8 ms·
FTP Server at LSUHealth New Orleans
- ck2 12y agoThis is a case of some idiot who is responsible for the server having to tell management something so they say "oh this guy hacked it". Management tells the lawyers and PR which forwards it to the "news" who just go for the most sensationalist story possible. Hope he wins any lawsuit and more importantly his reputation back somehow. I'm not even sure what would have been the better course here other than to have CC'ed other people on the email. ps. No way in heck I am going to click on them but those filenames seem to appear in google cache elsewhere.
- UnoriginalGuy 12y agoLet's assume that is all true, the "journalist" not contacting the professor before publishing that article seems quite unprofessional. I mean aren't real journalists meant to check sources and get both sides of a story (or outside of America anyway)?
- rational-future 12y ago> aren't real journalists meant to check sources and get both sides of a story No, they are meant to sell as much ads as possible.
- mpclark 12y agoSteady on. The journalists I know do indeed meet society's expectations for fairness and accuracy, and make calls and pound beats, but there are also a lot more people who project themselves as journalists who are a long way from this ideal. Sadly market pressures mean there are a lot of the latter about.
- acdha 12y agoThat's the theory but remember how badly journalism has been mismanaged into a death spiral. This article smells of someone with less experience (i.e. cheaper) being told to churn out a certain number of stories a week, given less support for editing and fact checking than they'd have had a generation ago, and – most importantly – they'd better sound interesting so people click and boost page views and as impressions.
- pyre 12y agoIt looks like the source article did not name the professor. I'm unsure how the SCMagazine article author was supposed to contact said professor. Should they have just contact City College for a comment[1]? [1] the original article said it was an unnamed professor of Computer Science at City College
- rational-future 12y agoAnd that's one of the reasons if you're not a security expert and stumble upon someone's security problems, you do nothing (at least in US).
- jnbiche 12y agoNot sure why this is downvoted. Reporting a security problem, particularly a significant one, puts you at high risk for unjust prosecution and imprisonment. Unless lives are at stake due to the security lapse, it's pretty clear to me that the only reasonable response is to go "oh, that's interesting" and then close your browser window and never tell a soul.
- lotsofmangos 12y agoWhat part of "server containing medical data about thousands of patients." indicates to you that lives were not at stake? edit - the folk saying that this guy was stupid for doing anything are completely irresponsible.
- jnbiche 12y agoWhat part of archived medical data would put lives at risk? I mean, it sure as hell puts their privacy at risk, but can you describe what scenario you are imagining that puts lives at risk? Just because it has the word "medical" doesn't mean it's life or death (and this appears not to be).
- click170 12y agoFrom my point of view this is what anonymous full disclosure is for. Naming and shaming typically gets some kind of a response. Keeping quiet does not. I know not everyone agrees with full disclosure but I assert there is a time and a place, and after a demonstration like this one, IMO this university is one of those places. Edit: typo
- akerl_ 12y agoReading through this, it seemed like a pretty clear-cut case where Bowne had done things right from start to finish. And then I got to this: "Apparently, committing libel is a common thing for them, and they are comfotable completely ignoring the protests of their victims." I understand that he's likely under tremendous stress as a result of the allegations that LSU has made, but I'm a bit concerned that in his expression of shock and outrage he has turned to making what appear to be potentially libelous statements of his own. I hope that his goal of having the accusations withdrawn is not hindered by this momentary slip into hyperbole.
- atmosx 12y agoHm, not really. That's just you being pedantic. When you've been a victim of someone else's incompetence you assume that he is an incompetent because, the only reason you know of his existence is because of his incompetence. Given the fact that many of us believe that the two magazines do not really care about what happened, as much as they prefer getting clicks - a view which is supported by the course of action this story took - it's not a far-fetched claim at all. Especially for a man in his position. NOTE: They didn't took any action even when notified. The only way for them to remove the article would a letter from a lawyer (or at least that's what I'm getting).
