Showing posts with label misconfiguration. Show all posts
Showing posts with label misconfiguration. Show all posts

Friday, January 17, 2020

Yet another lesson for misconfiguring cybersecurity in servers



When a person donates blood, the donation center collects data from the people. This is recorded and retained. This is done throughout the planet. Singapore likewise is involved with this process. Early in 2019, blood donor’s data, located in a database, was breached. While this was broadcast across the globe within the first few weeks after, most people read the headline and the high-level summary, and may not have dug into the details.
Vulnerability
The attack used was not excessively complex. There was an unsecured database that was available. Also, given the circumstances, this also was not likely encrypted. The database was located on an internet-facing server. The clearly incorrectly configured, openly accessible server information was leaked on the internet for two months prior to this being reported. The data was exposed for nine weeks beginning January 4, 2019, as reported by the Health Sciences Authority (HSA). The HAS provided the data to the 3rd party organization, SecurSolutions Group, to update the database. This prominent issue was detected by a cybersecurity subject matter expert (SME).

The SME contacted Singapore’s Personal Data Protection Commission (PDPC) on March 13th. The HSA, once alerted to the issue, worked with SecurSolutions Group to disable access to the account. The HAS is working with the SME to delete the data. As a coincidence, the cybersecurity researcher was based outside of Singapore. One report stated it appeared there was no unauthorized access during the subject period to the database, while another stated the data was access by an unauthorized party and possibly exfiltrated.
Affected
There were 808,201 blood donors who were affected by this negligent act. This exceptionally large number represented the blood donors since 1986, or to put this in perspective, the blood donors over the last 30+ years. The data possibly/probably accessed and exfiltrated included the names, NRIC, gender, number of blood donations, dates of the last three blood donations, and may have included the blood type, height, and weight. The odd coincidence with this instance was this was not the first time SSG (SecurSolutions Group Pte Lt.) noted its servers had been accessed by other unknown IP addresses.  
Lessons Learned
This issue brings up so many areas of concern.
a)      The data on the internet-facing server. In general, they should have thought twice about this. While this occurs all the time across the globe, there are inherent issues, especially when this is not configured correctly. As this was the case, the data was not secured. There was nothing present to prevent any unauthorized access, as this was openly accessible.
b)      You need to know the scope. The third-party contactor posted the data on the server. This was done without HAS’s knowledge or approval. In a review of the contract, this was not allowed. As with any agreement, the parties need to read the contract to know the scope of the project, and what may and may not be done.
c)       SCM. The supply chain management is still not fully addressed as a part of cybersecurity. When data is entrusted to a third party, they really should be vetted well before the contract’s execution. Without properly addressing cybersecurity in the supply chain, the business is allowing for a massive mountain of problems. SSG clearly breached its contractual agreement. This is especially notable since the service provider’s (SSG) had been accessed by unknown IP addresses since late 2018. This was also not the first occurrence of an attack. In 2017, the same server was attacked. With the same server being targeted, was the 2017 excursion used in the recon process, instead of a one-time attack? Overall, the business needs to ask or require a 3rd party to assess your vendor’s security posture.
d)      The database was not encrypted. Seemingly, if you are going to have this off-premises, and accessible you might want to have some form of encryption on the data. If this database contained data not attributable to the persons and was a generic aggregation, that’s one case. This had confidential data for persons directly attributable to them.
In closing…
This certainly was not the first error in judgment and most certainly won’t be the last time this happens in the industry. These instances keep occurring across the globe. Somehow we need to publish not only the error but also the remediation methods so others do not keep perpetuating the idiocracy. Please pass this along. After a configuration, the admin should check the configuration to make sure it is within the industry’s norms and guidelines. If it is not, the subject hardware should be reconfigured and retested. This isn’t quantum mechanics. Let stop the cycle of stupidity.

