We build and run sites for schools. Killer, kicking sites. Sites you'll love.
November 2006
Mo Tu We Th Fr Sa Su
  1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30  
Oct   Dec

Site structure
News Departments
Members
About us
We want to and will make it easy for schools to keep their staff, pupils, parents, partners, other stake-holders and wider community informed, updated and engaged.

Now, by merely typing in the text you can do it too!

It's so easy even 7 year old children can do it. If you are able to move a mouse, click a few buttons and string a few sentences together you can maintain a cutting edge site.

We'll give you all the training you'll need, support you on the phone or with email, all to make sure you get the best out of your investment.

Our killer features are:
Superb content management and blog software. Excellent Google optimisation.
An email to weblog interface, making updating your school blog a doddle. 
Top draw support and feedback.

Try a demo or build your

30 day free trial

school website yourself. What will you write today's school news to be?

Archive page for Thursday, 02 November 2006

 Th, Nov 2, 2006
Insecure webmail systems
I've been spamming again. Sending out emails to schools, saying how lovely we are etc., etc.. In my referers I see some of the links people have used to get here. If you've clicked a link in your email it'll show up here. Not all are terribly useful to me, sometimes I can make out domain names of schools, sometimes it's just an IP address.

However, with RM's EasyMail and DigitalBrain's webmail system, if I follow the link back I get to the log in page for your account AND see your username! The password isn't there, but it's trivial to keep hitting that page with numerous password attempts till it's cracked—it's a brute force attack. Once in I could read your email, post messages, with DigitalBrain, I'm sure I can also hack many more things, like updating your website, uploading or deleting files...

Obviously, I'm not going to do this. But, if you are with these suppliers please rise up and storm their citadels! Ask them to stop sending your username in referals. Sooner rather than later you'll be hacked and depending what you've got in your emails, you may find your back accounts drained too.
RM EasyMail usernames
RM EasyMail usernames

Digitalbrain usernames
Digitalbrain usernames


# Posted by Steve Hooker at 2/11/06; 1:14:25 PM to the Edu business dept.
Comment [0] Trackback [0]
Insecure webmail systems



You dancin?
# Posted by Steve Hooker at 2/11/06; 12:29:58 AM to the Off topic dept.
Comment [0] Trackback [0]
You dancin?