UNITED NATIONS ACCIDENTALLY EXPOSED PASSWORDS AND SENSITIVE INFORMATION TO THE WHOLE INTERNET

SOURCE: THE INTERCEPT

THE UNITED NATIONS accidentally published passwords, internal documents, and technical details about websites when it misconfigured popular project management service Trello, issue tracking app Jira, and office suite Google Docs.

The mistakes made sensitive material available online to anyone with the proper link, rather than only to specific users who should have access. Affected data included credentials for a U.N. file server, the video conferencing system at the U.N.’s language school, and a web development environment for the U.N.’s Office for the Coordination of Humanitarian Affairs. Security researcher Kushagra Pathak discovered the accidental leak and notified the U.N. about what he found a little over a month ago. As of today, much of the material appears to have been taken down.

In an online chat, Pathak said he found the sensitive information by running searches on Google. The searches, in turn, produced public Trello pages, some of which contained links to the public Google Docs and Jira pages.

Trello projects are organized into “boards” that contain lists of tasks called “cards.” Boards can be public or private. After finding one public Trello board run by the U.N., Pathak found additional public U.N. boards by using “tricks like by checking if the users of one Trello board are also active on some other boards and so on.” One U.N. Trello board contained links to an issue tracker hosted on Jira, which itself contained even more sensitive information. Pathak also discovered links to documents hosted on Google Docs and Google Drive that were configured to be accessible to anyone who knew their web addresses. Some of these documents contained passwords.

READ MORE...

SHARE THIS ARTICLE...

Views: 87

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

Comment by Boris on September 25, 2018 at 11:50am

accident ...sure

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega posted blog posts
1 hour ago
Sandy posted a photo
1 hour ago
Doc Vega posted photos
2 hours ago
cheeki kea favorited tjdavis's video
5 hours ago
cheeki kea commented on Doc Vega's photo
6 hours ago
Doc Vega posted blog posts
yesterday
Doc Vega posted a photo
Wednesday
Doc Vega posted blog posts
Wednesday
Doc Vega posted a blog post

How they Planned the Destruction of America (And Nearly Succeeded)

In 2020 The Democrats went on a major offensive. Prevent Donald Trump from taking office, continue…See More
Tuesday
Doc Vega posted blog posts
Sunday
Doc Vega posted a photo
Sunday
Sandy posted a photo
May 31
tjdavis posted a video

It's Over. The Tool Bans Just Arrived!

First tool ban is here! A new law was just signed in New York that requires blueprint blocking technology on every CNC machine, laser cutter, lathe and 3D pr...
May 30
tjdavis posted photos
May 30
Doc Vega posted a blog post

Angry Old Man James Carville Warns of More to Come?

 A new type of signaling is brewing among the left and disenfranchised Democrats who have refused…See More
May 30
Doc Vega posted photos
May 29
Sandy posted photos
May 29
Sandy posted videos
May 29
Doc Vega posted blog posts
May 29
Doc Vega posted photos
May 28

© 2026   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted