Уровень 0 · материалов: 11
Документы, описывающие конкретные случаи утечки или компрометации персональных и финансовых данных из-за ошибок безопасности, за исключением общих описаний техник обхода защиты или эксплойтов, не приведших к массовому раскрытию данных.
Общие признаки: раскрытие конфиденциальной информации, ошибки в архитектуре безопасности, утечки данных пользователей, недостатки контроля доступа
Группа выше: Утечки персональных данных
Смысл: The text highlights a severe security breach caused by a poorly planned marketing campaign where a state corporation encouraged users to publicly disclose private account identifiers, which then allowed unauthorized access to sensitive personal and financial data through a poorly secured web portal.
A Gazprom SMM contest asked users to post account numbers publicly, enabling anyone to access their home addresses and banking details via a flawed personal cabinet portal.
Смысл: The main idea is to expose a massive security failure where a financial company left a MongoDB database open to the public, leaking sensitive personal and financial data of nearly 300,000 clients and thousands of employees and partners.
An unsecured MongoDB database leaked the personal data, passports, photos, and loan details of over 294,000 Russian borrowers associated with FinService.
Смысл: The text highlights a gross negligence in information security on a government website, where poor session management led to the leaking of personal user data and the illegal use of software licenses.
A government website in Chelyabinsk leaked users' personal data by displaying the previous submitter's information in its online forms.
Смысл: The text highlights a severe failure in cybersecurity and data privacy within a state-run educational platform, demonstrating how poor access control and API insecurity can expose the private data of minors and their families.
An author reveals a critical security flaw in a government 'Navigator' system that allows unauthorized users to scrap sensitive personal data of children and parents.
Смысл: The text highlights a severe privacy leak in Evernote's email system where predictable user IDs in unsubscribe links allowed anyone to scrape the company's entire user email database.
Evernote's unsubscribe links used predictable numeric IDs, allowing attackers to discover users' private email addresses by simply changing a digit in the URL.
Смысл: The text exposes a severe security flaw in the official Panasonic online store, where user passwords were sent in plain text and copied to three internal email addresses, contradicting the company's own privacy guarantees.
Panasonic's online store leaked user passwords in plain text to third parties, violating its own privacy policy.
Смысл: The text exposes a critical security vulnerability in Privatbank where predictable employee LDAP logins, leaked via Skype, allow unauthorized access to private customer data.
An author reveals how Privatbank's predictable employee login patterns and Skype integration allow anyone to access private customer contact information.
Смысл: The main idea is that poor architectural decisions and the use of predictable, unsecured URLs in ICQ's file-sharing system led to a massive leak of private user data, accessible via simple brute-force enumeration.
A security flaw in ICQ's server-side file sharing allowed attackers to access private user files and documents by guessing short, six-character public links.
Смысл: The text serves as a critical exposé on the gross negligence of the bestpersons website administration regarding user data security. The main idea is that basic security fundamentals (like input filtering) are non-negotiable, and professional incompetence in this area can lead to catastrophic privacy breaches.
An author exposes the critical security vulnerabilities of bestpersons by stealing passwords and posting on user blogs to prove the administrators' negligence.
Смысл: The text exposes a critical security gap in Gosuslugi where corporate electronic signatures provide access to personal accounts, creating a massive privacy risk when tokens are shared with accountants.
Corporate electronic signatures on Gosuslugi erroneously grant access to personal private accounts, exposing sensitive data to anyone handling the company's digital tokens.
Смысл: The text exposes a privacy vulnerability in Google Calendar that allowed users to discover the real name of any Gmail user simply by adding their email address to a friend's calendar.
A legacy Google Calendar vulnerability allowed anyone to find a Gmail user's full name using only their email address.