blog.3bit.com


Labour’s malicious breach? No, human failure.

, posted: 13-Jun-2011 17:55

It's all over the news at the moment - political blogger Cameron Slater, aka Whaleoil, has got his hands on a whole raft of Labour files, as well as the personal details of their online donors.  In terms of a breach of data security, this is pretty much worse case scenario.

In Cameron's latest blog post, he outlines exactly how he got the data:

Quick summary of the video: using the online tool My-IP-Neighbors Cameron worked out the other sites running on the same IP address as Labour website lets-not.co.nz - one of those sites was healthyhomeshealthykiwis.org.nz, and with no index file and directory browsing switched on, it gives any visitor to it a complete file listing of every file and directory hosted on that site.  It also contained a surprising amount of files that really shouldn't be there - MySQL database dumps, personal and credit card details, plus other sensitive files.  To add insult to injury, the site has also been indexed by Google, meaning all the information on that site is now part of the Google cache.

Malicious hacking? Hardly.  Epic fail on the part of Labour's web team? You bet.

The "real life" analogy of this happening is not WhaleOil breaking into a Labour car and retrieving a briefcase of private documents and taking copies - it is more similar to Labour leaving the files spread out on the footpath, and them complaining when someone discovers and reads them.

I'm not condoning what WhaleOil does with the information; what I do want to point out is how he obtained the data is not hacking, not by any stretch of the imagination.  What has happened is the staff in charge of their websites have failed in the most basic steps to secure their websites, and it is not a design fault.  Hopefully this experience also teaches them not to store sensitive files online, especially not backups from their main website's MySQL database.  I also question why credit card details are being stored online - the industry standard is to use a third-party credit card processor who stores (if required) credit cards securely, removing this liability for your own website.

I would be asking some serious questions of the Labour staff, and how such a slipup could occur.



Other related posts:
Vodafone voicemail-to-email for free
Vodafone’s Sure Signal upgrade
How to fix “Message rejected by Google Groups”


 





Comment by Dermott Banana, on 13-Jun-2011 18:57

In 1998, in the first week of the Federal election campaign, something similar happened here in Australia.
A Labor staffer emailed his friends giving the URL for a Liberal Party website. The URL ended in "secret.html", and that was the full extent of their security.
The site had a web-form, allowing candidates (or their staff) to update their profiles on the Liberal Party's election website.
The email sent by the Labor staffer (who worked in the office of then Opposition Leader Kim Beazley) became a chain-email (as these things do) and a few generations down the line was received by some university students who used the URL to amend the details of PM John Howard, and many of his high-profile ministers.
Several generations further down the email chain, the email was received by the media, who identified the source as a junior staff member in Beazley's office, who was immediately sacked.
As happened a lot back then, and still does, the media labelled the whole incident as 'hacking' when it was nothing of the sort.


Comment by Matt, on 13-Jun-2011 21:12

Storing credit card details online? That's not PCI DSS compliant, I'd like to see them get the standard $500k per incident fine... but what's the bet that there's a loophole in there for just this scenario...


Comment by juha, on 14-Jun-2011 10:21

Slater wasn't authorised to access that data however, a simple fact that could land him in hot water. The video shows that the data access was no accident either.


Comment by eXDee, on 14-Jun-2011 18:09

I believe the site was designed by Boost New Media
See this blog post:
http://markhansen.co.nz/labour-party-leaks/


Comment by Ragnor, on 14-Jun-2011 21:06

Directory browsing turned on and backing up SQL to a folder in the web root is so epic fail.


Add a comment

Please note: comments that are inappropriate or promotional in nature will be deleted. E-mail addresses are not displayed, but you must enter a valid e-mail address to confirm your comments.

Your name:

Your e-mail:

Your webpage:

nate's profile

 
New Zealand


I'm Nate Dunn, and I work as a developer for 3Bit Solutions and a moderator here at Geekzone.






Disclaimer
The views and opinions represented in this blog are personal and belong solely to the blogger and do not represent in anyway those of 3Bit Solutions Limited or any other company.


Latest posts

Vodafone voicemail-to-email fo...
Vodafone’s Sure Signal u...
How to fix “Message reje...
GSM modems != good SMS gateway...
2,300 tweets a second...
Mobile prepay top ups with Vod...
Amazon’s Kindle to be so...
Latest and greatest from Panas...
All about GPS tracking...
Review: ICONZ Versa virtualise...

Most popular

TVNZ Ondemand now on Sony Play...
(20-Apr-2010 13:55, 11773 views)
Add more memory for free...
(1-Apr-2010 00:26, 10118 views)
Putting the BP Oil spill in pe...
(31-May-2010 06:00, 10107 views)
Why I would avoid Euro Car Ren...
(22-Mar-2010 11:03, 9657 views)
Amazing 3D from Panasonic...
(15-Mar-2010 10:00, 9574 views)
Mighty Ape heads over the ditc...
(27-Apr-2010 19:57, 9447 views)
Sky and the precioussss EPG....
(29-Mar-2010 11:00, 9139 views)
Review: Sony DSC-TX5 Cyber-sho...
(21-Jun-2010 01:07, 8929 views)
Who is deceiving – Close...
(22-Mar-2010 19:09, 8460 views)
Long suffering with Telecom...
(26-Apr-2010 09:00, 8052 views)

Comments

Craig on Vodafone voicemail-to-email for free: Just set this up with my 2degrees number and it works fantastically! Far, far ea...

Alana Fulvio on My quest to topup a Telecom T-Stick: I found your webpage about the Vodafone T-stick and couldn't help but laugh (1st...

rhysb on Vodafone voicemail-to-email for free: I did a similar thing, but using Exchange 2010 UM. Allows voice navigation and t...

anton.harper on Vodafone voicemail-to-email for free: The 028 "2Talk" voicemails are also very high quality uncompressed WAV's and are...

Adam Jobbins on Vodafone voicemail-to-email for free: Cool hack. Shame Visual voicemail doesn't work in NZ/Other than iPhone smart pho...

Steve Biddle on Vodafone voicemail-to-email for free: If you have lots of included minutes you can also just set the redirect and pay ...

Adam on Vodafone’s Sure Signal upgrade: Nice you got at upgrade, but I would be asking myself why you need one at all. I...

Kindle NZ on Amazon’s Kindle to be sold through Walmart: Does walmart sold kindle touch in new zealand?...

codyc1515 on Vodafone’s Sure Signal upgrade: So the benefit of this new one vs. the old one is that it offers a 14.4Mbps spee...

rokslide on TVNZ Ondemand now on Sony PlayStation 3: Looks like the 3.73 update changes the TV On Demand stuff around a bit. Interes...