Resources
CAN. (2019, March 30). Blood donor data leak: HAS’s vendor says information that went online was accessed illegally and possibly extracted. Retrieved from https://www.channelnewsasia.com/news/singapore/personal-data-of-800-000-blood-donors-accessed-illegally-hsa-ssg-11395364
Choo, F. (2019, March 16). 800,000 blood donors’ data put online by HAS vendor. Retrieved from https://www.straitstimes.com/singapore/health/800000-blood-donors-data-pmt-online-by-hsa-vendor
Gatlan, S. (2019, March 15). Insecure database exposes 800,000 singapore blood donors. Retrieved from https://www.bleepingcomputer.com/news/security/insecure-database-exposes-800-000singapore-blood-donors/
Johnston, M. (2019, March 18). Personal data of 800,000 blood donors exposed in singapore. Retrieved from https://sg.channelasia.tech/artricle/6518921/personal-dta-800-000-blood-donors-exposed-singapore/
Paganini, P. (2019, March 16). Secur solutions group data leak exposes 800,000 singapore blood donors. Retrieved form https://securityaffairs.co/wordpress/82452/data-breach/secur-solutions-group-data-leak.html
Siew, A. (2019, March 19). More than 800,000 blood donors had personal data exposed, in latest leak in singapore. Retrieved from https://www.techgoondu.com/2019/03/19/more-than-800000-blood-donors-had-personal-data-exposed-in-latest-leak-in-singapore/





Friday, September 13, 2019

Yet another AWS issue! Capital One breached


Capital One-Yet Another Breach
Charles Parker, II
#
There is a saying that we are our own worst enemy. While we may have the best intentions, at times we may create our own issues which act to our own detriment. This has been notable with a single-use case. The focal point has been with AWS and misconfigured servers. This has created so many issues for the data owners and managers. The latest victim is Capital One due to its misconfigured AWS. This certainly won’t be the last incident through the industry.
Breach
To note this was massive would be an understatement. This is one of the biggest data breaches involving a financial services company. There were 106M persons involved. The affected persons were not only in the US, however, were also located in Canada. The breach was open for an extended period of time, from March 19 through July 17, 2018.
Method
The focal point for the attack was the cloud servers rented from AWS. There was an issue with the cloud configuration. The attack was exceptionally successful due to a misconfigured WedApp firewall. The attackers used a special command to extract the files in the Capital One AWS. Oddly, on June 16, 2019, the attacker posted on Twitter exactly how it was done. This was a very odd event. Generally, if you are going to gain unauthorized entry, you don’t want everyone to know exactly who you are. In this case, the attacker did just this.
Data
The data was related to credit card applications filed between 2005 and early 2019. This is a rather large set of time to exfiltrate data for. The attacker accessed credit applications, social security numbers (approximately 40k in the US and 1M Canada social insurance numbers), bank account numbers (approximately 80k), names, addresses, dates of birth, and financial information (e.g. self-reported credit scores). Fortunately, no credit card account numbers or logins were exposed in the breach. Altogether, the total amount of data was approximately 30GB. Somehow, the attacker was able to exfiltrate this data over months, without anyone or an app examining the login or data access for an extended period.
Perpetrator
The FBI has arrested a person in this case. The speedy arrest was greatly due to the attacker letting everyone know who they are, and not trying to hide anything. The attacker previously worked as an Amazon Web services (AWS) engineer. The attacker’s name of record is Paige A. Thompson. Given her lack of intuitiveness, she is certainly a nominee for the Darwin Award. She bragged about the breach and crime on GitHub and social media. She tried to share the data online and not on the DarkWeb. To top off the award nomination, she used her full first, middle, and last name. She also stored the data in a GitHub account for the user “Netcrave”. The GitHub site also happened to have Paige’s resume (oops). She also used the alias “erratic”.

The criminal complaint was filed in the Western District of Washington. The hearing was on August 1, 2019. To further support the allegation with yet more evidence, the FBI executed a search warrant and seized electronic storage devices. The storage devices contained a copy of the data.
Mitigation
The AWS configuration has been corrected. They stated it was not likely the data was used fraudulently. It is very easy to state this, but exceptionally difficult to guaranty. They did promise to provide 12 months of credit monitoring for affected parties. They also are recommending for the affected parties to watch for phishing emails.

