For fun I am trying to summarise the “Hacking beppegrillo.it/Rousseau” affair, based on what I know from blogs and people I follow on Twitter.
- To write a timeline of events.
- As a link reference for anyone who wants to dig deeper.
- Maybe to explain to non-experts what happened, trying to use non-technical language where possible.
Disclaimer: I have NEVER attempted a hack, nor actively looked for vulnerabilities. Everything I state I simply deduced from public information.
January 2017
I noticed that the SSL certificate (https:// access) for beppegrillo.it had been expired for 5 days.
Nobody had noticed, so nobody was using it.
Accessing a website without encryption means being exposed to an attack called MITM (Man-in-the-Middle).
For example, if someone connected to a hotel Wi-Fi types a login and password on a site without https://, anyone with access to the hotel router can see and alter that data in clear text.
If you go to http://www.beppegrillo.it/login.php, you will notice that any modern browser now flags the problem.

Claudio d’Angelis noticed that https:// access did not work at all.
https://twitter.com/daw985/status/818212208945545218
So it is certain that nobody was using it.
Then, out of curiosity, I used an online security and configuration test for protected sites, Qualys SSL Labs.
If you want to try, go here: https://www.ssllabs.com/ssltest/ and enter
https://www.beppegrillo.it
The result, in January 2017, not only showed an SSL misconfiguration (which in itself was not that serious, since it was unused), but highlighted vulnerability to an attack called POODLE.
Ok, impossible to use as an attack vector since SSL was unused. But it showed that the server had clearly not been updated at least since 2014.
Paolo Attivissimo reported to Grillo’s staff the issue I had raised:
.@beppe_grillo 1/2 Mi segnalano vulnerabilità informatiche su Beppegrillo.it, potete verificare? https://t.co/NW8RjP2W5z
— Paolo Attivissimo @ildisinformatico@mastodon.uno (@disinformatico) January 8, 2017
Also, the web server was Apache 2.2.15, very very old (2010). A bad sign.
2 August 2017, 11:40 (EIGHT months later).
Il sito Rousseau del M5S è vulnerabile, voti e dati personali degli iscritti sono tutti a rischio #Hack5Stellehttps://t.co/7KPcFsXFhe
— @evaristegal0is@mastodon.social (@evaristegal0is) August 2, 2017
Evariste Gal0is opens a website called hack5stelle, pointing out how imposing a MAXIMUM password length of 8 characters is RIDICULOUS. And he highlights a series of SQL-injection vulnerabilities. These are vulnerabilities that let you read arbitrary data from the database, including reserved data. Highly likely it is also writable.
He does not disclose any detail on how to exploit those vulnerabilities, and says he informed the site owners.
In jargon he is a White Hat — a researcher who looks for website vulnerabilities solely to help.
He has hundreds of useful reports to his name, as you can see from his OpenBugBounty profile.
Why does he do it? For passion. To help webmasters. To protect users. To learn. To get known, maybe so one day it can become a full-time job.
Does he do it for free or is someone paying him? Free. No different from the open-source software developers you all use. Remember that, thanks.
He already starts regretting it shortly after, at 23:51
Scusate ho ricevuto troppa visibilità, che non riesco a gestire e in gran parte non mi interessa. Volevo solo avvisare di una potenziale–>
— @evaristegal0is@mastodon.social (@evaristegal0is) August 2, 2017
–> perdita dati da un sito ormai molto importante. A breve eliminerò l'account. Ho lasciato il sito con la sezione FAQ.
— @evaristegal0is@mastodon.social (@evaristegal0is) August 2, 2017
3 August 2017, 18:44
Associazione Rousseau publishes on Beppe Grillo’s blog a post titled La sicurezza di Rousseau.
Notably ridiculous, they write
Sono già state messe in atto tutte le azioni necessarie per impedire il ripetersi di intrusioni informatiche come questa.
(they will be contradicted later)
and
In ogni caso il suo sito è già scomparso così come i suoi account social, segno che le contromisure contro questi reati funzionano e siamo lieti che siano state così tempestive.
(they will be contradicted later)
but above all they attack/threaten Evariste Gal0is:
Valuteremo l’azione legale da intraprendere nei confronti dell’hacker, il cui attacco è assolutamente da condannare, anziché osannare come fanno i giornali.
Threatening a White Hat is absurd, stupid, extremely serious.
