SGA Web site hacked

A search engine link on the Student Government Association Web site was removed Friday afternoon after VCU officials discovered it linked to pornographic Web sites.

Reuban Rodriguez, associate vice provost and dean of student affairs, said he had the links removed as soon as he was notified of the problem.

“I immediately called our Student Government President Eddie O’Leary, and he was not aware of it,” Rodriguez said.

“From a university standpoint, we try to take all the measures we can via software to not have any links or anybody insert actual pages on there,” he added. “We have policies to address behavior and people being able to use or view or download these type of things.”

O’Leary said a similar incident occurred in the past.

“The only similar thing that happened was we used to have our forums spammed by Viagra advertisements and sometimes pornographic Web site advertisements.”

O’Leary released a written statement on behalf of the SGA explaining what happened to the Web site:

“The forum area of Monroe Park Campus Student Government Association Web site http://vcusga.com/forum was compromised due to a security flaw in the forum software on the week of April 14. All the offending content was removed immediately. This security flaw has been addressed by the developers of the software, and all of their recommendations have been implemented. We are taking several additional measures to ensure that no one is able to do this again. We estimate based on our Web site statistics that approximately six or fewer users could have seen the unauthorized content. We apologize for any inconvenience this may have caused the university community.”

Though he was not sure the specifics of how this incident occurred, Mark Willis, VCU’s chief information officer, said there are two main ways something like this can happen: either someone was able to guess the administrative password or the site did not have the most up-to-date patches for the server.

“In the case of the SGA, there was a link to some pornographic material. That happens fairly frequently with corporate Web sites,” he said.

As technology becomes more widespread, though, Rodriguez said incidents such as this have become a growing problem everywhere.

“As people intentionally come up with new ways of infecting Web pages and e-mails and spamming people, that’s never going to stop being a problem to address.”

Willis said in the future incidents like this can be avoided by taking a few precautionary steps.

“The moral of the story is our administrative Web sites have to make sure they have complex passwords that aren’t easy to guess and that the security patches are up to date as they come out from Microsoft,” he said. “If you do those type of things you’re pretty well protected from this.”