Resources
Corcoran, J. (2019, July 30). Former AWS engineer arrested as capital one admits massive data breach. Retrieved from https://threatpost.com/aws-arrest-data-breach-capital-one/146758/

Krebs, B. (2019, July 19). Capital one data theft impacts 106M people. Retrieved from https://krebsonsecurity.com/2019/07/capital-one-data-theft-impacts-106m-people/

McLean, R. (2019, July 30). A hacker gained access to 100 million capital one credit card applications and accounts. Retrieved from https://www.cnn.com/2019/07/29/business/capital-one-data-breach/index.html

U.S. Attorney’s Office. (2019, July 29). Seattle tech worker arrested for data theft involving large financial services company. Retrieved from https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arrested-data-theft-involving-large-financial-services-company

Tuesday, September 10, 2019

Elsevier Pwned!

When academics and students are writing papers, research is required. At times this research can be massive, depending on the subject. The more technical the more references may be used. These act as support for the researcher’s thoughts, ideas, applications, and work in general. For these references to be useful, they have to be from peer-reviewed journals. These peer-reviewed works indicate the work is not a sole person’s opinion but is accepted by the researcher’s peers. These journals provide the resource which has been analyzed and reviewed by other professions. This removes the opportunity for biased research and research-based on faulty methods. These articles are searchable through various sources. One of these respected tools used for the search is Elsevier.
Issue
As this service has been in use for an extended period of time, there should not have been a problem. Unfortunately, due to human error or other problems, one of their servers was left open to the public to peruse through. This server happened to hold the user email addresses and passwords. Yes, this is as bad as it sounds. The users included anyone having access, including those from universities and other educational institutions across the globe. Elsevier was not aware of how long this condition was in effect. They also did not know how many users or accounts were impacted. These aspects are odd, as the servers were under their control and someone should be able to figure out through a simple review of these numbers.

The problem at hand is with credential stuffing. The affected user may use the same email account and password for other services from other providers (e.g. same email and/or password for Panera Bread, Amazon, the interface to your vehicle). This could prove to make someone’s day very interesting.
Remediation
Once Elsevier was notified of this, as they did not discover the issue, the organization did correct the issue with the configuration. They are investigating what occurred for this to vulnerable. This does however simply appear to be human error. They did not believe the server or any data had been inappropriately used. The organization did notify the users and reset their accounts.

This shows the importance, again of proper configurations. Without this in place, the servers are open to anyone, which is not a good thing.

Resources

Beau HD. (2019, March 18). Education and science giant Elsevier left users’ passwords exposed online. Retrieved from https://it.slashdot.org/story/19/03/18/2052211/education-and-science-giant-elsevier-left-users-passwords-exposed-online

Brown University. (n.d.). Password leak at Elsevier. Retrieved from https://it.brown.edu/alerts/read/password-leak-elsevier
Cox, J. (2019, March 18). Education and science giant Elsevier left users’ passwords exposed online. Retrieved from https://motherboard.vice.com/en_us/article/vbw8b9/elsevier-user-passwords-exposed-online

Drexel Library. (2019, March 21). Notice: Elsevier usernames & passwords accidentally exposed. Retrieved from https://www.library.drexel.edu/news-and-events/news/libraries-news/2019/March/Elsevier_Usernames/

Hashim, A. (2019, March 25). Elsevier exposed user credentials publicly through misconfigured server. Retrieved from https://latesthackingnews.com/2019/03/25/elsevier-exposed-user-credentials-publicly-through-misconfigured-server/

Stalfort, H. (2019, March 29). Notice: Elsevier data leak-action required. Retrieved from https://blogs.library.jhu.edu/2019/03/notice-elsevier-data-leak-action-required/

Vaas, L. (2019, March 20). Elsevier exposes users’ emails and passwords online. Retrieved from https://nakedsecurity.sophos.com/2019/03/20/elsevier-exposes-users-emails-and-passwords-online/

