United Nations Websites Besieged by Data Leaks, Exposed Files

  /     /     /  
Publicated : 23/11/2024   Category : security


United Nations Websites Besieged by Data Leaks, Exposed Files


In time for the UNs General Assembly this week, two reports find that the United Nations websites have been leaking data for months, thanks to unsecured files and applications.



The UN is getting a serious diplomatic lesson in data leakage this week.
As the 
United Nations General Assembly
 continues this week in New York City, a pair of reports from different security researchers finds that a number of the UNs websites have been leaking data for some time, thanks to exposed files and poor security practices.
The first report finds that the UN accidentally published some sensitive materials, which include passwords and technical papers, after someone misconfigured some popular, web-based applications used to manage workflow, including Trello, Jira, as well as Google Docs.
(Source:
UN
)
Kushagra Pathak, an independent security researcher, found the misconfigured files, which were available to anyone with the proper link. After first finding more than 60 of these files exposed in August, Pathak alerted officials within the UN and then shared the information with 
The Intercept
 on September 24.
As part of his research, Pathak found several Trello boards exposed to the wider Internet and through those he then found Jira tickets, as well as Google Docs, with each gradually exposing more and more sensitive information.
For example, according to The Intercept, Pathak found:

One public Trello board used by the developers of Humanitarian Response and ReliefWeb, both websites run by the U.N.s Office for the Coordination of Humanitarian Affairs, included sensitive information like internal task lists and meeting notes. One public card from the board had a PDF, marked for internal use only, that contained a map of all U.N. buildings in New York City.

Although Pathak contacted UN security officials about the exposed files and applications, a representative told him that their security team could not reproduce the vulnerability. After being contacted by The Intercept, the files were then taken down, according to the report.
Following that report, Mohamed Baset, a security researcher with 
Seekurity
, which conducts penetration testing, published a blog post detailing how he found a vulnerability in a WordPress-based UN website that exposed resumes and job applications sent to the organization.
After conducting some vulnerability testing, Baset and his team found a portal where applicants could upload their resumes if they were seeking a job with one of the organizations numerous divisions.
Regardless that the application is not enforcing HSTS [HTTP Strict Transport Security], which means the application is supporting both HTTP and HTTPS versions, an MITM attacker would get your CV file while uploading it -- the application is vulnerable to local path disclosure, according to the September 24 blog post.
Overall, Baset claims that thousands of resumes, along with personal data, could have been exposed for months. As with the other case, Baset claims that he contacted UN officials but that he didnt hear back before writing his post.
In his blog post, Baset notes that this particular vulnerability is easy to patch. He recommends that anyone running WordPress-based websites should upgrade to the latest version and use security plug-ins to harden the site.
These types of data leaks are becoming more and more common as businesses and other organizations move toward cloud infrastructure to support their IT footprint, as well as investing more in software-as-a-service (SaaS) and web-based applications. In the past month, researchers found an exposed MongoDB belonging to Veeam that exposed millions of records. The database was hosted by the company on Amazon Web Services. (See
Unsecured Veeam Database Reportedly Exposed Millions of Records
.)
Related posts:
Data Breach Can Affect Companys Long-Term Stock Price
Data Breaches Costing More C-Level Executives Their Jobs
Verizon Offers Look Inside Data Breach Investigations
Data Leaks Via Smart Light Bulbs? Believe It
— Scott Ferguson is the managing editor of Light Reading and the editor of 
Security Now
. Follow him on Twitter 
@sferguson_LR
.

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
United Nations Websites Besieged by Data Leaks, Exposed Files