Showing posts with label server. Show all posts
Showing posts with label server. Show all posts

Wednesday, October 30, 2019

Misconfigured servers can give you a headache


The local, state and federal governments collect massive amounts of data from its citizens. There are massive data centers whose only function is to hold the data. While these secure the data, there are numerous attacks daily, ranging from the simple scans to the far more advanced. One of these states is Oklahoma, who had a notable issue. The Oklahoma Department of Securities is tasked with protecting investors.
Issue
This year a research team (The UpGuard Data Breach Research Team) detected a server, which was insecure. This occurred on December 7, 2018. The server happened to have millions of files open to the public. The server was registered to the Oklahoma Office of Management and Enterprise Services (OMES). This was however actually owned by the Oklahoma Department of Securities. The server contained 3TB and millions of files fully, openly accessible. This was open possibly since at least November 2018 through the detection date.
Data
The data was located on a rsync service that was not secured. Rsync is generally used to synchronize files across systems. A person’s data can be very sensitive and provide information to unauthorized parties the person does not want provided. The data, in this case, involved a list of persons with a specific ailment, FBI investigation details, and other PII. This also had credentials and social security numbers for over 10K brokers in one of the databases. The credentials could have been used for remote access to the Oklahoma Department of Securities workstations. The earlier records noted were from 1986.
Remediation
As noted, the server with cybersecurity issues was detected on December 7, 2018. The owner was notified on December 8, 2018. Fortunately for the person whose data was on the system, the public access was removed immediately. They are working with a forensic team in conducting an investigation. The government was very responsive and responsible for taking care of this. They did not wait for an extended period of time to act on the issue.
Lessons Learned
This is a rather unusual set of circumstances, nearly a trifecta. The issues compounded on each other. The servers were openly accessible by anyone, the data on the server was not encrypted, and it appears they had not been using TLS keys and certificates. In the very least the data at rest should have been encrypted and TLS enabled. There are basic and uncomplicated measures to ensure there are no issues. It is curious how this was configured incorrectly and passed their internal checks. Allegedly the breach occurred while a firewall was being stalled. While a good standard operating procedure, it should not have taken at least a week to implement. This issue emphasizes the need for timely work and proper configurations for systems.

Resources
Denwalt, D. (2019, January 17). Oklahoma government agency left millions of files unsecured, including sensitive data, cybersecurity team finds. Retrieved from https://www.tulsaworld.com/news/state-and-regional/oklahoma-government-agency-left-millions-of-files-unsecured-including-sensitive/

Dissent. (2019, January 16). Massive Oklahoma government data leak exposes 7 years of fbi investigations. Retrieved from https://www.databreaches.net/massive-oklahoma-government-data-leak-exposes-7-years-of-fbi-investigations/

Mikelionis, L. (2019, January 17). FBI records, emails, social security numbers exposed in massive data leak, security experts say. Retrieved from https://www.foxnews.com/tech/oklahoma-government-data-leak-exposed-fbi-investigations-emails-dating-back-17-years-social-security-numbers

O’Donnell, L. (2019, January 16). Millions of Oklahoma gov files exposed by wide-open server. Retrieved from https://threatpost.com/oklahoma-gov-data-leak/140936

Osborne, C. (2019, January 17). Oklahoma government data leak exposes fbi investigation records, millions of department files. Retrieved from https://www.zdnet.com/article/oklahoma-gov-data-leak-exposes-millions-of-department-files-fbi-investigation

The Associated Press. (2019, January 17). Firm: Oklahoma securities agency’s computer files breached. Retrieved from https://www.thestate.com/news/business/national-business/article224681545.html


Tuesday, August 27, 2019

Misconfigurations abound: This oversight affects 120 million Brazilians


For better or worse, there seem to be more instances of misconfigurations. This may be on servers, AWS, or other targets. The issues range from minor to rather significant (i.e. forgetting about application security and allowing anyone with an AWS account to log in for your instance). At this point, significant misconfigurations really should not be occurring. There are many opportunities and sources to learn from. One such oversight occurred in Brazil. This provided for a massive oversight. Brazil is known for its celebrations. Unfortunately, this country is also becoming known for cybersecurity issues.
Affected
The issue with this particular breach is a misconfigured Apache server with CPF (Cadastro de Pessaoas Fisicas) numbers for nearly 120M Brazilians being exposed. The CPF is their identification number provided by the Brazilian Federal Reserve to Brazilian citizens and taxpaying residents. This is much like the US social security numbers. This number is not optional and is required for the monetary tasks of daily life (e.g. opening a bank account, opening a business, paying taxes, getting a loan, and other functions). The length of time these were exposed is unknown. As no one is sure how long the server was misconfigured, this period could have been a lengthy period. It is notable and odd that this period of time is not able to be estimated. Seemingly there should be a record memorializing when the server was configured.  The data exposed includes the person’s name, birth date, email, phone number, address, employment details, bank account details, loans and repayment history, debit and credit history, voting history, voting registration number, and more. This is a wonderful collection for phishing and to take over someone’s identity for fraudulent uses. To top off the issue, all of this data is able to be sold quite easily on the dark web.
Misconfiguration
The issue was discovered in March 2018. The web server was misconfigured to allow public access. Within its database, the file “index.html”, a default file, was renamed to “index.html_bkp”. For someone viewing the files, this would provide for a point of attention. This caused the webserver to complete a directory listing of the files located within the file. The files ranged in size from 27MB to 82GB. While the researchers at InfoArmor were working to understand who the owner of the server was, so they could be notified, the researchers noted an 82GB file was replaced with a raw 25GB sql file. The file name stayed the same. What may have happened is the directory file was used to store a database backup, and the person creating and configuring this did not understand the files were publicly available.
Notification
The researchers were able to find the email addresses associated with the server, and naturally emailed one of these. The email bounced back with the “User Unknown” response. Two further attempts were done. Finally, the researchers received a reply stating the hosts had contacted their clients about the legal issues with leaving the data exposed. The data, however, remained exposed and wide open for several weeks after this. Later that month, the server was secured.
Thoughts
Once the point of contact for the server was notified, it is curious why this took so long to correct the issue. This required the researchers attempting contact three times and still took several weeks to correct. One question is why the data was on a third-party server. This should not have been the case. This is clearly rather significant confidential and sensitive data. It also is difficult to know who accessed the data and for how long.

Resources
Abrams, L. (2018, December 12). Taxpayer ID numbers for 120 million Brazilians exposed online. Retrieved from https://www.bleepingcomputer.com/news/security/taxpayer-id-numbers-for-230-million-brazilians-exposed-online/

Cyware. (2018, December 13). Misconfigured cloud server exposed taxpayer ID numbers of 120 million Brazilians. Retrieved from https://cyware.com/news/misconfigured-cloud-server-exposed-taxpayer-id-numbers-of-120-million-brazilians-91298892

InfoArmor. (n.d.). InfoArmor reports identification numbers of 120 million Brazilians exposed online. Retrieved from https://cdn2.hubspot.net/nubfs/3836852/PCOs/InfoArmor_Brazilian%20Exposure%20Report.pdf

Muncaster, P. (2018, December 13). Apache misconfig leaks data on 120 million Brazilians. Retrieved from https://www.infosecuritymagazine.com/news/apache-misconfig-leaks-data

S., Gurubaran. (2018). 120 million unique taxpayer ID numbers exposed online from misconfigured servers. Retrieved from https://gbhackers.com/120-million-unique-taxpayer/amp