Print 2 comment(s) - last by andrewaggb.. on Sep 26 at 2:43 PM

No public acknowledgment of the leak offered

The Institute of Electrical and Electronics Engineers (IEEE) reportedly made a massive mistake that left nearly 100,000 usernames and passwords of members of the organization exposed on a public server. A plain text list of username and password combinations was publicly available on a FTP server for over a month before being discovered. The plain text list was discovered last week by teaching assistant in the computer science department at the University of Copenhagen. 
Considering the huge number of technology experts who are members of the IEEE and who work for the organization, this is a massive and hugely embarrassing security fault. The usernames and passwords of members weren't the only pieces of information exposed on the publicly accessible FTP site. In addition, over 100 GB of Web server log files from and were publicly available because server administrators hadn't set access controls.
Those logs reportedly showed 376 million HTTP requests and 411,308 of those included both usernames and passwords. ZDNet reports that most of the compromised accounts belonged to employees at Apple, Google, IBM, Oracle, and Samsung. However, some of the user names and passwords exposed also belong to researchers from NASA, Stanford University, and other universities and organizations.
ZDNet reports that the IEEE has yet to publicly admit the data was leaked and hasn't been returning calls for comment. Teaching assistant Radu Dragusin said, "One simple and stupid mistake: public access to logs. The other, more troublesome, keeping passwords in plain text, which seems to be more on how they architect their login system." He also noted that, "While the first issue [log files] is clearly solved, I doubt the second is."

Source: ZDNet

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

RE: Revolution
By andrewaggb on 9/26/2012 2:43:35 PM , Rating: 2
meh. It sickens me that large organizations have such poor security.

"A politician stumbles over himself... Then they pick it out. They edit it. He runs the clip, and then he makes a funny face, and the whole audience has a Pavlovian response." -- Joe Scarborough on John Stewart over Jim Cramer

Copyright 2015 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki