Posted: . At: 9:20 AM. This was 5 years ago. Post ID: 12696
Page permalink. WordPress uses cookies, or tiny pieces of information stored on your computer, to verify who you are. There are cookies for logged in users and for commenters.
These cookies expire two weeks after they are set.


Security still forgotten on the Internet.


The concept of securing your website is forgotten on the modern Internet, there are still unsecured websites and half-completed Drupal installations littering the web. This must be taken care of. There are a huge number of SQL database dumps that have been saved in /backup/ folders exposed to the Internet, but at least you can download them and then go through the passwords. That is nice of people to upload their stuff for me to look at. That is the great thing about the Internet, there are countless things to see, even unsecured NAS drives that are accessible and read-write. They can be used to store anything you wish, but it will get deleted by someone else. Nice of them to supply free file storage though. That is really thoughtful of them. Why do some people not care at all about security? This should be taken very seriously. I guess it only sinks in when you connect your NAS to the Internet and everything is deleted. Or not. Connecting a NAS to the Internet would be OK, if the Internet was not full of people who know how to use Google Dorks to find various open servers on the web.

That can also find unsecured printers, that is great if you have a huge 900 page PDF and wish to show it to a stranger. Uploading a PDF file about learning Linux would be very good, they would learn about free and open software. But seriously, they need to get serious about network security. Things are getting real right now. You can casually connect to a printer over the Internet and take it down easily. That should not happen. Even some HVAC systems are connected to the Internet. They do not let you change settings on the ones I have found, but they are exposed and further access could be gained with some more work. But going past publicly accessible parts is not what I would try. I am just staying with the open pages that I come across. It is just too easy. I found a webcam once that was a Russian Internet Cafe, but it requires a password now. Not sure why, it was just people playing games and surfing the web. I guess they do not want foreigners watching them. That is harmless though, better than wasting printer paper and ink. They would not like that at all.

So we need better security than we have now. But the message needs to get out, and it is not at the moment. A security researcher discovered 157 GB of highly sensitive data from more than 100 companies, including automakers such as Ford, GM, Tesla, Toyota, Chrysler, Fiat, and Volkswagen, exposed on the web. The data stored on the publicly exposed backup server belonging to the Canadian company Level One Robotics and Controls required not even so much as a password to access. This is what happens when a company does not care about privacy and security and only wants something online now not later, and the security aspect is forgotten. That is why more time must be taken to take care of these things when deploying a new solution for your business. Inspect the plan for a new installation and what network it is on, then work out what will have access to it. Do this before it is too late. Otherwise your company has embarrassing news stories about it on the web. Microsoft have this happen all of the time. The web site for Fox News was even a casualty. Sensitive information was exposed on a public web server by accident.


Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.