- akerl_ 12y agoNeither his position nor his circumstances provide factual backing for the claim that "committing libel is a common thing for them" or that "they are comfotable completely ignoring the protests of their victims". Being a victim of their incompetence does not give him free license to imagine ways he things that they are incompetent and then express them as fact. They have not yet taken any action. It's just as likely that they haven't seen his tweet. They are certainly in the wrong here. But his jab at their moral standing weakens his position, and given the state of business <-> individual relations when it comes to disclosing security vulnerabilities, he wants his position to be as strong as possible in case they do turn out to be malicious and attempt to make the case that he violated their security.
- skywhopper 12y agoClearly the article was wrong, but the reporter could only go off of what the hospital told him or her, and that does not seem to have included the professor's contact information. Rather, I'm guessing the message that got out of the IT department was "we got hacked by a professor", which then likely mutated via the rumor mill into the details about a class demonstration. If anything, I think this shows the hospital gave the professor a lot more benefit of the doubt than I would have expected. The professor did himself no favors with his email: I am Sam Bowne, an instructor at City College San Francisco, and I found two security problems on your server with a Google search. Your FTP server has been compromised, and some files named "w0000000t" were added to it. If I'm the IT administrator who receives this message, then after reading the first two sentences, I've already jumped to the conclusion that this professor is the individual who compromised my server! "Hi, I found security issues with your server, and now it's compromised!" Sure, once you've read the intro by the professor, the meaning is clear, but think of yourself as a sysadmin getting this email, without the context of "I just found this, I had nothing to do with it" in your brain, and how are you going to react? Once the idea that the sender of this email is a hacker who broke into your server has entered your mind, it's going to be very hard to interpret it differently. Given that, the guy got treated pretty nicely by the story and the hospital in the end.
- binarymax 12y agoYour first sentence echoes the sorry state of affairs regarding what passes for journalism these days. Getting all angles of the story and doing fact checking is absolutely the responsibility of the journalist. The author had the professors name - all it takes is 5 minutes of research to get contact information to follow up correctly. The journalist really has no excuse in this matter.
- ar-jan 12y ago> The author had the professors name No, as far as we know the articles were based on the University Health legal notice http://www.uhsystem.com/Conway/FINAL%20Conway%20-%20Press%20Release%20-%202014-8-15.pdf http://www.uhsystem.com/Conway/FINAL%20Conway%20-%20Press%20..., which does NOT contain Sam's name. Can you accuse someone of libel if the accused is unnamed? This doesn't take away from the fact that the claims in the report are false, of course.
- jnbiche 12y agoSam, if you're reading this, you need to find the newspapers' ombudsman. You'll probably get better results from him/her than the CEO, since their job is specifically to address these issues and in a decent organization will be given the autonomy to do so (no guarantees here!). It's not clear to be that LSU is responsible for anything more than shitty security. It's possible that they told the newspaper lies, but it's also possible that they told them the truth and that the newspaper misreported. I think reporting them for a HIPAA retaliation may have been premature, unless you know more about this situation than you wrote on your site (as opposed to reporting a HIPAA violation, which this clearly is). But best of luck going after the newspapers. I'm getting sick of these "journalists" making up lies about the central figures in their stories without bothering to even check with them first to get their side of the story. EDIT: Aaand, apparently, neither publication has an ombudsman, which tells you a lot already. Not a big surprise with SCMagazine, which is some kind of trade magazine, but it's too bad that even a small-circulation newspaper like the News Star wouldn't have one.
- coldcode 12y agoI spent a time as a HIPAA architect so I know exposing patient information to the public is a violation and should be reported even if accidental. However reporting it and having someone actually investigate it and prosecute is unlikely. It was pretty rare that anything was ever done (been a few years), especially to a large organization. I also know that people inside companies that handle HIPAA covered information rarely care as long as they pass their audits.
- Soyuz 12y agoI'm not sure why people inform organizations about vulnerabilities. All what they will get from informing them is to get shock when they slap you on the face and call the police for the alleged hack! it is better to sell the vulnerability in the underground forums
- XorNot 12y agoNo it is better to do absolutely nothing, and quietly divest yourself from them because that's not illegal. But what we really need are some damn whistleblower protections for cybersecurity - buzz-wordy enough for government funding and command centers, but no actual help for the people who want to help because it feels like the right thing to do.
