Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

How I Found Norm Coleman's Website Database in 2 Minutes

Loading...

Sign in or sign up now!
8,285
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Mar 11, 2009

Blog Link: http://tinyurl.com/colemandatabase

I was the one who found the database which was sitting right out there in a website directory. No hacking was required and the only tool I used was my Firefox web browser.

  • likes, 2 dislikes

Link to this comment:

Share to:

Uploader Comments (adriarichards)

  • Adria, it does matter that you are Democrat, because this is not a matter of people just "happening" upon the database. Most people do not snoop for IP addresses unless they are up to no good. That means that the folks who were "pinging" for an IP address, probably had the intention of trying to hack into the system. Did someone hack in and change the security levels? Hmmm, I'd love to know.

    Maliciously revealing personal information online should be a hanging offense. I've got the rope!

  • @HammerofHeretics there was no "hacking" required because the website administrator left a very important and unencrypted file in a public directory.  No snooping was required either as Norm Coleman's office brought the attention themselves by claiming their site was down due to popularity (most likely misconfiguration)!

  • Simonesdad2007,

    I am already streaming live! Every weekday at 3:30pm CST check me out on AskAdria. You can get to it from any of my websites. (sorry, can't put website addresses into comments at YouTube)

  • History is replete with examples of human error (or stupidity) compromising the most secret information.... This error (on the part of the Colemanforsenate website) adds to that long list.

    Thanks for the insight on your discovery. Looking forward to your Livestream program.

  • Yes, we must look to our past and really embrace how much time we could save by learning from mistakes others have already made.

    In IT, I think a lot of guys find it hard to admit they've made a mistake and ask for help...which can lead to a Senator's database being comprimised

  • Whoa wow. I knew you were major talent when I started watching your videos a while back. You are super awesome for all of time. LEGEND! Thanks for all the wisdom you impart.

  • Thanks Ray!

Top Comments

  • Adria,

    Good work by you! Have you ever considered streaming live on your site? You are a rising talent. I may have an affordable solution for you but I really wanted to just give you kudos.

see all

All Comments (12)

Sign In or Sign Up now to post a comment!
  • Love your work.

  • LOL! Wanna bet he went as cheap as possible on his site. You get what you pay for.

  • Leaving directory browsing enabled and not restricting access using host headers bad! Hosting the database on the front end web server?! Really bad!! Getting caught by Adria Richards and getting exposed on YouTube priceless!!!

  • wow.. that is why we have public folders and private folders.. never the twain shall meet. Coleman must have a crack webstaff. honestly that is the problem with interns. they are cheap to have around but can sometimes be a liability.

    In anycase nice work on the directory play.. You have l337 skillz... :-) Help I have been haxxored by libruls..

  • hehehehe thats really funny i wish i could see something like that in real life instead of just on a video.. seems like it would be better in person.

  • Well that's pretty much it for Norm Coleman now. If he thinks he can get anywhere in politics now, He is out of his mind!! If he appeals to higher courts after this case. He is not going to be able to raise enough money because people will not feel secure on his website. All he can really be at this point is a tool for the Republican party for keeping the Democrats from having 59 seats in the Senate.

  • Powerline is blasting out that Lefty Hackers are responsible for compromising Coleman's website and donor data.

    Be ready for attacks Adria.

    What Adria did is so simple it's scary. Dropping an IP address into a browser search bar is very basic. Opening publicly visible folders is as simple in a browser as it is on your desktop.

    Coleman's site could have set permissions to prevent exposure, takes all of 30 sec.

    If Coleman knew, indict him for this too

    Saving the Screenshots was important.

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more