News: 1631619013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thousands of internet-connected databases contain high or critical CVEs, says report by cloud security biz

(2021/09/14)


After spending five years poring over port scan results, infosec firm Imperva reckons there's about 12,000 vulnerability-containing databases accessible through the internet.

The study also found that of the 46 per cent of 27,000 databases scanned, just over half that number contained "high" or "critical" vulns as defined by their CVE score.

The news might prompt responsible database owners to double-check their updates and patching status, given the increasing attractiveness of databases and their contents to criminals and hostile foreign states alike.

[1]

Imperva's chief innovation officer Elad Erez said in a statement: "Too often, organizations overlook database security because they’re relying on native security offerings or outdated processes. Although we continue to see a major shift to cloud databases, the concerning reality is that most organizations rely on on-premises databases to store their most sensitive data."

[2]

[3]

Erez's company sells cloud security products, so he's not without a dog in this fight. Nonetheless, his assertion that on-premises databases tend to be more vulnerable to attackers than cloudy ones may have some force to it.

[4]Open-source software starts with developers, but there are other important contributors, too. Who exactly? Good question

[5]Das geeks hit crowdfunding target: IBM mainframes are coming home

[6]Microsoft fixes flaw that could leak data between users of Azure container services

[7]Google plays catch-up with JSON support for distributed RDBMS Spanner

For British database owners and operators, Imperva reckoned that 61 per cent of those it scanned contained at least one vuln, while on average it said there were 37 vulns per database across its UK sample – though if the sample included more than a handful of abandoned DBs (say, a SQL database powering a long-forgotten discussion forum or blog) this could easily skew the average vulns-per-database figure.

"This indicates that many organizations are not prioritizing the security of their data and neglecting routine patching exercises," said Imperva in its report summary, adding that "some CVEs have gone unaddressed for three or more years."

Brazil was the country that came out best in the study, with just 19 per cent of databases containing one or more vulns and an average of 14 per database scanned. The US sat just below the average, with 37 per cent of databases containing a vulnerability and 25 holes per database on average.

[8]

"Regional analysis uncovers significant disparities between nations, with countries such as France (84 per cent), Australia (65 per cent), and Singapore (64 per cent) having much higher incidences of insecure databases," concluded Imperva. "However, for countries such as Germany and Mexico, while the number of insecure databases is relatively low, those that are vulnerable are well above the average when it comes to the number of vulnerabilities capable of exploitation."

Unauthorised access to databases by malicious people can have consequences that reverberate for aeons, relatively speaking: the 2015 hack of Slack was [9]behind a wave of forced password resets four years later . Similarly, a UK energy firm called People's Energy confessed that retail and business customers alike [10]had their information stolen by criminals last December.

If you're responsible for one of these common targets for digital criminals, it's worth double-checking you've fully patched it. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUDHQRbSsbNXdASzidkCagAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUDHQRbSsbNXdASzidkCagAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUDHQRbSsbNXdASzidkCagAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/09/08/open_source_beyond_the_programmers/

[5] https://www.theregister.com/2019/06/03/das_geeks_hit_crowdfunding_target/

[6] https://www.theregister.com/2021/09/09/azure_container_flaw/

[7] https://www.theregister.com/2021/09/08/google_spanner_json/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUDHQRbSsbNXdASzidkCagAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2019/07/19/2015_database_hack_slack/

[10] https://www.theregister.com/2020/12/17/peoples_energy_hacked/

[11] https://whitepapers.theregister.com/



Think of the databases

elsergiovolador

Given the authoritarianism is no longer something that is frowned upon by the current elites, and that they like to use fear and security as an excuse to advance the agenda of total control, it's not a far fetched idea that in not so distant future only the government will be allowed to run databases.

This means your tech company will have to apply for a database, state its purpose, what kind of data it is going to hold in and what RDMS system will be required and so on. Then company will get the keys and will be able to store e.g. customer data in a "secure" database to "protect" citizens, but everything will be looked after by dedicated agency and government will be able to see what the population is up to.

Re: Think of the databases

Wellyboot

Just to be clear, are you using the term 'elites' as a description for the self aggrandizing power hungry numpties and hangers on that we get to choose between at election time or the self aggrandizing power hungry numpties and hangers on that run big tech?

Re: Think of the databases

elsergiovolador

I mean both. They are intertwined. I am sure any of big tech companies would love to run such project - it will keep competition at bay, it will get extra revenue - possibly an opportunity for politicians to use tax payer money to subsidise those databases for "startups" and getting PR, they will have leverage when it comes to avoiding paying taxes (we know we don't pay tax, but we can also turn the lights off and what you gonna do?), more data to train AI... the list of mutual benefits is probably endless...

Port scan results

noisy_typist

So the universe if databases they have results for is those with an open and scannable port facing the internet... I would expect a basic security procedure in almost all cases would be to not do this.

So out of the set of databases exposed directly to the internet, just under half have critical vulnerabilities. I am surprised it's not higher.

Re: Port scan results

simkin

Seriously. The fact that a database is exposed to the Internet at all is a critical vulnerability.

On-premises databases tend to be more vulnerable

Warm Braw

They seem to have a [1]Cloud Data Security product nevertheless.

Bring back the good old days when a basement, a filing cabinet and a leopard (or threat thereof) was all you needed.

[1] https://www.imperva.com/products/cloud-data-security/

Fourth Law of Thermodynamics:
If the probability of success is not almost one, it is damn near zero.
-- David Ellis