- gilgoomesh 12y agoThere are protections for cybersecurity here. From the article: > HIPAA explicitly forbids LSU from retaliating against me for reporting a HIPAA violation, so I filed a federal complaint against them for their illegal retaliation.
- cnlwsu 12y agoConsider it a ethics thing. Willing to take the risk to protect those innocent people's data or sell a grandma's SSN to the highest bidder. I think identity theft takes a certain amount of self centeredness and lack of empathy that I could never deal with. The option to do nothing is a strong one as well. I would say its best to report it but do it anonymously.
- SeanDav 12y agoThis is a symptom of an unfortunately very common reaction to system security. Unless businesses are actively encouraging bug hunting, almost unbelievably they will act with a lot of hostility to exposure of weaknesses in their systems and will often shoot the messenger with extreme prejudice, even if they receive the information privately. There are countless examples of people getting burned rather than rewarded or even thanked for bringing to attention some sort of flaw. My advice is do not bother. There is almost no upside for you and likely very significant downsides.
- RexRollman 12y agoYou would think they would have been grateful for the head's up. I guess some people would rather shift blame then accept they made a configuration or security mistake.
- busterarm 12y agoThat's pretty much the norm in IT. After 15 years or so, I've seen pretty much everyone shift blame or blatantly lie their ass off to cover their own shortcomings...including a very senior person "invent" a completely fictitious rootkit to excuse the fact that the business lost critical data due to his negligence. It doesn't pay off to blow the whistle on this behavior either and provides a blackmail opportunity that I've seen people capitalize on. Most everyone looks the other way in this business and there's a large amount of lying about credentials & experience to land jobs.
- deleted 12y ago[deleted]
- kermorvan 12y agoReading your post makes me wonder why bug-hunters aren't more cautious about this. Sure the sentiment is good, it is a moral obligation to expose a bug that could be harmful to users. But if you suspect you could get burned for pointing it out, you can take steps to mitigate it. Anonymity for example. Then again if you are in it for the fame and recognition, getting burned is a risk you are taking out of vanity.
- Mithaldu 12y agoThe follow-up article ( http://www.scmagazine.com/professor-says-google-search-not-hacking-yielded-medical-info/article/368909/ http://www.scmagazine.com/professor-says-google-search-not-h... ) has the most ironic line in it: > At press time, Sam Bowne had not responded to a Thursday email and Friday phone call from SCMagazine.com for comment.
- sentientmachine 12y agoIts a mistake airing your side of the story in legal proceedings before trial. At this point the professor is guilty until proven innocent by people who don't know the difference between a browser and an internet. The prosecution is going to have the benefit of knowing the defense before the trial, and the defense will not have the benefit of knowing the cards of the prosecutor before the trial. "Hacking" is a villianized word like witchcraft was back in the Salem witch trials. The law has no idea what it is, doesn't know what should be legal or illegal, and fear is drummed up to maximum. Its a recipe for some innocents to get cooked. The ones accused of being a witch better play their cards right, or else the judicial system is going to punish the good actors, and reward the bad actors. Don't talk to police: http://m.youtube.com/watch?v=6wXkI4t7nuc http://m.youtube.com/watch?v=6wXkI4t7nuc
- mariuolo 12y agoNext time send the newspaper an anonymous tip. The guys with the open FTP server clearly don't give 2 fucks about your privacy, but in a sue-happy atmosphere they're trying to place the blame on someone else.
- volume 12y agoAt a minimum the reporter could have googled Sam to find out he teaches security and the range of classes: http://samsclass.info/ http://samsclass.info/ ... or applied some logic. Instead of contacting them directly he could have: * broadcasted it to the world (maybe a reporter!) that the FTP server was insecure * do/say nothing
- pyre 12y agoHow was the reported supposed to Google this? Looks like he wasn't named in the original article or the SCMagazine.com article. Just a "professor of computer science at City College in San Francisco." Unless he is the only computer science professor there, then they didn't have his name.
