The Joomla! Forum ™





Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Fri Mar 14, 2008 8:15 pm 
Joomla! Apprentice
Joomla! Apprentice

Joined: Thu Oct 04, 2007 6:30 am
Posts: 12
Location: Sacramento, CA USA
CNET is reporting that a Harvard prospective student database has been hacked (http://www.news.com/8301-10789_3-9893174-57.html?tag=nl.e404) with the database and site posted on BitTorrent, including social security numbers and other personal information for 6,600 students. They note that one of the SQL files posted is joomla.sql.

What do we know about this? Was this in fact a Joomla! site? Was it 1.0 or 1.5? Were they following security best practices or not? What can we learn about this to make our own sites more secure?


Top
 Profile  
 
PostPosted: Fri Mar 14, 2008 8:47 pm 
Joomla! Virtuoso
Joomla! Virtuoso

Joined: Sun Apr 16, 2006 12:20 am
Posts: 3196
Location: 127.0.0.1
Just because a database is called joomla doesn't mean it was running Joomla!. I'm not saying it does or does not.

_________________
Backup, backup, backup!
The "Master" .htacess file by Nicholas http://snipt.net/nikosdion/the-master-htaccess


Top
 Profile  
 
PostPosted: Tue Mar 25, 2008 4:03 am 
Joomla! Champion
Joomla! Champion

Joined: Wed Nov 22, 2006 3:35 pm
Posts: 6927
Location: Nebraska
As someone who works at a University with student and employee data, I will tell you, this is the kind of thing one worries about.

This was not a Joomla! vulnerability. In fact, the Joomla! website was not ever cracked or defaced, at all.

What happened was an unethical person gained access to a network administrator's userid and password. With those credentials, that person illegally logged onto the server. By server, I mean the Linux server that housed the website and other files and databases. The individual had "root level" control of the entire server.

With that access, this person copied files and folders off of a file server - those files included a file called joomla.sql that was a backup of a beautiful Graduate College of Arts and Sciences Joomla! website. These files were zipped up, along with credentials used to access the server - and the contents were floated out to the world of BitTorrent. A couple of days later, the media figured out what happened and gave these accounts.

1 - http://www.devicepedia.com/security/har ... rrent.html
2 - http://torrentfreak.com/harvard-website-hacked-080218/
3 - http://www.pcworld.com/article/id,142589/article.html

If you actually read what the GSAS said in the announcement entitled Harvard Graduate School of Arts and Sciences hacking incident states the worst case scenario of potential compromise since the creditials used provided access to all data on the entire server:
Quote:
As the investigation continued, it became apparent that some sensitive applicant data, including Social Security numbers, could potentially have been accessed.

That's the type of fear that those of us who work with personally identifiable data worry about.

I hope they catch this bastard because the damage done to these people will never end. They will have to watch their records closely from now on to see if someone tries to assume their identity and harm them financially.

Joomla!'s only relationship to this situation was the name of the database backup file that was included in the zip file on the torrent. It's unfortunate Joomla! is getting a "black eye" on this since it was not a Joomla! vulnerability. In light of the recent announcement, though, real people have been harmed and that is the real tragedy with this story.

I wish the media would read some of the articles they link to as reference material. Following this one story made me keenly aware that reporting the facts isn't always what happens.

Anyway, hope that helps.
Amy

_________________
http://Twitter.com/AmyStephen
http://www.alltogetherasawhole.org/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 



Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group