UNITED NATIONS ACCIDENTALLY EXPOSED PASSWORDS AND SENSITIVE INFORMATION TO THE WHOLE INTERNET

SOURCE: THE INTERCEPT

THE UNITED NATIONS accidentally published passwords, internal documents, and technical details about websites when it misconfigured popular project management service Trello, issue tracking app Jira, and office suite Google Docs.

The mistakes made sensitive material available online to anyone with the proper link, rather than only to specific users who should have access. Affected data included credentials for a U.N. file server, the video conferencing system at the U.N.’s language school, and a web development environment for the U.N.’s Office for the Coordination of Humanitarian Affairs. Security researcher Kushagra Pathak discovered the accidental leak and notified the U.N. about what he found a little over a month ago. As of today, much of the material appears to have been taken down.

In an online chat, Pathak said he found the sensitive information by running searches on Google. The searches, in turn, produced public Trello pages, some of which contained links to the public Google Docs and Jira pages.

Trello projects are organized into “boards” that contain lists of tasks called “cards.” Boards can be public or private. After finding one public Trello board run by the U.N., Pathak found additional public U.N. boards by using “tricks like by checking if the users of one Trello board are also active on some other boards and so on.” One U.N. Trello board contained links to an issue tracker hosted on Jira, which itself contained even more sensitive information. Pathak also discovered links to documents hosted on Google Docs and Google Drive that were configured to be accessible to anyone who knew their web addresses. Some of these documents contained passwords.

READ MORE...

SHARE THIS ARTICLE...

Views: 87

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

Comment by Boris on September 25, 2018 at 11:50am

accident ...sure

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega commented on Doc Vega's photo
Thumbnail

715995407_27066569266338656_4621890679891427521_n

"cheeki kea I was born in Los Angeles, California and I will never go back there! The Democrats have…"
1 hour ago
Doc Vega posted blog posts
1 hour ago
Sandy posted photos
1 hour ago
Doc Vega posted blog posts
yesterday
Sandy posted a photo
yesterday
Doc Vega posted photos
yesterday
cheeki kea favorited tjdavis's video
yesterday
cheeki kea commented on Doc Vega's photo
yesterday
Doc Vega posted blog posts
Friday
Doc Vega posted a photo
Wednesday
Doc Vega posted blog posts
Wednesday
Doc Vega posted a blog post

How they Planned the Destruction of America (And Nearly Succeeded)

In 2020 The Democrats went on a major offensive. Prevent Donald Trump from taking office, continue…See More
Tuesday
Doc Vega posted blog posts
May 31
Doc Vega posted a photo
May 31
Sandy posted a photo
May 31
tjdavis posted a video

It's Over. The Tool Bans Just Arrived!

First tool ban is here! A new law was just signed in New York that requires blueprint blocking technology on every CNC machine, laser cutter, lathe and 3D pr...
May 30
tjdavis posted photos
May 30
Doc Vega posted a blog post

Angry Old Man James Carville Warns of More to Come?

 A new type of signaling is brewing among the left and disenfranchised Democrats who have refused…See More
May 30
Doc Vega posted photos
May 29
Sandy posted photos
May 29

© 2026   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted