Results 1 to 8 of 8

Thread: Reading HTML is hacking

  1. #1

    Reading HTML is hacking

    Right-click, commit a crime?
    ————————-

    The Post-Dispatch says it discovered the vulnerability in a web application that allowed the public to search teacher certifications and credentials, and that more than 100,000 SSNs were available. The Missouri state Department of Elementary and Secondary Education (DESE) reportedly removed the affected pages from its website Tuesday after being notified of the problem by the publication (before the story on the flaw was published).

    The newspaper said it found that teachers’ Social Security numbers were contained in the HTML source code of the pages involved. In other words, the information was available to anyone with a web browser who happened to also examine the site’s public code using Developer Tools or simply right-clicking on the page and viewing the source code.

    The Post-Dispatch reported that it wasn’t immediately clear how long the Social Security numbers and other sensitive information had been vulnerable on the DESE website, nor was it known if anyone had exploited the flaw.

    But in a press conference Thursday morning, Gov. Parson said he would seek to prosecute and investigate the reporter and the region’s largest newspaper for “unlawfully” accessing teacher data.

    “This administration is standing up against any and all perpetrators who attempt to steal personal information and harm Missourians,” Parson said. “It is unlawful to access encoded data and systems in order to examine other peoples’ personal information. We are coordinating state resources to respond and utilize all legal methods available. My administration has notified the Cole County prosecutor of this matter, the Missouri State Highway Patrol’s Digital Forensics Unit will also be conducting an investigation of all of those involved. This incident alone may cost Missouri taxpayers as much as $50 million.”



    https://krebsonsecurity.com/2021/10/...vulnerability/

  2. #2
    The prosecutor’s intake team when they get the criminal referral:

    Name:  25D6332A-6102-4918-9B1A-B7AAEE9C9941.jpeg
Views: 344
Size:  18.8 KB
    -All views expressed are those of the author and do not reflect those of the author's employer-

  3. #3
    I’ll bet the cybercrimes unit is *really* excited about showing off their technical expertise on this one. ;-)

  4. #4
    I don't have enough "I don't even" to "I don't even".

    Does this mean using the HTML viewer to read articles behind a paywall theft now?

  5. #5
    Sanitize your data, idiots. Never mind, they’re probably outsourced anyways.
    #RESIST

  6. #6
    Revolvers Revolvers 1911s Stephanie B's Avatar
    Join Date
    Mar 2014
    Location
    East 860 by South 413
    The real crime is making Gov. Parsons look stupid.

    (Which isn’t a difficult task.)

  7. #7
    <!--Whoops-->

    E: I'm sorry for the inappropriate comment. <!--The actual site doubtless abused Javascript and may well attempt to execute the closing tag as I first posted.//-->
    Last edited by SCCY Marshal; 10-15-2021 at 12:42 AM. Reason: Java

  8. #8
    Site Supporter
    Join Date
    Jun 2020
    Location
    Missouri
    Parsons is such a potato of a man.

User Tag List

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •