NSA Detection of a security gap by Greek investigators

Two Greek researchers managed to identify a security gap in the web of the NSA – ( Security Agency), which allowed them to use the SQL injection technique and gain access to the agency's database.

Researchers Dimitris Hatzidimitris and Anastasis Vassiliadis on 20/03/2020 identified a vulnerability in the security of the website: https://www.nsa.gov

The vulnerability is of the SQL Injection type and the link for the specific weakness remains at the disposal of our editor s.

Some of the elements of vulnerability:

Parameter: ver
Method: (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause

Database: Microsoft_Access_mast ****

NSA

Which contains 2 tables encoded!

Researchers Dimitris Hatzidimitris and Anastasis Vassiliadis report:

After that we did not proceed to a possible access to the server beyond the base since we had already confirmed the weakness in better safety of the page.

NSA

The NSA was notified in time for the security breach on 20/03/2020 and to date has not made any repairs preventing a possible leak of personal data from malicious third parties.

The information remains at the disposal of those directly interested, by the researchers themselves but also by our editorial team.

Reporting on vulnerabilities discovered in organizations is considered highly necessary (especially when they exist in high traffic), and for us they are an immediate priority.

We hope that in this way, i.e. the immediate exposure of each vulnerability, we contribute to a more secure one .

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.081 registrants.

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).