Not to mention ridiculous…
In altre parole state dicendo che avete denunciato uno che ha fatto full disclosure? Il partito della rete… seh, come no. https://t.co/hTwsjxmjCE
— Stefano Zanero (@raistolo) August 4, 2017
https://twitter.com/evilsocket/status/893827654562050049
Personally I do not find it consistent to threaten a White Hat while at the same time supporting projects like WikiLeaks (what do they think those do?) or people like Julian Assange.
Brilliant the hashtag #solowikileaksvabene from David Puente.
3 August 2017, 22:40
On Twitter user @r0gue_0 claims to have had access to the server or servers for months, and starts publishing data as proof.
He is a Black Hat — “black hat”, say ‘a bad hacker’. But ‘hacker’ is a big word for this guy.
He claims and demonstrates he can write to the database, as well as read it.
He insults White Hat Evariste Gal0is, guilty in his view of drawing attention to the disastrous situation and harming his interests.
Personally I think r0gue_0 was waiting for a more favourable political moment to exploit his access.
In a later interview with Wired he will make statements such as
“Io li dentro ci stavo già, e da molto tempo. Ho dato due esempi di tabelle molto diverse solo per fare capire il lasso di tempo, come che gli host violati erano diversi. Se non era per il vostro amico wannabe, che ha voluto mettere il cappello bianco e provare a diventare famoso, non si veniva a conoscenza nemmeno della mia esistenza. Non avreste mai visto nulla, e io sarei rimasto lì indisturbato a continuare gli affari miei. Per tutto questo casino potete dunque ringraziare lui”.
I will not dwell on the type of data disclosed, the individual tweets or anything else from this bastard (pardon my French).
r0gue_0 also put all the stolen data up for sale for a little under $1000. It is unknown who or how many people bought that data.
I trust sooner or later there will be the cherry on top: someone will publish it on WikiLeaks, which M5S so much appreciates.
I refer you to David Puente’s articles for more detail on r0gue_0’s deeds:
Violato Rousseau! Hacker R0gue0 pubblica su Twitter dati prelevati dalla piattaforma del M5S
R0gue_0 e il database di Rousseau: Matteo Renzi ha donato 1 milione di euro al M5S? Ma anche no!
Non solo Rousseau, R0gue_0 ha bucato anche BeppeGrillo.it e Il Blog delle Stelle
5 August
Evariste Gal0is comes back online. He had taken a break because he did not enjoy the popularity.
He contradicts Associazione Rousseau’s post about the countermeasures:
Il sito https://t.co/7KPcFsXFhe è andato offline per le troppe visite. L'ho modificato lasciando FAQ e Conclusione, spero aiuti
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
He condemns r0gue_0’s action:
Sono dispiaciuto e condanno il gesto dell'altro idiota che ha diffuso dati personali. Non capisco il fine, e probabilmente non lo condivido.
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
He warns that the problems persist:
Forse, non entro in questi meriti, avrei optato per una comunicazione differente, solo questo. Il sito ha ancora molti errori.
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
And despite the threats he received, he continues his White Hat work:
concordo con il tuo cinismo, dopo l'articolo che hanno scritto sul blog non volevo più inviargli nulla. Però poi non ho pensato fosse –>
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
–> corretto verso gli utenti, e ho deciso di segnalare comunque. Il problema rimane, io ho messo una minipezza.
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
To me he replied:
spero vivamente che non procedano per vie legali 🙂 insomma gli sto ancora segnalando le variabili vuln, sarebbe sciocco
— @evaristegal0is@mastodon.social (@evaristegal0is) August 5, 2017
Admirable.
6 August 2017
Di Maio declares:
Il problema non siamo noi ma la sicurezza informatica di questo Paese
.
Glorious waffle.
According to M5S MP Luigi Di Maio, the issue is not their own platform being vulnerable to SQL injection, but "the country's cybersecurity". https://t.co/YXThJpn6g8
— Stefano Zanero (@raistolo) August 6, 2017
https://twitter.com/evilsocket/status/894309046144126976
7 August 2017
Matteo Flora summarises the affair with a YouTube video:
Attacco a #Rousseau del Movimento 5 Stelle: tutto quello che dovete sapere
8 August 2017, 12:14
Evariste Gal0is and Antonio Sanso publish a new analysis: #Hack5Stelle – Parte 1: dump e le password.
They discover the installed software is an obsolete version of Movable Type, version 4.2.
