Comment On Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

One of the cardinal rules of computer programming is to never trust your input. This holds especially true when your input comes from users, and even more so when it comes from the anonymous, general public. Apparently, the developers at Oklahoma’s Department of Corrections slept through that day in computer science class, and even managed to skip all of Common Sense 101. You see, not only did they trust anonymous user input on their public-facing website, but they blindly executed it and displayed whatever came back. [expand full text]
« PrevPage 1 | Page 2 | Page 3 | Page 4 | Page 5Next »

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:09 • by ID (unregistered)
Woaw just... woaw.

I have nothing more to say.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:12 • by SpamBot (unregistered)
WTF!

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:17 • by Saaid (unregistered)
189721 in reply to 189719
This is a real WTF and it's not funny.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:17 • by Sean Ellis (unregistered)
The real WTF is you publishing a screenshot without anonymizing their names and addresses...

I imagine the residents of Merland Drive, Cindy Road, Lee Avenue, and so on are gathering up their torches and pitchforks as we speak.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:22 • by Koko the gorilla (unregistered)
EPIC fail.
Some must get fired.
And prosecuted.
And kicked in the balls, twice.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:22 • by Royal (unregistered)
If ever there was a major WTF, this is it.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:22 • by Suburban Decay (unregistered)
189726 in reply to 189722
The names and addresses were already available through the registry. The only thing that wasn't supposed to be was the SSN.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:29 • by q (unregistered)
189728 in reply to 189722
moron

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:30 • by Grisen (unregistered)
You should have helped them by doing a ALTER TABLE and removing the SSN :)

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:32 • by Grovesy
jeez, they may as well have put their entire database onto a cd, unecryted then loose it in the post... oh wait..

http://news.bbc.co.uk/1/hi/uk_politics/7117291.stm

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:32 • by Anonymous (unregistered)
>_<

But seriously, this is not so tragic. That's because the government watches terrorist internet activity closely, so that any bad guy trying to pull this SQL trick is going to be intercepted by highly competent cyber-cops and will never receive the data he requested from the server. In other words, you can be assured that only the good guys are able to view your personal data and you've nothing to hide from the good guys after all.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:33 • by Julia
It also doesn't take a lot of imagination to try a SQL UPDATE. Like adding that guy up the road who irritates you to the sex offenders...

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:35 • by A Nonny Mouse
189734 in reply to 189730
Grovesy:
jeez, they may as well have put their entire database onto a cd, unecryted then loose it in the post... oh wait..

http://news.bbc.co.uk/1/hi/uk_politics/7117291.stm


heh, i was about to post up http://news.bbc.co.uk/1/hi/uk_politics/7104368.stm :)

(don't know why i'm smiling... :-\ )

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:36 • by anon (unregistered)
189736 in reply to 189731
But seriously, this is not so tragic. That's because the government watches terrorist internet activity closely, so that any bad guy trying to pull this SQL trick is going to be intercepted by highly competent cyber-cops and will never receive the data he requested from the server. In other words, you can be assured that only the good guys are able to view your personal data and you've nothing to hide from the good guys after all.

oh god at first i thought that was a real comment

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:39 • by Sad Buckeye (unregistered)
189738 in reply to 189730
That happened here in Ohio too, where our state government's "backup plan" was to send an intern home with an unencrypted tape backup. Where they were to keep it in their home "safe" and sound. One of them left it in their car, which was promptly broken into and the "odd" looking tape was stolen along with other junk from the car.

More info from this /. http://it.slashdot.org/article.pl?sid=07/07/27/1222215

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:40 • by anon (unregistered)
Wow, and I live in Oklahoma... thankfully I've never had a reason to be registered in such a database, but still... makes me wonder what else my great state may be doing in the realm of WTF.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:52 • by KNY
I just want to congratulate everyone involved with this story on bringing about a fix for the problem. If only there were more well-behaved developers pointing out (rather than exploiting) security holes, and companies being receptive to said notifications (instead of being defensive and accusatory).

Again, well done.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:54 • by jonny s. (unregistered)
189743 in reply to 189731
Anonymous:
But seriously, this is not so tragic. That's because the government watches terrorist internet activity closely, so that any bad guy trying to pull this SQL trick is going to be intercepted by highly competent cyber-cops and will never receive the data he requested from the server. In other words, you can be assured that only the good guys are able to view your personal data and you've nothing to hide from the good guys after all.


Challenge: make a comment that is so obviously sarcastic it is impossible that someone in the world is the dumb enough to actually think that way.
Hint: this is impossible.

: (

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:57 • by pauldwaite (unregistered)
Maybe Oklahoma should start an online registry of the idiot developers who put this system together, and the managers who let them.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 08:59 • by Erick
When a corporation does this, they take a huge hit in the form of lawsuits, stock drops, and lost business. When the government does it, it's a big brouhaha news story, maybe one person gets fired, and then it's back to business as usual.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:01 • by jcoehoorn
That's the kind of breach someone should lose a job over.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:06 • by MadJo@Work (unregistered)
Euhm, Alex, the blurring of the email addresses in that last picture doesn't really work, I can figure almost all of them out. Might want to use a black pen next time instead of blurring. The Social Security numbers are blurred a bit better, but still it would be better still to use a black pen in whatever photo editing program you are using,

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:07 • by anon (unregistered)
and remember many people are in favor of having the government run healthcare. wtf indeed.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:10 • by Craig (unregistered)
FUCKING
A W E S O M E . . .

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:11 • by dkf (unregistered)
189753 in reply to 189748
MadJo@Work:
Might want to use a black pen next time instead of blurring.
Better yet, print it out, use a black pen, then take a picture of the result lying on a wooden table...

