Showing posts with label web app. Show all posts
Showing posts with label web app. Show all posts

Thursday, January 24, 2019

Woesnotgone Meadow; December 17, 2018

Woesnotgone Meadow
December 17, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Generally, people in the Meadow are healthy. We enjoy the outdoors, hiking, and sitting downtown on the benches watching people walk by. At times, though, our residents may need to go to the clinic for various chronic or acute problems. At times Jerry claims Margie is trying to poison him. When we attend the doctor’s, we are required to provide a bit of private and health information. Tandigm Health had an issue with a vulnerability and their patient’s data recently.

Tandigm Health is a value-based healthcare company. Their service offers to support health plans by working with primary care physicians to provide better healthcare. The attack causing the issue involved their web application. The vulnerability allowing this was a rather serious vulnerability with one of their websites. This allowed for an unauthorized person to gain access to their system. This attack and vulnerability were open from April 24, 2017, to December 31, 2017, or over eight months.

Tandigm detected the “potential” vulnerability on September 25, 2018. They noted this was with one of their websites, and affected approximately 7k patients. The attackers could have accessed the patient’s name, date of birth, medical information, and health insurance data during the open window. On the brighter side, this did not include any patient financial or credit data.

Once Tandigm learned of the vulnerability, the management sent letters to the potentially affected patients. This was done as an abundance of caution. The company did launch an investigation. They contracted with a 3rd party for the forensic work. Their goal was to detail the nature and scope of the issue. The direct question was whether the vulnerability could enable an unauthorized person to bypass the security in place. If this were found to be the case, the next question involved what data could be accessed.

For the affected parties, the business is offering a credit monitoring service for two years. As a proactive measure, improving staff training was a significant focus. They are also reviewing their security policies.

This was a rather significant issue for a long period of time. It is curious why this took so long to detect this vulnerability.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Davis, J. (2018, November 29). Data of 7,000 tandigm health patients exposed by site vulnerability. Retrieved from https://healthitsecurity.com/news/data-of-7000-tandigm-health-patients-exposed-by-site-vulnerability

Dissent. (2018, November 23). Tandigm health notifying 7,000 patients after discovering vulnerability that might have exposed patient data in 2017. Retrieved from https://www.databreaches.net/tandigm-health-notifying-7000-patients-after-discovering-vulnerability-that-might-have-exposed-patient-data-in-2017/


Thursday, January 3, 2019

Woesnotgone Meadow; December 7, 2018

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Here in the Meadow, parking really isn’t an issue. We only have the two meters, both in front of the city hall. Generally, our residents put their dimes in the meters and we are happy. From time to time Margie walks out from her office to write out a ticket. This happens so infrequently, Margie regularly misplaces her ticket pad.

This was not the case in Ames, Iowa. Regularly, visitors and residents receive tickets for parking violations. This tends to give the people a slight headache when they see the paper, waving in the wind beckoning the driver “Hello!” The city even has the option to pay these online.

Issue
Unfortunately, there was a data breach with the online payment system for their parking tickets (Click2Gov). The city learned of the compromise on November 18th or 19th, 2018, through their IT department. Once this occurred, the city notified Click2Gov. In response, the online parking ticket payment system was taken offline. The administrative actions for the issue involved replacing the web server. This service was brought back online on November 20th. Although the service was back online, the city is still reviewing the compromise to review what the vulnerability was allowing the successful attack.

Affected Parties
There were approximately 4,600 Ames, Iowa residents who paid their parking tickets to the city online using the provided service. The other city’s residents not using this service were not affected. The potentially affected residents were mailed the written notice and emailed the same.

Data Exfiltrated
The data for the residents included their data as provided when they were using the service. This included the first name, last name, mailing address, email address, and debit/credit card numbers. If there were to be an enterprising person who just happened to have this data, it may be useful for phishing, fraudulent credit card transactions, and other exciting activities. Due to this compromise, the affected persons will need to monitor their personal credit for years and years to come.

We have the opportunity to learn from this. For this application, a simple static review would be warranted, along with monitoring more closely the SIEM.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
Associated Press. (2018, November 30). City of ames warns of parking ticket system data breach. Retrieved from https://www.washingtimes.com/news/2018/nov/30/city-of-ames-warns-of-parking-ticket-system-data-b/

City of Ames. (2018, November 30). Data breach compromises parking ticket payment system. Retrieved from https://www.cityofames.org/Home/Components/News/News/5117/

Leeson, D. (2018, December 2). Ames parking tickets data breach could have compromised 4,600 motorists payment information. Retrieved from http://www.iowastatedaily.com/news/ames-parking-ticket-data-breach-could-have-compromised-motorists-payment/

Olenick, D. (2018, December 3). Ames, Iowa, parking ticket payment system breached. Retrieved from https:/www.scmagazine.com/home/security-news/ames-iowa-parking-ticket-payment-system-breached/

Tribune Staff. (2018, November 30). Data breach found in city’s parking ticket payment system. Retrieved from https://www.amestrib.com/news/2081130/data-breach-found-in-city8217s-parking-ticket-payment-system

U.S. News. (2018, November 30). City of ames warns of parking ticket system data breach. Retrieved frm https://www.usnews.com/news/best-states/iowa/articles/2018-11-30/city-of-ames-warns-of-parking-ticket-system-data-breach