Jump to content

Unprotected Government Server Exposes Years of FBI Investigations

Quote

A massive government data belonging to the Oklahoma Department of Securities (ODS) was left unsecured on a storage server for at least a week, exposing a whopping 3 terabytes of data containing millions of sensitive files.

The unsecured storage server, discovered by Greg Pollock, a researcher with cybersecurity firm UpGuard, also contained decades worth of confidential case files from the Oklahoma Securities Commission and many sensitive FBI investigations—all wide open and accessible to anyone without any password.

Other severe files exposed included emails, social security numbers, names, and addresses of 10,000 brokers, credentials for remote access to ODS workstations, and communications meant for the Oklahoma Securities Commission, along with a list of identifiable information related to AIDS patients.

While the researcher doesn't know exactly how long the server was open to the public, the Shodan search engine revealed that the server had been publicly open since at least November 30, 2018, almost a week after (on December 7) Pollock discovered it.

Some real bad juju here. Someone is going to be loosing their job and ODS is going to be in a world of hurt. 

From some other news articles on this. It also looks like this leak basically allowed anyone to download government files. 


Source

ZDNet

Original article from Upguard

 

Be sure to @Pickles von Brine if you want me to see your reply!

Stopping by to praise the all mighty jar Lord pickles... * drinks from a chalice of holy pickle juice and tossed dill over shoulder* ~ @WarDance
3600x | NH-D15 Chromax Black | 32GB 3200MHz | ASUS KO RTX 3070 UnderVolted and UnderClocked | Gigabyte Aorus Elite AX X570S | Seasonic X760w | Phanteks Evolv X | 500GB WD_Black SN750 x2 | Sandisk Skyhawk 3.84TB SSD 

Link to comment
Share on other sites

Link to post
Share on other sites

Yikes

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

FBI, please make your files more secure.

- A citizen that is paying your salaries

“Security is always excessive until it’s not enough.”

– Robbie Sinclair, Head of Security, NSW Australia 

 

“Have you tried turning it off and on again?” - Every Tech Rep Ever

 

If you need help with your build please tag me.

 

 

 

Main PC:

CPU: Ryzen 3 1300x RAM: 8gb ddr4 2666 MT/s Mobo: ASRock A320M HDD: 1tb WD GPU: Gtx 1050ti 4gb

 

Spoiler

P.s. if you can tell me what reference my location I will follow you. 

Bonus points if you can tell me the names of the people there. 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, I-r0k said:

FBI, please make your files more secure.

- A citizen that is paying your salaries

FBI, please stop hiding your shady dealings along with the extremely shady dealings of all of our "representatives".

- Another citizen that is paying your salaries.

 

Leak all of it.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

When the average citizen has better internet security than a federal/state agency... 

 

ORIGIN OF *breath in* Boi - YouTube

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

Maybe they shut down the security systems because of the government funding?

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

50 minutes ago, williamcll said:

Maybe they shut down the security systems because of the government funding?

I doubt it. This kind of stuff is pretty important.

8086k

aorus pro z390

noctua nh-d15s chromax w black cover

evga 3070 ultra

samsung 128gb, adata swordfish 1tb, wd blue 1tb

seasonic 620w dogballs psu

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

This was prior to this mess we are in. Someone was an idiot/incompetent. 

Be sure to @Pickles von Brine if you want me to see your reply!

Stopping by to praise the all mighty jar Lord pickles... * drinks from a chalice of holy pickle juice and tossed dill over shoulder* ~ @WarDance
3600x | NH-D15 Chromax Black | 32GB 3200MHz | ASUS KO RTX 3070 UnderVolted and UnderClocked | Gigabyte Aorus Elite AX X570S | Seasonic X760w | Phanteks Evolv X | 500GB WD_Black SN750 x2 | Sandisk Skyhawk 3.84TB SSD 

Link to comment
Share on other sites

Link to post
Share on other sites

GG No Re, someone is having the worse case of the shits today!

My Rig - Intel I7-5820k@ 4ghz| Rampage V Extreme| 4x4GB Corsair Vengeance DDR4|RTX 2060 SUPER| Corsair 650D| Corsair HX750| 2TB Samsung 850 EVO| H100i| 3x SF-120's| 1x 240 cooler master Red LED Front intake

 

Everything I say defaults to include /s

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Please remember this the next time someone says government agencies should have access to our private information.

Leaks like these happens constantly, and the more access the government agencies has to our information, the more of it will become readable by everyone.

 

The only proper security is one with no backdoors or other deliberate weaknesses, even if "they can only be accessed by the government".

Link to comment
Share on other sites

Link to post
Share on other sites

Now I'm wondering whether senior government officials even set a passcode lock on their phones 

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

15 hours ago, LAwLz said:

Please remember this the next time someone says government agencies should have access to our private information.

Leaks like these happens constantly, and the more access the government agencies has to our information, the more of it will become readable by everyone.

 

The only proper security is one with no backdoors or other deliberate weaknesses, even if "they can only be accessed by the government".

I'll remember this the next time someone asks me to feel bad about a government employee not getting paid.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/23/2019 at 6:26 PM, I-r0k said:

FBI, please make your files more secure.

- A citizen that is paying your salaries

It sounds like this was Oklahoma's fault, not the FBIs.  Oklahoma just happened to have FBI files on their server.

My Rig:

-i7 7700k @ 4.8 Ghz, delid

-ASRock Z270-ITX/ac mobo 

-16GB G.Skill Ripjaws V @ 3000Mhz

-RX 580 Sapphire Nitro+

-240 AIO, Celsius S24

-Crucial MX300 525GB, 2TB HDD

-Fractal Design Define Nano S

-650 80+ Gold semi modular from EVGA

-1080p 75Hz dell monitor

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×