News: 1588150812

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

ProtonMail-run website boasting 'complete guide' to GDPR left credential-baring .git repo exposed online

(2020/04/29)


An EU-sponsored GDPR advice website run by Proton Technologies had a vulnerability that let anyone clone it and extract a MySQL database username and password.

The vulnerability in question allowed the entire contents of the website's /.git/ repository to be cloned, as Pen Test Partners explained [1]in a blog post about what it found on advice site GDPR.eu.

"The irony of a EU-funded website about GDPR having security issues isn't lost on us," mused the security consultancy.

GDPR.eu is run by Proton Technologies AG, better known as the Swiss corporation behind email service ProtonMail, which prides itself on being leader of the pack for all things security and privacy. While not an official site as such, it bears a prominent header that reads: "This project is co-funded by the Horizon 2020 Framework Programme of the European Union," along with an EU flag graphic.

Nine million logs of Brits' road journeys spill onto the internet from password-less number-plate camera dashboard [2]READ MORE

Within the /.git/ repo were the keys to GDPR.eu's WordPress kingdom: a full and unabridged copy of wp-config.php. In a WordPress installation, wp-config.php is the critical file containing a plaintext copy of the username and password for the SQL database powering the entire site. Someone malicious with those creds could wipe the site, rewrite its contents or deface it.

"This is an internal system, so it wouldn't be a trivial matter to compromise it externally unless the password is re-used elsewhere," noted PTP, in fairness to Proton Technologies.

A spokesman for Proton Technologies told The Register this was a "legitimate finding" while agreeing with the level of seriousness.

He said: "We were informed of this issue on Friday, the 24th of April, and a fix was deployed shortly afterwards. gdpr.eu is hosted on independent third party infrastructure, does not contain any user data, and the information in the exposed git folder cannot lead to the gdpr.eu being defaced because database access is limited to internal only. Nevertheless this is a legitimate finding under our bug bounty program. It's important to note that no personal information is stored at gdpr.eu and at no point was any sensitive data at risk."

Should you have carelessly uploaded your /.git/ repository alongside your WordPress website, treat any creds in it – not just those in wp-config.php – as compromised and change them immediately, advised PTP. Such creds could include, for example, the admin username and password for the WordPress installation. ®

Sponsored: [3]Choosing A Low-Code Vendor



[1] https://www.pentestpartners.com/security-blog/gdpr-eu-has-er-a-data-leakage-issue/

[2] https://www.theregister.co.uk/2020/04/28/anpr_sheffield_council/

[3] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

3.6 Roentgen Not great, Not terrible

Anonymous Coward

Obviously this is very sub-optimal. But I guess they are at least being open and transparent in their failure. Many companies wouldn't be.

Tux Penguin Boxing Match

LAS VEGAS, NV -- The unofficial Linux mascot Tux the Penguin will face his arch
rival the BSD Daemon in a boxing match this Saturday night. The match is part
of the International Computer Mascot Boxing Federation's First Annual World
Championship Series. The winner will advance to face one of the Intel "Bunny
People".

Boxing pundits favor Tux as the winner. Last week Tux won his first match in
the Championship Series against Wilbur the Gimp. "The Gimp didn't have a
chance," one spectator said. "With Tux's ability to run at top speeds of over
100mph, I don't see how he could possibly lose." The BSD Daemon, however, is
certainly a formidible opponent. While boxing rules prohibit the Daemon from
using his patented pitchfork, his pointy horns are permitted in the ring.

Some observers think the whole Computer Mascot Boxing Federation is a fake.
"WWF is all scripted," one sports writer pointed out. "And so is this. You
actually think that a penguin is capable of boxing? The idea of a penguin
fighting a demon is patently absurd. This whole Championship Series has no
doubt been scripted. It's probably nothing more than two little kids in
penguin and demon suits duking it out in a boxing ring. What a waste of time."