There are databases listing software vulnerabilities, for example the CVEs.
Normally, when a new vulnerability is found, it is reported to the software author, who can fix it. After some time (generally a few months), it is made public (disclosure), sometimes with detailed instructions on how to exploit it.
Disclosing the version of software in use, especially if obsolete, is equivalent to saying my weak spot is here; if you hit me — moreover like this — you hurt me.
They also discover that passwords, where not stored in clear text, are easily crackable because of an algorithm from computing prehistory: DES / Crypt.
It is highly likely Associazione Rousseau installed Movable Type many years ago,
adapted it to their needs effectively creating a fork, and now cannot update it without redoing all the customisations.
A typical mistake of incompetent webmasters.
8 August 2017
Paolo Attivissimo touches on the affair: Due parole sulle vulnerabilità di Rousseau
8 August 2017
Evariste Gal0is gives an interview to David Puente: Intervista a Evariste Gal0is: non era un attacco politico e non sono R0gue_0. Segnalate falle anche nel nuovo Rousseau
He writes a final article: #Hack5Stelle – Parte 2: fix che non lo erano..
It is clear that Associazione Rousseau’s technical team cannot even properly fix the reported problems.
They do not know how to fix them, so they improvised trying to plug the holes with no know-how on the subject. Failing, of course.
Nope — turning to an expert does not seem to be considered a priority.
Evariste Gal0is declares he no longer wants to deal with the affair:
2/ Penso di aver fatto abbastanza, in maniera corretta. E ora cercherò di tornare a dedicarmi alle mie segnalazioni su @openbugbounty
— @evaristegal0is@mastodon.social (@evaristegal0is) August 8, 2017
(and he is right to, imho).
11 August
I read on David Puente’s blog the article Cosa devono risolvere e rimuovere da Beppegrillo.it per la loro sicurezza noting they left a file called mt-check.cgi.
It works like this: to install the CMS (Content Management System), i.e. the website’s ‘engine’ software, they placed a file whose ONLY purpose is to check whether the server can host the software.
Not by chance the page ends with “You’re ready to go! … Continue with the installation instructions.”.
Any webmaster knows that kind of file MUST be deleted after installation.
Because it contains details on how the server is configured and the software versions it has, in real time.
It serves no other purpose. Time required to fix the problem: one second — delete that file.
As explained earlier, those are the details you need to correlate searches in known-vulnerability databases (CVEs first and foremost).
In the same post, David Puente also notes that the password is sent in clear text by email during recovery (very bad!), further confirming they use obsolete software.
15 August 2017, 09:50
Associazione Rousseau publishes on Beppe Grillo’s blog a post titled I sicari informatici non fermeranno il MoVimento 5 Stelle.
They condemn R0gue_0’s actions. Agreed.
They confirm that
Purtroppo non sono stati colti in flagrante
and that therefore R0gue_0 has had server access for an indeterminate time. I remind you he had write power in the DB.
Notably ridiculous:
I dati che sono stati divulgati dall’hacker si sono dimostrati comunque privi di fondamento
No. They were real, confirmed personal data.
and of course again a
In questo momento stiamo prendendo tutte le misure necessarie affinché non si ripetano situazioni del genere e siamo al lavoro anche in questo giorno di festa.
Now, 15 August 2017 at 21:50, as I write this post
The server is still vulnerable to the POODLE attack (2014) and still runs Apache/2.2.15 (2010). Snapshot on archive.is Realtime test
The mt-check.cgi file is still there. Snapshot on archive.is
Personally, correlating versions and CVE reports, I think I have identified a remote-code-execution vulnerability.
That means in my view there is a vulnerability that lets anyone who exploits it read and write any data on the server, run any command, and install a backdoor — i.e. a secret secondary access that will stay active even if the server is later fixed.
Should I verify it and then report it? Associazione Rousseau has declared they do not appreciate that.
Besides, it resolves automatically by fixing another problem already mentioned in this article, so they just need to turn to someone competent sooner or later.
I deliberately leave out any legal consideration of Associazione Rousseau’s conduct; I do not understand enough of that to allow myself an opinion.
I have read that the Privacy Authority has opened an investigation.
I hope I have not forgotten any important fact; otherwise please tell me via Twitter, thanks.
Update 16 August 2017
They finally removed the mt-check.cgi file. They have not grasped at all what they got wrong, because the problem persists in other similar files.