Blogs
Detroit Blog

BEAT BUSH IN '04
John Kerry
Ralph Nader

AROUND THE WEB
ZNet
ACLU, ACLU-MI
Open Secrets
The Onion
Memory Hole
Cryptome
Snopes
WhiteHouse.org
Porto Alegre
UN
Labor Start
Arts and Letters
UnderReported.com

ARCHIVES
May04
April04
March04
February04
January04
December03
November03
October03
September03
August03
July03
June03
May03
April03
March03
February03 (Feb. 18-22)
January03
December02
November02
October02
September02
August02
July02
June02
May02
April02
March02
February02
January02
December01
November01
Sept.-Oct01

ADVERTISEMENTS


NEWS

Tuesday, May 25, 2004

Wolverine Access Flaw Update

It seems that there's a bit more to the story about the recently discovered privacy flaw in Wolverine Access. The student who found the flaw is alleging that the vulnerability was accessable from any browser, his friend said "The University only emailed students because Jon contacted the Ann Arbor News." This from a a Live Journal post by the student who discovered the flaw:

"I would also be very suprised if someone else did not stumble upon, given the huge number of people that use Wolverine Access. Unfortunately, for that same reason, it is rather infeisible to maintain log files for that long of a period of time to know for sure.

While a full dump of the database would not be possible with the limited web-based forms and restriction to 300 results, it would be possible to get a large majority of the data with some complex screen-scraping and common-name techniques. Let's hope no one came across it and thought of that.

So in conclusion, there's not really anyway to know who's been affected so everyone just needs to keep a watchful eye on their credit report."


Also, although the Daily story says:
"[UM Spokesperson Julie] Peterson added that the student used the Safari web browser for Macintosh operating systems whereas most students use Internet Explorer and would not be able to gain access through Internet Explorer."

Mr. Oberheide noted in a feeback posted on the story that, "Actually I used Mozilla Firefox on Gentoo Linux. Mozilla is also available for Windows and Mac. In addition, it IS possible to access through Internet Explorer although it requires a bit more technical knowledge."

It turns out that the University claims they never told the Daily that, and in Mr. Oberheide's words, "apparently the Daily pulled that one out of their ass."

> From this Live Journal discission
> Daily: "Student reports glitch in Wolverine Access to 'U'"
> U-M Information: "Wolverine Access Student Data Vulnerability Discovered"

Posted by Rob at 2:41 PM 1 Comments

Comments:
I don't understand why the University just doesn't open up the source code for Wolverine Access, Peoplesoft be damned. It'd be a quicker, more efficient of removing the bugs and would greatly reduce the risk of problems like these creeping up in the future.

It worked for Linux, it can work for us.

Post a Comment
RECENT POSTS
> Stevens Co-Op Burns
> > "On Saturday, the Ann Arbor Wastewater Treatment...
> Daily columnist Elliott Mallen discusses the finer...
> University-driven Sprawl
> Highlights "Storm leaves power outages" "Scio Twp....
> ArborUpdate.com
> Defending Porch Couches
> I have switched the way visitors to this site can ...
> Washingtonienne update ... Washington Post: "The ...
> No Reason To Ban Porch Couches

WHAT'S HOT

Inside the Daily
U-M Earnings
Political Giving
Michigamua
BAMN
MSA
My Course

Ann Arbor Cool Cities Task Force
Our Voices Count
Anti War Action!


EVENTS

(Continue list)

Ticket Master Events: Ark, Blind Pig, Hill Auditorium, Michigan Theatre, Power Center Also see: UMS events, and Current's Lectures, Readings, and Forums

Movie Times
MUTO Events
UM Campus Events
CURRENT's Calendar Ann Arbor Observer

UMICH
Google
Daily Jolt
U-M Directory
MIRLYN
Lexis-Nexus

mail.umich.edu
ITCS Account Usage
MPrint
IFS Space

Recent Crime
Campus Information

Wolverine Access
Coursetools
(CTNG)
LSA Courseguide
Advice Online
Rate My Professor
ITCS Status (CAEN)

Construction Info
Sculptures Info
Student Policies

ONSITE
Borders Strike
Campus Shame
Planada
City Council Elections (Voting)
NAKED MILE
HASH BASH
CRIME ALERTS
BOOKS
CRITICAL FILES
PERSONAL PAGE
CAMPUS TOURS
9.11.01
GU MAINE
MICHIGAN DAILY
SURVEILLANCE
NETPD
PALESTINE CONF.
HADDAD
GANNETT PROGRAM
HOROWITZ
DAILY BOYCOTT

TEXTBOOKS
DogEars.com
Online Student Marketplace
Student Book Exchange
Cordx.com
Half.com
Shaman Drum
Union Bookstore
Michigan Book + Supply
Ulrich's

DORMS
Dining Hall Menus
TV!
Telephone
FIXIT Request

JOBS
U-M Jobs
U-M Student Employment
Career Center

A2 "PLANNING"
City Planning Dept.
Peter Allen
New Course
Ecology Center

STATEWIDE:
MI Land Use Leadership Council
MI Land Use Institute

Ann Arbor
Detroit/A2 Craigslist
A2 Local Market
MLive Town Talk
Local Sites Via GeoUrl
Ann Arbor District Library
City Government

STUDENT POLITICS

Student Orgs
MSA
RHA
LSASG
EQGA
UMEC

ACLU
ADC
AWA!
Dems
CR's
GEO
Greens
PIRGM
SOLE
SSAA
SFC
Students Allied
SFL
Zionists


NEWS ALERTS
<1 email per week
SITE INFO

Rob@ Goodspeedupdate.com

Atom XML Feed

AIM: RobGoodsp

Policies

PAY/DONATE: Paypal or Amazon


This page is powered by Blogger. Isn't yours?