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:15 • by Grovesy
189754 in reply to 189739
anon:
Wow, and I live in Oklahoma... thankfully I've never had a reason to be registered in such a database, but still... makes me wonder what else my great state may be doing in the realm of WTF.


Well.. with such a gaping sql injection hole, thankfully no one registered you!...

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:19 • by J. Walter Weatherman (unregistered)
That's nothing compared to what I leaked out of my ass this morning.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:21 • by ptomblin
They better hope that Little Bobby Tables never commits a crime.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:21 • by captain obvious (unregistered)
189758 in reply to 189741
KNY:
I just want to congratulate everyone involved with this story on bringing about a fix for the problem. If only there were more well-behaved developers pointing out (rather than exploiting) security holes, and companies being receptive to said notifications (instead of being defensive and accusatory).

Again, well done.

Receptive? They failed, the first time, they took the site down only to have it come up with a failure, a band aid solution. Second time, they resorted to just taking the whole thing down. Agreed on the accusatory nature of organisations though.

And don't think about congratulating the IT department. This is a disaster. I seriously hope those directly responsible for this are not only fired, sued and maybe even locked up or a shit load of community service. This is an utter failure in their duty of care, why the fuck would you take on a role on a project involving sensitive data if you have any idea how incompetent you are? Sad thing is they probably don't know that, and neither does management.

captcha: feugiat (bit of an understatement don't you think)

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:23 • by ptomblin
189759 in reply to 189750
<i>and remember many people are in favor of having the government run healthcare. wtf indeed.</i>

Yes, because private companies never leak data.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:23 • by ParkinT
189760 in reply to 189729
Grisen:
You should have helped them by doing a ALTER TABLE and removing the SSN :)


And that would test their backup strategy (or lack thereof)

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:25 • by ParkinT
189761 in reply to 189739
anon:
Wow, and I live in Oklahoma... thankfully I've never had a reason to be registered in such a database, but still... makes me wonder what else my great state may be doing in the realm of WTF.

April 12, I added your name to the list with a properly formed URL.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:26 • by Martin Dreier
189762 in reply to 189757
ptomblin:
They better hope that Little Bobby Tables never commits a crime.


Sorry, but you forgot the obligatory XKCD reference ;).

Please!!!

2008-04-15 09:33 • by EPE (unregistered)
Please, do not go to "Advanced Search" at Goolge, and do not look for pages containing SELECT FROM WHERE in the URL... Please, do not do it, oh please!

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:39 • by Coditor
I vote for an anual "WTF Award" - preferably big and pointy, to be shuved up their *.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:39 • by MAV (unregistered)
Good gravy... I'm dumbfounded.

Clearly the terrorists have already won.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:41 • by Mark G (unregistered)
The real WTF is the poor attempt at blurring the email addresses.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:43 • by DOA
And you post this AFTER they took it down? Damned responsible users...

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:43 • by CGomez (unregistered)
Very brave of you to post the exploit in the open like this. I know that your readers could have done the same thing and I also know that nothing is to be gained by shrouding your work in secrecy.

I'm just thinking there is probably some ridiculous law that has been violated and will be used to blame you for merely showing the incompetence and failure of whomever developed the system.

Wow. I applaud the work.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:55 • by Frigax (unregistered)
The real WTF is:

and upper(zip) = '73064'

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 09:58 • by brian j. parker (unregistered)
I started the story and thought "seriously now, people working for the government don't know about validating input fields for SQL injection?"... but then I get passing the query in the URL and comments describing the schema in public-readable comments. That is a pretty epic level of WTF.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:01 • by dignissim (unregistered)
Looks like Paula got a job working for Oklahoma!

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:10 • by dlikhten
I'm glad you are honest and moral. Also I would have gone straight to the news to ensure that they get their asses whooped for doing something so amazingly stupid and so nasty for regular folks completely unsuspecting.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:17 • by FredSaw
I see Pamela Anderson works there. Wonder if she's a guard.

If I had only known...

2008-04-15 10:23 • by Unethical (unregistered)
My recently-ex boyfriend got married a year ago. I found out this little fact a couple of days back. He lives in OK...

Why, oh why, did you have to leave this article until after the security hole was closed?

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:33 • by maniek (unregistered)
http://www.google.pl/search?q=allinurl:+select+from+and
There are some interesting hits (especially a few pages further into the search results)

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:33 • by akatherder
189786 in reply to 189760
ParkinT:
Grisen:
You should have helped them by doing a ALTER TABLE and removing the SSN :)


And that would test their backup strategy (or lack thereof)


Effectively leaving the data open to the public is their backup strategy. The only difficult part is getting people to admit they have it so they can do a restore.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:36 • by ThePants999
189789 in reply to 189762
Martin Dreier:
ptomblin:
They better hope that Little Bobby Tables never commits a crime.


Sorry, but you forgot the obligatory XKCD reference ;).

...because we all knew where it came from anyway!

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:37 • by ThePants999
189790 in reply to 189758
captain obvious:
why the fuck would you take on a role on a project involving sensitive data if you have any idea how incompetent you are? Sad thing is they probably don't know that, and neither does management.

Research shows that clever people think they're clever, average people think they're average, and dumb people think they're clever. It's a shame nobody else realised they were dumb though.

Re: Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data

2008-04-15 10:40 • by SomeCoder (unregistered)
.......

There are no words. I really hope whoever wrote that code gets Worse Than Fired...
« PrevPage 1 | Page 2 | Page 3 | Page 4 | Page 5Next »

Add Comment