iTnews
  • Home
  • News
  • Technology
  • Security

Security bungle exposes 450 NZ Labor supporters

By Darren Pauli
Jun 15 2011 1:21PM
Follow google news

Backups, passwords exposed on public servers.

A furore has erupted across the Tasman after a right-wing blogger promised to release 452 names and 18,000 email addresses of New Zealand Labor Party supporters obtained through basic security failures in the party’s web site donation portal.

Security bungle exposes 450 NZ Labor supporters

Blogger Cameron Slater told SC Magazine Australia today that he would release the names, addresses and donation information of the party supporters obtained through the holes “over the coming months” and said is confident he had legal authority to do so.

Slater discovered the Labor Party’s Civi Customer Relationship Management database, which operates on the open source Droopal platform, cached by Google search. With it he found unencrypted administrative passwords and backups located on public facing servers.

Worse, he said the administration passwords he obtained for the Labor Party website were also used to access the Party’s payment transaction facility, flo2cash.

Slater, a former change management head of a major bank, advised the Labor Party of the password bungle yesterday after it moved to reassure members that their financial details were safe and said it had changed the access credentials.

Labor Party President Moria Coatsworth was unavailable for comment today, but the party said the security flaws had been fixed and it had investigated the incident.

“They have left their data to be cached by Google. It doesn’t take Chinese hackers to obtain it,” Slater said.

“It was complete ineptitude. They had created backups in public directories.

“That is like putting your TV and video player out on the front lawn and wondering why it was stolen.”

Slater said despite his right wing stance, his efforts were apolitical because he “would do the same if it were the National Party”.

“It’s about bad security.”

The 452 names were collated through donations over a four-month period, and email addresses were harvested during social media campaigns used to subscribe members.

A staffer in the rival National Party had also obtained the names and email addresses but denied allegations by Coatsworth that it supplied the information to Slater.

“This is a politically motivated attack. The National Party had a choice to alert us to this vulnerability in our system. Instead they chose to exploit it and to download the material and pass the gap onto the blogger who they knew would reveal private information,” Coatsworth said in a statement.

Chris Gatford, director of penetration testing firm HackLabs told SC Magazine that “default passwords and poor configurations and failure to patch” are key elements used to compromise web sites.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
crmdata breachencryptionlabornz governmentpcidsssecurity

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

AI is delivering business value today
Partner Content AI is delivering business value today
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.