[wilhelmtux-discussion] Fwd: [gull] Diebold GEMS

Myriam Schweingruber myriam.schweingruber at wilhelmtux.ch
Wed Sep 15 11:05:05 CEST 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

FYI

Ein proprietäres e-Voting-System kann anscheinend durch eine Sicherheitslücke 
manipuliert werden. Das kann ja heiter werden...

- ----------  Message transmis  ----------

Subject: [gull] Diebold GEMS
Date: Montag, 13. September 2004 11.55
From: schaefer at alphanet.ch (Marc SCHAEFER)
To: gull at alphanet.ch

Une vulnérabilité (backdoor) dans un système de vote électronique
propriétaire:

   Diebold GEMS Central Tabulator Vote Database Integrity Compr...
   BugTraq ID: 11076
   Remote: Yes
   Date Published: Aug 31 2004
   Relevant URL: http://www.securityfocus.com/bid/11076
   Summary:
   It is reported that the GEMS Central Tabulator stores received votes
   in three segregated regions of an Access database.  The GEMs system
   harvests data from each of these database regions in order to generate
   reports.

   All of the tables in these separate database regions are linked
   together in an attempt to prevent database tampering, by ensuring that
   the table data corresponds to table data in other database regions.

   The Diebold GEMS Central Tabulator is reported prone to a
   vulnerability, where a two-digit code can be entered into a hidden
   location to de-link the tables in the GEMS database. This will permit
   an attacker to add sets of fake votes.

Plus d'information:
   http://www.conspiracyplanet.com/channel.cfm?ChannelID=31

Un HOWTO pour frauder avec ces machines:
   http://www.conspiracyplanet.com/channel.cfm?channelid=31&contentid=1510

Aucune idée de la qualité de ces informations.

_______________________________________________
gull mailing list
gull at lists.alphanet.ch
http://lists.alphanet.ch/mailman/listinfo/gull

- -------------------------------------------------------

- -- 

Wilhelm Tux - Kampagne für Freie Software in der Schweiz
Guillaume Tux - Campagne pour les Logiciels Libres en Suisse
Guglielmo Tux - Campagna per il Software Libero in Svizzera
Guglielm Tux - Campagna per programs libers in Svizra
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBR/exkvv9V4b8pZIRApSnAJ9BoZG+Y+YxTi1fkaifaKjlmiFo9QCePJEe
RRL4vueF78tWyrNuC1FyGQI=
=4ro7
-----END PGP SIGNATURE-----



More information about the wilhelmtux-discussion mailing list