News: 1705646646

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

IT consultant fined for daring to expose shoddy security

(2024/01/19)


A security researcher in Germany has been fined €3,000 ($3,300, £2,600) for finding and reporting an e-commerce database vulnerability that was exposing almost 700,000 customer records.

Back in June 2021, according to our pals at [1]Heise , an contractor identified elsewhere as Hendrik H. was troubleshooting software for a customer of IT services firm Modern Solution GmbH. He discovered that the Modern Solution code made an MySQL connection to a MariaDB database server operated by the vendor. It turned out the password to access that remote server was stored in plain text in the program file MSConnect.exe, and opening it in a simple text editor would reveal the unencrypted hardcoded credential.

With that easy-to-find password in hand, anyone could log into the remote server and access data belonging to not just that one customer of Modern Solution, but data belonging to all of the vendor's clients stored on that database server. That info is said to have included personal details of those customers' own customers. And we're told that Modern Solution's program files were available for free from the web, so truly anyone could inspect the executables in a text editor for plain-text hardcoded database passwords.

[2]

The contractor's findings were discussed in a June 23, 2021 [3]report by Mark Steier, who writes about e-commerce. That same day Modern Solution issued [4]a statement [PDF] – translated from German – summarizing the incident:

Today, June 23, 2021 at 8:09am, an 'ethical hacker' alerted us to a security vulnerability in our system. Due to this vulnerability, it was possible to access the password to our database and access unencrypted passwords and personal data. Using this database password, the hacker gained external access to our database and our ticketing system. We currently do not know to what extent this data was passed on or further used by the 'ethical hacker' and whether further access occurred. We are working intensively to investigate the incident.

The statement indicates that sensitive data about Modern Solution customers was exposed: last names, first names, email addresses, telephone numbers, bank details, passwords, and conversation and call histories. But it claims that only a limited amount of data – names and addresses – about shoppers who made purchases from these retail clients was exposed.

Steier contends that's incorrect and alleged that Modern Solution downplayed the seriousness of the exposed data, which he said included extensive customer data from the online stores operated by Modern Solution's clients.

[5]

[6]

In September 2021 police in Germany seized the IT consultant's computers following a complaint from Modern Solution that claimed he could only have obtained the password through insider knowledge – he worked previously for a related firm – and the biz claimed he was a competitor.

Hendrik H. was charged with unlawful data access under [7]Section 202a of Germany's Criminal Code, based on the rule that examining data protected by a password can be classified as a crime under the Euro nation's cybersecurity law.

[8]Microsoft suggests command line fiddling to get faulty Windows 10 update installed

[9]ShinyHunters chief phisherman gets 3 years, must cough up $5M

[10]MongoDB warns breach of internal systems exposed customer contact info

[11]Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

In June, 2023, a Jülich District Court in western Germany sided with the IT consultant because the Modern Solution software was insufficiently protected. But the Aachen regional court directed the district court to hear the complaint. Now, the district court has reversed its initial decision. On January 17, a Jülich District Court fined Hendrik H. and directed him to pay court costs.

"The penalty order is all the more shocking because it is fundamentally wrong," [12]wrote Steier, the blogger who helped bring the exposed database to light, in a post on Wednesday.

[13]

"A password that has been saved almost in plain text does not constitute a 'special security' which is required by §202. It's understandable that a judge can't evaluate that, but then an expert would have had to be heard on exactly this question. Unfortunately that didn't happen."

According to [14]reports , the verdict is not yet legally binding as the two parties have a week to appeal, which the IT consultant reportedly intends to do.

In a [15]post to Mastodon, Wladimir Palant, a security researcher, software developer, and co-founder of Germany-based ad filtering biz eyeo, expressed frustration with the court's decision.

[16]

"I very much hope that there will be a next instance ruling overturning this decision again," Palant wrote. "But it’s exactly as people feared: no matter how flawed the supposed 'protection,' its mere existence turns security research into criminal hacking under the German law. This has a chilling effect on legitimate research, allowing companies to get away with inadequate security and in the end endangering users." ®

Get our [17]Tech Resources



[1] https://www.heise.de/news/Datenleck-Anzeige-gegen-IT-Experte-kam-von-Modern-Solution-6254839.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZapWX0-sXZ8HhC9tuKDD@gAAAYg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://wortfilter.de/warnung-datenleck-beim-jtl-partner-modern-solution-gmbh-co-kg/

[4] https://wortfilter.de/wp-content/uploads/2021/06/moso-1.pdf

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZapWX0-sXZ8HhC9tuKDD@gAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZapWX0-sXZ8HhC9tuKDD@gAAAYg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.gesetze-im-internet.de/stgb/__202a.html

[8] https://www.theregister.com/2024/01/12/microsoft_update_for_bitlocker_vuln/

[9] https://www.theregister.com/2024/01/10/shinyhunters_kingpin_prison/

[10] https://www.theregister.com/2023/12/18/infosec_in_brief/

[11] https://www.theregister.com/2023/12/08/five_eyes_star_blizzard_warning/

[12] https://wortfilter.de/entdecker-des-datenlecks-modern-solution-heute-vor-gericht/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZapWX0-sXZ8HhC9tuKDD@gAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://www.heise.de/news/Warum-ein-Sicherheitsforscher-im-Fall-Modern-Solution-verurteilt-wurde-9601392.html

[15] https://infosec.exchange/@WPalant/111776937550399546

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZapWX0-sXZ8HhC9tuKDD@gAAAYg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://whitepapers.theregister.com/



Could be worse

ldo

Imagine being [1]prosecuted and fined , not for password hacking, but just for typing “../../../” into your browser’s address bar.

