UNITED NATIONS ACCIDENTALLY EXPOSED PASSWORDS AND SENSITIVE INFORMATION TO THE WHOLE INTERNET

SOURCE: THE INTERCEPT

THE UNITED NATIONS accidentally published passwords, internal documents, and technical details about websites when it misconfigured popular project management service Trello, issue tracking app Jira, and office suite Google Docs.

The mistakes made sensitive material available online to anyone with the proper link, rather than only to specific users who should have access. Affected data included credentials for a U.N. file server, the video conferencing system at the U.N.’s language school, and a web development environment for the U.N.’s Office for the Coordination of Humanitarian Affairs. Security researcher Kushagra Pathak discovered the accidental leak and notified the U.N. about what he found a little over a month ago. As of today, much of the material appears to have been taken down.

In an online chat, Pathak said he found the sensitive information by running searches on Google. The searches, in turn, produced public Trello pages, some of which contained links to the public Google Docs and Jira pages.

Trello projects are organized into “boards” that contain lists of tasks called “cards.” Boards can be public or private. After finding one public Trello board run by the U.N., Pathak found additional public U.N. boards by using “tricks like by checking if the users of one Trello board are also active on some other boards and so on.” One U.N. Trello board contained links to an issue tracker hosted on Jira, which itself contained even more sensitive information. Pathak also discovered links to documents hosted on Google Docs and Google Drive that were configured to be accessible to anyone who knew their web addresses. Some of these documents contained passwords.

READ MORE...

SHARE THIS ARTICLE...

Views: 83

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

Comment by Boris on September 25, 2018 at 11:50am

accident ...sure

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

tjdavis favorited Burbia's video
14 hours ago
tjdavis posted videos
14 hours ago
rlionhearted_3 commented on Sandy's photo
Tuesday
cheeki kea posted a photo
Tuesday
cheeki kea favorited tjdavis's blog post Propaganda,Cognitive Warfare Europes Self Destruction
Tuesday
cheeki kea commented on tjdavis's photo
Thumbnail

Sustenance

"Bacon health to the nation for one and all and stealth for operations elsewhere in the war. Yip a…"
Tuesday
Doc Vega posted a blog post

The Consequence of Loneliness: Another Missing Person Case

Chapter I“Unit 7, Unit 7. Do you read? This is dispatch!”“This is Unit 7, over!” Deputy Patterson…See More
Monday
Cora is now a member of 12160 Social Network
Monday
tjdavis's 3 blog posts were featured
Monday
Doc Vega's 6 blog posts were featured
Monday
Sandy posted a photo
Sunday
Doc Vega posted blog posts
Sunday
tjdavis posted a video

Devo - Fresh

"Fresh" is from Devo's 2010 album, Something For Everybody. Video producer – Brian Carr/David VotteroVideo director – Gerald Casale & Davy Forcehttps://www.C...
Sunday
Doc Vega commented on tjdavis's blog post Drones Used In Gaza Surveilling US Cities
"Remember that song by Alan Parsons "Eye in the Sky"?"
Saturday
Snakedaddy favorited tjdavis's video
Saturday
Doc Vega posted a blog post
Nov 7
tjdavis posted blog posts
Nov 7
Cora favorited Doc Vega's blog post They Won’t Stop
Nov 6
Cora favorited Doc Vega's blog post They Won’t Stop
Nov 6
Sandy commented on tjdavis's blog post Drones Used In Gaza Surveilling US Cities
Nov 5

© 2025   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted