Threat Intelligence

11/26/2018
01:40 PM
50%
50%

USPS Web Vuln Exposes Data of 60 Million

The US Postal Service recently fixed a security bug that allowed any USPS.com account holder to view or change other users' data.

The United States Postal Service (USPS) last week patched a vulnerability in the API for a program called "Informed Visibility," which enabled anyone with an account for USPS.com to view and, in some cases edit, information of other users, KrebsOnSecurity reports.

KrebsOnSecurity was alerted to the bug by an anonymous researcher who reportedly informed USPS of the problem more than a year ago and didn't receive a response. In this case, the vulnerability was in the API of Informed Visibility, an online application designed to provide package tracking data to businesses, advertisers, and other organizations sending mail in bulk.

The bug exposed "near real-time data" about mail in transit from commercial users. It also let any USPS online account holder to query its system for other users' account details: usernames, phone numbers, email and physical addresses. If multiple accounts shared a common trait, like a street address, searching for that one piece of data unearthed multiple user records.

Setu Kulkarni, vice president of strategy and business development at WhiteHat Security, points out how when not secure, APIs can prove dangerous for organizations. He advises companies to perform security tests against potential weak spots, like APIs, network connections, mobile apps, websites, and databases.

"APIs are turning out to be a double-edged sword when it comes to internet scale B2B connectivity and security," he explains. "APIs, when insecure, break down the very premise of uber connectivity they have helped establish."

In a statement, USPS said it has no data indicating this bug was used to exploit user records.

Read more details here.

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-15031
PUBLISHED: 2018-12-18
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
CVE-2018-19522
PUBLISHED: 2018-12-18
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for partial input.
CVE-2018-1833
PUBLISHED: 2018-12-18
IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.
CVE-2018-4015
PUBLISHED: 2018-12-18
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to...
CVE-2018-20201
PUBLISHED: 2018-12-18
There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.