Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

7/26/2019
11:35 AM
50%
50%

FormGet Storage Bucket Leaks Passport Scans, Bank Details

Exposed files include mortgage and loan information, passport and driver's license scans, internal corporate files, and shipping labels.

A cloud security mishap at FormGet has exposed sensitive user-uploaded files dating back to 2013 through a misconfigured Amazon S3 storage bucket, TechCrunch reports. It's the latest company to leave troves of data open to the Internet, signifying a concerningly common trend.

Bhopal, India-based FormGet provides online form creation and email marketing services to around 43,000 customers. People can use its tools to create forms for job applications, online shopping, and other processes. An anonymous security researcher found its S3 bucket had been left online sans password and contacted TechCrunch in an attempt to address the issue.

The bucket contained "hundreds of thousands" of files and documents dating back to 2013, packing a broad range of sensitive user-uploaded files: scans of passports, driver's licenses, paychecks, and Social Security numbers; details of obtained loans and mortgages, bank account statements, and utility bills; UPS shipping labels with names and phone numbers; resumes containing contact information; and internal corporate documents containing cybersecurity assessment notes for multiple banks and financial firms, the report states.

"The problem of misconfigured cloud storage is often exacerbated by trusted third parties," says Ilia Kolochenko, founder and CEO of ImmuniWeb. Businesses often need to share data with vendors like FormGet, which may often prioritize performance over data protection to keep up with a competitive market. Most companies have a vendor risk management policy, he adds, but these are rarely monitored for noncompliance, and few are properly enforced.

Given the frequency at which these data exposures happen, Amazon and other cloud providers have taken steps to lock down storage buckets by default. Businesses storing data in the cloud are urged to double-check their configuration settings to be sure information is private.

Read more details here.

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
tdsan
50%
50%
tdsan,
User Rank: Ninja
7/28/2019 | 5:35:31 PM
Another S3 bucket issue
There are numerous articles written where vendors and organizations allow actors to compromise S3 buckets with vital information. The vendors can only do but so much, each instance involves the oversight of a person working for the organization who has not been properly trained. This is a pattern that can be mitigated with proper training and experience.

There is a simple way to address this problem, the S3 bucket process involves blocking public access if the user goes to aws.amazon.com | Select S3 | Click the bucket | Click Permissions Tab | Select Block Public Access. Secondly, select "Access Control List" | access for bucket owner | Select the bucket owner (should be a long bucket id to allow access only to this S3 bucket).




Examples of S3 Bucket compromise are listed below (this is not the complete list but it should give you an idea of breaches. 
Attunity
Megacart
TD Bank
Netflix
Ford
UpGuard
Accenture Federal Services

Again, all of these instances could have been mitigated by following best practices provided by AWS (improperly trained personnel or oversight need to be top priority). 

T
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...