Skip to main content

Exclusive: Shoddy programming exposes personal details on Malaysians worldwide

posted onJune 15, 2005
by hitbsecnews

Several vulnerabilities have been identified on the Global Malaysians Network (www.globalmalaysians.com) allowing hackers to steal members personal details at will.

Through a casual surfing of the Global Malaysians Network (GMN) website, Hack In The Box has identified several vulnerabilities affecting the Global Malaysians Directory.

The Global Malaysian Network is an initiative by The Star Malaysia (www.thestar.com.my) to facilitate networking and to tap into the resources, knowledge, skills, investment and contacts that Malaysians can offer to other Malaysians wherever they are in the world. The directory requires members to submit their personal details including their name, marital status, postal address, contact details, professional/occupation information and even educational background details.

Due to bad programming practices and unchecked variables there are several SQL injection vulnerabilities in the web application that powers the GM Directory. By manipulating the input strings a malicious attacker could potentially compromise the security of the database server and disclose any content within the database including private and sensitive information of the Directory members.

HITB contacted GMN and The Star on Sunday 12th June 2005 via e-mail regarding the problem however it was only till a follow-up phone call was made on Tuesday 14th June that we received a reply from the Secretariat of the GMN that these issues were being looked into.

Considering the recent spate of high profile privacy breaches (Choice Point, Lexis Nexis etc) one would think that a little more care would have been excercised by the GMN developers. There's a reason why we have Software Development Life Cycles. Offering an application/service for the use of the public when it isn't ready is bad enough - However when the privacy of its members is also put at risk, someone needs to be accountable.

While the security issues with the site appear to have since been fixed (if somewhat crudely), there appears to be no notification to exsisting members regarding the problems discovered or that steps have been taken to rectify the issues to prevent them from occuring again in. We certainly hope it doesn't...

Source

Tags

Security

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th