The Null Device

Pen and paper scripting attack

Recently, there was an election in Sweden in which the votes were electronically counted. Write-in entries had to be hand-written, but that didn't stop wiseguys trying to pwn the election by pulling a Bobby Tables-style attack:
R;13;Hallands län;80;Halmstad;01;Halmstads västra valkrets;0904;Söndrum 4;pwn DROP TABLE VALJ;1
Or, indeed, attempting (unsuccessfully) to pwn the browsers of anyone looking at the results (thwarted by the transcriber entering the wrong type of bracket):
R;14;Västra Götalands län;80;Göteborg;03;Göteborg, Centrum;0722;Centrum, Övre Johanneberg;(Script src=http://hittepa.webs.com/x.txt);1
It's not clear whether they expected to succeed or were just aiming for a laugh from the geeks of the world.

There are 1 comments on "Pen and paper scripting attack":

Posted by: Greg Sun Oct 17 21:49:34 2010

Why don't hackers use their powers for good? Perhaps a bit of backup and maintenance.

Want to say something? Do so here.

Post pseudonymously

Display name:
URL:(optional)
To prove that you are not a bot, please enter the text in the image into the field below it.

Your Comment:

Please keep comments on topic and to the point. Inappropriate comments may be deleted.

Note that markup is stripped from comments; URLs will be automatically converted into links.