Feeds

Hackers hijack UK.gov wiki

Environment contract party - will it have cake?

Using blade systems to cut costs and sharpen efficiencies

An attempt by a UK cabinet minister to discuss proposed environment policy using a wiki has ended in embarrassment after pranksters made merry at the expense of the Department for Environment Food and Rural Affairs' (Defra).

Tech-savvy environment secretary David Milliband was left with egg on his face after his department's draft "Environment Contract" wiki was edited to include spurious entries poking fun at the initiative.

Hours after publication of the policy, pranksters launched dozens of attacks against the wiki, hosted on Defra's official website. The heading for discussion "Who are the parties to the environmental contract?" became, "Where is the party for the environmental contract? Can I come? Will there be cake? Hooray!"

Responses to the question of "what tools can be used to deliver the environmental contract?" solicited the illuminating answer: "Spade, Organic Yoghurt Stirrer, Old washing up liquid bottle, Sticky Back Plastic."

Hackers suggested the correct tools to "create the right incentive frameworks" included a "Big stick" and an "Owl magnet".

Less light-hearted responses included criticisms of the government's use of taxes for "little tangible improvement" to citizens' quality of life. An image of a Swastika was posted in another attack. Around 170 spurious entries were reportedly made to the site.

As defacement archive Zone-h notes, the misuse of the government wiki was an accident waiting to happen.

"The reason why there were so many intrusions was in the structure of the document's page itself that used an editing technique which is very similar to the one of Wikipedia, that is, all the users with basic skills could get into the page and do whatever they wanted with the content," it reports.

After failing to stem the attacks, government sys admins purged the offending entries and temporarily disabled new entries.

Milliband said the attacks have not put him off the idea of using wikis for future policy consultation exercises.

"I gather that we have demonstrated the extreme openness of the wiki by playing host to some practical jokes plus a swastika. Strange how some people get their kicks. But the experiment will continue," he writes in an entry to his departmental weblog. ®

Boost IT visibility and business value

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.