- powertower 12y ago"It is outrageous for a journalist to write such lies, accusing me of serious crimes, without even contacting me to find out what happened." There is little to nothing that can be done about this. It's all about narratives, sensationalism, and agendas today. Just take a look at the media stories about Ukraine where everyone (in US media) just makes shit up and presents it as the truth. No one questions anything. Or the Michael Brown shooting. Where the media (CNN, MSNBC) pushed their narrative once more, completely ignoring all facts surrounding the event. It goes on and on and on, with almost every major story being so biased, misleading, and twisted, that it might as well be seen as a complete fabrication... Here is another good example of security related stories being "misleading" - http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudulent.html http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudul...
- ethanpil 12y agoThis is exactly was has been happening to reports about Israel / Gaza. Same problem. Outright lies.
- pessimizer 12y agoAnd while we're being vague cranks, how about the parking on the street around the corner from my house? Is it allowed on weekdays or isn't it? At what time? I can never get a straight answer.
- lotsofmangos 12y agoI can remember back when there were ships on the Tyne. Big ships. With funnels and everything.
- spacemanmatt 12y agoOutside of U.S. jurisdiction for a libel (civil) case
- rdxm 12y agoOne can only hope our friends at UHC are undergoing a proper procto-scoping by the regulators at this point. As for the reporting side of this (note I did not use the word 'Journalism'...)..this is the quality level that has become the standard in the world of junk news. One must have the sensationalism in the title to get the click...that's it. The actual quality of the content is pretty much irrelevant..
- chris_wot 12y agoThe journalist's twitter account is here: https://twitter.com/writingadam https://twitter.com/writingadam
- hliyan 12y agoAnd for anyone considering writing to the source of the problem: http://www.lsuhsc.edu/ContactUs/ http://www.lsuhsc.edu/ContactUs/
- pavel_lishin 12y agoLet's not turn this into a reddit-style witch hunt.
- chris_wot 12y agoUmm... too late? The witch hunt began with the man targeting the professor.
- pavel_lishin 12y agoMom, he started it!
- lnanek2 12y ago> This is a very strange way to run a news blog. He doesn't seem to realize all that matters to the blog is getting page views...
- jigglepanda 12y agoit's sad that institutions act this way. I also stumbled upon a rather nasty vulnerability in the website of a largish company. I left it as is, without notifying anyone, precisely because I didn't want any trouble. if I found it by accident, I'm sure malicious actors can find it as well.
- chid 12y agoIf you read the article, it was already exploited.
- metaobject 12y agoI like the fact that the article stated that no patient information had been accessed. How many times have you heard that line when news of a breach is made public? It makes me think that these folks would rather cover up a breach than actually take responsibility for it.
- fnordfnordfnord 12y agoYeah. Having been caught storing private information on an open ftp server disqualifies your authority to claim that you know/knew who else may have accessed the data.
- spacemanmatt 12y agoRead: logging=off
- ninkendo 12y agoTechnically they said "no patient information was lost", which is one of those weasel phrases they can "clarify" if anyone calls them on it. "Oh we meant it wasn't lost, as in it wasn't deleted off our servers!"
- tptacek 12y agoFalsely accusing someone of a crime often isn't just libel, it's per se libel, meaning that that there's liability even if the aggrieved party can't prove damages. Running a newspaper article that turned out to be false without even attempting to contact you might clear the negligence hurdle here.
- gravypod 12y agoI have always loved Sam's work at Defcon. It is sad to see the world "turn" on a good security researcher.
- cientifico 12y agoI think the first article is just an sponsored article by University Health Conway. By trying to convince public opinion that it was hacking, University Health Conway probably want to skip charges for negligence, reveal and distribute personal data publicly...
- mk00 12y agoThis guy is an idiot who will soon be working at a non-accredited university. Nice little publicity stunt for his non-credentials. White hat hacking is a myth and an ego-booster for guys with no balls.
- chrisbennet 12y agoSince you didn't read the article: He didn't hack them (unless performing a Google search and clicking on the link is "hacking" now) and he didn't tell anyone but LSU about their security problem - until he was attacked for trying to help them out.
- cjschroed 12y agoThis is why I never ever "report" security vulnerabilities without first having a contract with the afflicted party. It sucks, but I am not willing to be burned as a witch just because I understand security.
