Уровень 0 · материалов: 7
В кластер включаются документы, описывающие конкретные технические ошибки в механизмах защиты данных и доступа в российских сервисах, и исключаются общие рассуждения о кибербезопасности без привязки к конкретным уязвимостям.
Общие признаки: хранение паролей в открытом виде, критические ошибки аутентификации, утечки персональных данных, недостатки безопасности API и веб-порталов
Группа выше: Уязвимости систем аутентификации
Смысл: The main idea is to expose a critical authentication flaw in MegaFon's services where a lack of brute-force protection on one portal compromised the security of another, leading to financial theft from users.
A security loophole in MegaFon's SMS portal allowed hackers to brute-force passwords and steal money by subscribing users to paid services.
Смысл: The text describes a critical security vulnerability in Rostelecom's authentication system where a user was incorrectly logged into another customer's account, granting unauthorized access to private data and services, and criticizes the company's inadequate response to the report.
A user discovered a major security bug in Rostelecom's login system that allowed them to access a stranger's private account, but the company ignored the vulnerability in its official response.
Смысл: The text serves as both a technical case study of a professional phishing campaign and a public disclosure of a critical security flaw in the MAX messenger API. Its main idea is that structural vulnerabilities in API design can make high-end phishing attacks nearly indistinguishable from legitimate logins, and corporate silence on such issues endangers millions of users.
A security researcher uncovered a massive MITM phishing network targeting MAX messenger users, exposing a critical API flaw that allows account takeover and potential access to government services.
Смысл: The main idea is that the MegaFon SMS leak was caused by basic web development negligence (lack of indexing restrictions and session control), leading to the accidental public exposure of private messages via search engines.
A technical breakdown explaining how MegaFon's poor website security allowed Yandex to index and publicize private SMS messages sent through their web service.
Смысл: The author discovers a security breach where their utility company stored passwords in plain text, and upon seeking a regulatory body to complain (Roskomnadzor), discovers that the regulator's own website leaks citizens' passport data.
An author trying to report a utility company for a data leak discovers that the federal regulator, Roskomnadzor, is leaking passport data on its own website.
Смысл: The main idea is that LiveInternet.ru stores passwords in plain text (or reversible formats) and sends them directly via email during recovery, posing a severe security risk to users through credential exposure and potential password reuse attacks.
LiveInternet.ru dangerously sends existing passwords in plain text via email during the recovery process, exposing users to identity theft and unauthorized account access.
Смысл: The text reports a critical security flaw where RU-CENTER (a .ru domain registrar) allegedly stores administrative passwords in plaintext or reversible formats, allowing them to be sent back to users in full and viewed by internal operators.
The author discovered that RU-CENTER stores domain passwords in a recoverable format after receiving the same password multiple times through a recovery request.