Tuesday, August 27, 2019

Misconfigurations abound: This oversight affects 120 million Brazilians


For better or worse, there seem to be more instances of misconfigurations. This may be on servers, AWS, or other targets. The issues range from minor to rather significant (i.e. forgetting about application security and allowing anyone with an AWS account to log in for your instance). At this point, significant misconfigurations really should not be occurring. There are many opportunities and sources to learn from. One such oversight occurred in Brazil. This provided for a massive oversight. Brazil is known for its celebrations. Unfortunately, this country is also becoming known for cybersecurity issues.
Affected
The issue with this particular breach is a misconfigured Apache server with CPF (Cadastro de Pessaoas Fisicas) numbers for nearly 120M Brazilians being exposed. The CPF is their identification number provided by the Brazilian Federal Reserve to Brazilian citizens and taxpaying residents. This is much like the US social security numbers. This number is not optional and is required for the monetary tasks of daily life (e.g. opening a bank account, opening a business, paying taxes, getting a loan, and other functions). The length of time these were exposed is unknown. As no one is sure how long the server was misconfigured, this period could have been a lengthy period. It is notable and odd that this period of time is not able to be estimated. Seemingly there should be a record memorializing when the server was configured.  The data exposed includes the person’s name, birth date, email, phone number, address, employment details, bank account details, loans and repayment history, debit and credit history, voting history, voting registration number, and more. This is a wonderful collection for phishing and to take over someone’s identity for fraudulent uses. To top off the issue, all of this data is able to be sold quite easily on the dark web.
Misconfiguration
The issue was discovered in March 2018. The web server was misconfigured to allow public access. Within its database, the file “index.html”, a default file, was renamed to “index.html_bkp”. For someone viewing the files, this would provide for a point of attention. This caused the webserver to complete a directory listing of the files located within the file. The files ranged in size from 27MB to 82GB. While the researchers at InfoArmor were working to understand who the owner of the server was, so they could be notified, the researchers noted an 82GB file was replaced with a raw 25GB sql file. The file name stayed the same. What may have happened is the directory file was used to store a database backup, and the person creating and configuring this did not understand the files were publicly available.
Notification
The researchers were able to find the email addresses associated with the server, and naturally emailed one of these. The email bounced back with the “User Unknown” response. Two further attempts were done. Finally, the researchers received a reply stating the hosts had contacted their clients about the legal issues with leaving the data exposed. The data, however, remained exposed and wide open for several weeks after this. Later that month, the server was secured.
Thoughts
Once the point of contact for the server was notified, it is curious why this took so long to correct the issue. This required the researchers attempting contact three times and still took several weeks to correct. One question is why the data was on a third-party server. This should not have been the case. This is clearly rather significant confidential and sensitive data. It also is difficult to know who accessed the data and for how long.

Resources
Abrams, L. (2018, December 12). Taxpayer ID numbers for 120 million Brazilians exposed online. Retrieved from https://www.bleepingcomputer.com/news/security/taxpayer-id-numbers-for-230-million-brazilians-exposed-online/

Cyware. (2018, December 13). Misconfigured cloud server exposed taxpayer ID numbers of 120 million Brazilians. Retrieved from https://cyware.com/news/misconfigured-cloud-server-exposed-taxpayer-id-numbers-of-120-million-brazilians-91298892

InfoArmor. (n.d.). InfoArmor reports identification numbers of 120 million Brazilians exposed online. Retrieved from https://cdn2.hubspot.net/nubfs/3836852/PCOs/InfoArmor_Brazilian%20Exposure%20Report.pdf

Muncaster, P. (2018, December 13). Apache misconfig leaks data on 120 million Brazilians. Retrieved from https://www.infosecuritymagazine.com/news/apache-misconfig-leaks-data

S., Gurubaran. (2018). 120 million unique taxpayer ID numbers exposed online from misconfigured servers. Retrieved from https://gbhackers.com/120-million-unique-taxpayer/amp