- plg 12y agoI think the thing to be careful of here is the method(s) one uses to reveal a vulnerability. Think of a brick-and-mortar analogy. You queue up at airport security, you go through, and you notice that their procedures are such that one COULD bring a banned item through and potentially not get spotted. You inform the appropriate authorities that you think there might be a weakness, and you say how and why. This is probably not going to get you in trouble. Another scenario: You go through security and make a mental note (as above) of a potential vulnerability. You (as above) report it to the appropriate authorities. Now some time in the future you are going through airport security and you wonder to yourself "I wonder if they fixed it". So you decide to test it out. You bring a banned item through. You get caught. You are in trouble but you say in response "but I was the guy who informed you of the vulnerability and I was just checking to see if it was fixed". Good luck with that. My feeling is that if you notice a potential (or actual) vulnerability as part of a everyday, normal use case of a website, or a web service, or network, then fine, you can report it, and you likely won't get into trouble. On the other hand if you additionally decide to test the system in such a way that could be misconstrued as an attack, then you will probably get into trouble. Another analogy: you walk into Macy's and on your way in you notice that the security system they are using is outdated, and you know it is vulnerable --- (made up silly example) you know that if you break in while holding a tuna sandwich, the alarm will not go off. So that night after the store is closed and locked, you break in, while holding a tuna sandwich, and you take a pair of $300 shoes. The next day you go to the store and you say "look guys, I was able to break into your store and steal these $300 shoes." You think they will thank you? or will they call the police?
- pitnips 12y agoI like your first analogy. Your second analogy, on the other and, seems to me to justify the action. I think Macy's would thank you rather than call the police, but that's just my opinion.
- plg 12y agomaybe they would thank you. Imagine though the day after, they had noticed security camera footage of a masked intruder wandering the store, and then taking merchandise out the door. They can't identify the intruder. They call the police. There is an investigation. They spend $$$ on a new security system. People are fired. Then some time later you wander in with a smile on your face and tell them how you were the one who cracked their system. I can see a scenario where they are furious with you and call the police, telling them that you have just confessed to a crime. Then police then say, hey buddy you committed a crime, you confessed to it, and now you are trying to say you did it "for a good reason". Good luck with that.
- lutusp 12y agoIf the linked recitation in any way corresponds to reality, and it seems to, the professor has a legitimate complaint, but he should have consulted an attorney before publishing his responses to the various parties involved. The reason I say this is because, even though he appears to be in the right and has a reason to be outraged, he could be sued for libel himself. As one example, if he describes a named or identifiable person as a "liar" online, the subject could sue for defamation of character if it turns out that they didn't know what they said was false (which fails the definition of "lying"). That's a simple case where an extreme, emotional term places someone in a false light. http://en.wikipedia.org/wiki/False_light http://en.wikipedia.org/wiki/False_light Remember, in this litigous society, no one is immune from legal actions, even those clearly wronged, as the facts seem to indicate in this case.
- teachingaway 12y agoThe follow-up article is a bit better. But I don't like the way the original title is presented as fact: "Professor hacks University Health Conway in demonstration for class" While the follow-up is titled as "Professor says..." "Professor says Google search, not hacking, yielded medical info" http://www.scmagazine.com/professor-says-google-search-not-hacking-yielded-medical-info/article/368909/ http://www.scmagazine.com/professor-says-google-search-not-h...
- rmc 12y agoWhy don't they lawyer up, and sue them for defmation/libel?
- Mandatum 12y agoI can give some personal experience on this - I started bug/vuln reporting mid-last year. I've reporting a bunch of web-applications bugs that ranged from simple XSS and CSRF to RCE and directory transversal in a range of applications (Enterprise software is rampant with holes). I've only encountered two non-respondents. Everyone else has thanked and patched within a month and I even gained employment from one encounter! Yet to get a reward, however I do this for a hobby, rather than money. Although one day I hope to do this professionally! There isn't much work in New Zealand for it though. EDIT: To clarify, my process is: report to vendor with suggested patches, follow-up 1 week later if no response, follow-up two weeks after response to see if it's patched, ask permission to use my bug report publicly. In some cases there'll be a phone call from the respondent to ask about my background and see what my intentions are. Occasionally they schedule a coffee/meeting.