»  Welcome   »  Projects   »  Government

Government

Madison Gurkha performs high profile projects for large organizations (quoted on the stock exchange). On this page you will find some examples of projects for governments. References can be provided in the final stages of the decision making process of hiring Madison Gurkha.

National governmental organization

Project: Crystal Box application audit with code inspection.
Technology: Web application with Java (server side)

This governmental organization contracted a company to create a web application for them, which can be used to access and add data to a national register. Because this register contains classified information, IT security should play a big part in the creation of this web application. When it came to IT security, the company that was assigned to create the application did not put enough effort into it.

Essential security measures that should have been taken were not present in many areas of the application. Input and output validation was not implemented. This gave us the possibility to perform SQL-injection in several ways, which made us able to gain unauthorized and unauthenticated access to the data, including changing, adding or deleting data.

Because the source code was available, we could clearly determine that this application was not written with a security mindset. Luckily, this audit took place before the application was put to use.

Waterworks

Project: Black Box Security Audit Laptops
Technology: Laptop

This organization used laptops for the operator service desk to log on to systems from which so called SCADA systems can be operated and monitored. The company wanted to know what risks would occur if one of the laptops got stolen or lost. To find the answer to that question, Madison Gurkha was given a standard laptop used at the operator service desk. This laptop seemed well secured but after taking out the hard drive, a fundamental weakness was exposed. The hard disk was not encrypted, which allowed us to break in and crack user and administrator passwords to log on to the network. The network then gave access to many more systems than necessary. This experience shows how important it is to use encryption (especially on mobile devices).

Communal service

Project: Black Box Audit Internal network
Technology: Windows, Linux, Unix, Routers, Firewalls

This service of a large city wanted us to test the vulnerabilities of their internal network. Networks like this are usually highly vulnerable and this network was no exception. The network was suffering from easy to crack passwords, un-patched systems, absent authentication measures and intrusion detection systems. Combine these findings with the fact that this is an open type of organization where everyone can walk in and out and can gain access to the network without much effort, and you are exposed to unexceptionally high risks.

Ministry

Project: Forensic research Website hacking
Technology: web application

This ministry uses an ASP web application. This web application seemed to be hacked with all the consequences that come with it. The ministry immediately contacted Madison Gurkha. Later that day we did our first research on how and from where the attack was performed. Based on our findings further (legal) actions were taken, and the problems we discovered were solved. This case clearly shows that outsourcing a web application through an ASP model will not solve your IT security risks.



Latest news

27 july 2010
Hans Van de Looy contributes to an article in Webwereld about the safety of Internetbanking

18 june 2010
Madison Gurkha Update 8

14 may 2010
Eth0:2010 summer- Sponsorship

03 may 2010
Dutch hacker in cel, domain confiscated

19 march 2010
Madison Gurkha Update 7

29 january 2010
Hans van de Looy in Automatiserings Gids about computer hacking

Agenda

2010-07-29
DEFCON18, July 29th - August 1st, 2010, Las Vegas, USA

2010-08-10
Eth0:2010 Summer, August 10-13, Wieringerwerf, NL

2010-09-24
BruCON 2010, September 24 and 25, 2010, Brussel, Belgium

2010-10-27
Hack.lu 2010, October 27-29, Luxembourg, NL

2010-11-03
Infosecurity, November 3rd and 4th 2010, Utrecht, Nederland

2010-11-11
NLUUG autumn conference 2010, November 11th 2010, Ede, NL

Job openings

There are no job openings

Newsletter

Madison Gurkha Update 8
Madison Gurkha Update 7
Madison Gurkha Update 6
Madison Gurkha Update 5
Madison Gurkha Update 4
Madison Gurkha Update 3
Madison Gurkha Update 2
Madison Gurkha Update 1