A webpage on the State of Louisianaâs official site appears to be advertising âanimal porn Porn Videos.â The online home of the Federal Judicial Center offers âfree how to sex videos,â with a closed captioning feature. The Centers for Disease Control and Preventionâs SimpleReport, identified as an âofficial website of the United States governmentâ in a banner at the top of the page, provides âDesi Girl Xxx Video sex Videos,â while the City of Bethlehem, Pennsylvania, points to âSexy Beautiful European Porn.â
These are just a few examples of the wide range of U.S. government websites inadvertently directing visitors to hardcore porn content. Other examples can readily be discovered when searching for pornographic keywords like âxxxâ and utilizing Googleâs âsite:â search operator to query only U.S. government domains.
In some cases, the content appears to violate the very laws of the governments whose sites they have taken over. Pages hosted on the State of Louisianaâs official government site that now redirect to porn, for instance, donât require visitors to provide proof-of-age verification, as is required under Louisianaâs controversial age verification law. The Supreme Court is due this week to hear a case about the constitutionality of age verification laws.
Spammers have in the past exploited the redirection functionalities of government websites to steer traffic to pornographic content â meaning the government sites themselves never actually hosted malicious content. But this recent wave of porn spam appears to be using a more complex technique: uploading to government pages rogue content that transports website visitors to malicious sites.
The new attacks work by tricking the site into attempting to load a nonexistent image. Doing so invokes whatâs called an onerror event in the HTML code, which instructs the web browser to pull up a third-party website if an image wonât load. This exploit transports users from the government page to a third-party site, which in turn redirects to yet another site hosting porn and soliciting signups with referral codes and affiliate links. If the user ultimately signs up for an account on one of these sites, the owner may receive a cash incentive.
In some instances, visitors end up on a page to purchase antivirus software from vendors such as McAfee. In response to questions from The Intercept about a specific ad redirected from a Bethlehem city government website, a McAfee spokesperson said the company would âbe taking action to remove this ad.â McAfee did not respond to a question about how much the spammer had made through the affiliate program.
The rogue webpages in some cases appear to have been uploaded to the government websites that use older versions of the Kentico content management system, which previously allowed any user to upload files to the website.
Users on forums such as BlackHatWorld, which describes itself as âthe global forum and marketplace for cutting edge digital marketing techniques and methods to help you make money in digital marketing today,â routinely advise each other to use the Kentico exploit to inject their content into websites.
Kentico disputed that such attacks point to a vulnerability in its systems, stating that its default settings allow any user to upload file and that it is up to its clientsâ website administrators to restrict upload permissions. Kentico confirmed to The Intercept that âmedia libraries are not secured by defaultâ and that the âdefault admin account has no password.â
The company pointed The Intercept to its official documentation. âBy default, files in media libraries are NOT secured,â the documentation states. âIt is up to the userâs discretion when using some feature to read the documentation. E.g. when creating a media library, secure it according given projectâs needs and goals.â
None of the impacted government responded to requests for comment; all pages flagged by The Intercept were taken offline shortly after our outreach.
WAIT! BEFORE YOU GO on about your day, ask yourself: How likely is it that the story you just read would have been produced by a different news outlet if The Intercept hadnât done it?
Consider what the world of media would look like without The Intercept. Who would hold party elites accountable to the values they proclaim to have? How many covert wars, miscarriages of justice, and dystopian technologies would remain hidden if our reporters werenât on the beat?
The kind of reporting we do is essential to democracy, but it is not easy, cheap, or profitable. The Intercept is an independent nonprofit news outlet. We donât have ads, so we depend on our members to help us hold the powerful to account. Joining is simple and doesnât need to cost a lot: You can become a sustaining member for as little as $3 or $5 a month. Thatâs all it takes to support the journalism you rely on.