Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

UK citizens' portal exposes edit kit interface

HTML undergarments of Direct.gov.uk aired in public

Published Wednesday 4th June 2008 10:49 GMT

Coding errors left the edit kit interface on the UK government's citizens' portal visible last week.

Hmmm. Excuse me but your HTML is showing

Although the interface of Direct.gov.uk was visible, a faux pas akin to exposing the site's undergarments to public view, more serious mischief wasn't possible. The interface didn't have write permissions to the website, security experts at UK-based penetration testing consultancy SecureTest confirmed.

Reg reader Phil stumbled on the page while passing time waiting for a Java update and looking at which UK health and government sites disallowed indexing by Google. "I'm not sure that's something I should be able to see. I didn't play with it much after seeing that, and wouldn't have known what to do if I had, but when a .gov.uk page says something like that, I can't help but wonder if someone who actually knows what they're doing might be able to cause some mischief," he explained.

As it happens the slip-up was minor - since it wasn't possible to post anything from the interface - but nonetheless surprising. The webmasters of Direct.gov.uk have since tucked in their undies pulled the page from public view. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

Solution Brief: Reduce Energy Costs

Energy consumption has become a big issue. Dramatically increase server utilization and significantly reduce energy costs through Virtualization..
whitepaper title

Enforce Your Email and Web Acceptable Usage Policies

Unmanaged employee use of email and the web can subject any organization to costly risks. Learn how clearly written Email and Web Acceptable Usage Policies (AUPs) can protect your business.
Whitepapers Jobs

Top 20 storiesAll The Week’s HeadlinesArchiveSearch