UNITED NATIONS ACCIDENTALLY EXPOSED PASSWORDS AND SENSITIVE INFORMATION TO THE WHOLE INTERNET

SOURCE: THE INTERCEPT

THE UNITED NATIONS accidentally published passwords, internal documents, and technical details about websites when it misconfigured popular project management service Trello, issue tracking app Jira, and office suite Google Docs.

The mistakes made sensitive material available online to anyone with the proper link, rather than only to specific users who should have access. Affected data included credentials for a U.N. file server, the video conferencing system at the U.N.’s language school, and a web development environment for the U.N.’s Office for the Coordination of Humanitarian Affairs. Security researcher Kushagra Pathak discovered the accidental leak and notified the U.N. about what he found a little over a month ago. As of today, much of the material appears to have been taken down.

In an online chat, Pathak said he found the sensitive information by running searches on Google. The searches, in turn, produced public Trello pages, some of which contained links to the public Google Docs and Jira pages.

Trello projects are organized into “boards” that contain lists of tasks called “cards.” Boards can be public or private. After finding one public Trello board run by the U.N., Pathak found additional public U.N. boards by using “tricks like by checking if the users of one Trello board are also active on some other boards and so on.” One U.N. Trello board contained links to an issue tracker hosted on Jira, which itself contained even more sensitive information. Pathak also discovered links to documents hosted on Google Docs and Google Drive that were configured to be accessible to anyone who knew their web addresses. Some of these documents contained passwords.

READ MORE...

SHARE THIS ARTICLE...

Views: 85

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

Comment by Boris on September 25, 2018 at 11:50am

accident ...sure

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

tjdavis posted a photo
3 hours ago
tjdavis posted a video
yesterday
Doc Vega posted blog posts
yesterday
Burbia commented on Cryptocurrency's group Video Archive
Tuesday
Doc Vega commented on Doc Vega's blog post How Many Clues Did You Need To Figure out the Covid scare was Bogus? Revisiting Stupidity
"cheeki kea you are spot on. It won't be until the elephant on Wall Street is as high as the…"
Monday
Sandy posted photos
Monday
harrisseo is now a member of 12160 Social Network
Sunday
Doc Vega's 4 blog posts were featured
Sunday
tjdavis posted a blog post
Saturday
tjdavis posted videos
Saturday
cheeki kea left a comment for Gordon Freeman
"Greetings and welcome to you Gordon it's great to have you join us all here."
Friday
cheeki kea commented on cheeki kea's photo
Friday
cheeki kea posted a photo
Friday
cheeki kea commented on Doc Vega's blog post How Many Clues Did You Need To Figure out the Covid scare was Bogus? Revisiting Stupidity
"For those trapped in mass formation the ugly truth and all the clues will not be realised until the…"
Friday
cheeki kea favorited Doc Vega's blog post How Many Clues Did You Need To Figure out the Covid scare was Bogus? Revisiting Stupidity
Friday
tjdavis posted a video

Dare to Dream/Dare to Build

As we enter the month of Av we intensify our traditional mourning for the Holy Temple, but are we really in touch with what we are mourning for? Are we ready...
Apr 1
Gordon Freeman is now a member of 12160 Social Network
Mar 31
Burbia posted a photo
Mar 31
Doc Vega commented on Doc Vega's blog post How Many Clues Did You Need To Figure out the Covid scare was Bogus? Revisiting Stupidity
"The Chinese sent more than 100 thousand visitors to the US after the failure of the Wuhan lab to…"
Mar 30
Sandy posted photos
Mar 30

© 2026   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted