Security bungle exposes 450 NZ Labor supporters

 

Backups, passwords exposed on public servers.

A furore has erupted across the Tasman after a right-wing blogger promised to release 452 names and 18,000 email addresses of New Zealand Labor Party supporters obtained through basic security failures in the party’s web site donation portal.

Blogger Cameron Slater told SC Magazine Australia today that he would release the names, addresses and donation information of the party supporters obtained through the holes “over the coming months” and said is confident he had legal authority to do so.

Slater discovered the Labor Party’s Civi Customer Relationship Management database, which operates on the open source Droopal platform, cached by Google search. With it he found unencrypted administrative passwords and backups located on public facing servers.

Worse, he said the administration passwords he obtained for the Labor Party website were also used to access the Party’s payment transaction facility, flo2cash.

Slater, a former change management head of a major bank, advised the Labor Party of the password bungle yesterday after it moved to reassure members that their financial details were safe and said it had changed the access credentials.

Labor Party President Moria Coatsworth was unavailable for comment today, but the party said the security flaws had been fixed and it had investigated the incident.

“They have left their data to be cached by Google. It doesn’t take Chinese hackers to obtain it,” Slater said.

“It was complete ineptitude. They had created backups in public directories.

“That is like putting your TV and video player out on the front lawn and wondering why it was stolen.”

Slater said despite his right wing stance, his efforts were apolitical because he “would do the same if it were the National Party”.

“It’s about bad security.”

The 452 names were collated through donations over a four-month period, and email addresses were harvested during social media campaigns used to subscribe members.

A staffer in the rival National Party had also obtained the names and email addresses but denied allegations by Coatsworth that it supplied the information to Slater.

“This is a politically motivated attack. The National Party had a choice to alert us to this vulnerability in our system. Instead they chose to exploit it and to download the material and pass the gap onto the blogger who they knew would reveal private information,” Coatsworth said in a statement.

Chris Gatford, director of penetration testing firm HackLabs told SC Magazine that “default passwords and poor configurations and failure to patch” are key elements used to compromise web sites.

Copyright © SC Magazine, Australia


Security bungle exposes 450 NZ Labor supporters
Anna Cervova, public domain
"What are you talking about BaysNet ? Cloud is the technology for the platform, not the security of the site or application presenting the site. For the NZ hack, it makes no difference cloud or ..."
By DJ
 
 
 
Comments: 2
BaysNet
Jun 16, 2011 12:40 PM
A good example of the sorts of typical "human errors" that in a Cloud computing world lead to huge security issues that are yet not well understood. Cloud Security Architecture reviews and basic penetration testing regimes are available now from your trusted security advisor. We are waiting for your call why are you waiting till after the breach?
DJ
Jun 16, 2011 3:34 PM
What are you talking about BaysNet ?

Cloud is the technology for the platform, not the security of the site or application presenting the site.

For the NZ hack, it makes no difference cloud or otherwise because the nuffies who setup the website didn't configure basic security - as the article says epic fail.

Doh.
Comments have been disabled for this article.
 
 
 
Top Stories
CommBank suppliers compete for portable workloads
Multi-sourcing deals yield $100m savings.
 
Australia turns to homegrown drones
Debating the finer points of unmanned aerial vehicle design.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  20%
 
No
  80%
TOTAL VOTES: 529

Vote