[1] https://www.theregister.com/2005/10/11/tsunami_hacker_followup/

The problem is law is old and tech is new

heyrick

When non-nerdy judges meet people arguing over tech things, those mystical boxes of woo-woo that are never wrong (*), it can be hard for them to sort out who is culpable. If the guy had the password then clearly he took it from somewhere, right? The idea of dropping a file into an editor and reading a plaintext password built into it would be little more than gibberish.

Maybe courts attending to tech matters should be obliged to demonstrate a prior level of understanding of the sorts of issues that could arise?

* - one word: Horizon.

Re: The problem is law is old and tech is new

Yorick Hunt

Summarised perfectly by the astoundingly insightful Not the Nine O'Clock News team, all those years ago...

https://youtu.be/9VgwxKW0J6I

Re: The problem is law is old and tech is new

KittenHuffer

I knew exactly which clip that link was for. Still went for a view cos it still makes me laugh 40 years later!

Re: Summarised perfectly

sabroni

Missing the point completely by the astoundingly popular Not the Nine O'Clock News team, all those years ago...

If you understand how courts work you know that judges are required to ask these kinds of questions to make sure the jury understand what is going on.

Re: The problem is law is old and tech is new

Oh Matron!

I thought this was the Tory back bench for a moment!

Great clip!

Re: The problem is law is old and tech is new

Anonymous Coward

In that specific case, it doesn't seem to be a problem with the law, but rather with the judges themselves. Remember that the first decision was found in favor of the consultant.

The second one is very unlikely to stand. Let's be patient and keep an eye on the evolution of the case. Hoping that ElReg will report again, even if the appeal decision is not shocking as this one is.

Re: The problem is law is old and tech is new

Blazde

The problem is geeky types like to find pedantic reasons why a password isn't a password but judges are wise and usually old, and the law older still, so they see straight though it. Nobody is not calling it a password because it is one, and a straightforward translation to bricks-and-mortar ethics says you don't have permission to go inside someone's house just because you find their front door key lying around outside for anyone to access. I'm not at all familiar with the interpretation and nuance of German law but a quick glance at the code in question says you shouldn't try to use passwords you know you don't have permission to use, regardless of how you came across them, and how tempting it is.

It is harsh, and very arguably the company should be prosecuted for terrible security practice too, but you can see in an age where there's a legal responsibility to report data breaches an ethical hacker creating a data breach in many cases won't be that much less of a headache that a non-ethical one doing it.

Re: The problem is law is old and tech is new

jmch

"straightforward translation to bricks-and-mortar ethics"

I pass by a warehouse where the key is stuck in the lock on the door outside. I open the door to go inside and shout "Hallo, anyone there? You left the key in the lock!!". What that would usually result in is a "Gosh, thanks, I forgot that" - not a police report for trespass, and certainly not even a prosecution let alone a conviction.

Re: The problem is law is old and tech is new

Blazde

"Hallo, anyone there"... No one is there. So you take it upon yourself to rummage through a filing cabinet containing 'extensive customer data from the online stores operated by Modern Solution's clients'.

Is that okay? Or should a genuine security researcher be expected to know when to curb their curiosity?

An only slightly generous reading of the law says he might have been okay if he'd connected to the database, thus confirming the password worked, and then immediately disconnected without even listing any tables etc. That would be closer to your scenario.

Re: The problem is law is old and tech is new

Anonymous Coward

One would like to think that in similar cases that prosecution was not "in the public interest" but ....

Re: The problem is law is old and tech is new

simonlb

but a quick glance at the code in question says you shouldn't try to use passwords you know you don't have permission to use, regardless of how you came across them, and how tempting it is

So the law is saying, 'Just because you can, doesn't mean you should.'

But which is going to be worse in the long term?

1. Someone finding and using that plain text password to access the systems and potentially steal information which would critically affect that companies reputation and possibly cost them a lot of money?

2. Someone finding and using that plain text password to access the systems, recognising what has happened and going no further, and then telling that company they are doing their security wrong?

There's a serious lack of common sense here.

Re: The problem is law is old and tech is new

Blazde

If you read the blog where the data was leaked it's clear there is an attempt to damage the company's reputation. It's not clear what the relationship between the security researcher and the blogger is, but you can kinda see where the paranoia about a competitor comes from or at least why that becomes a plausible smear the company then uses.

I suspect it's more likely just typical hacker hubris ('Haha we pwned you but it's okay because as well as telling the world about it and sharing screenshots of customer info, we also emailed you how we did it"). Personally I'm all for giving professional-acting security researchers some leeway, ideally written into law (in the UK the public interest test is probably sufficient, except for the thorny issue of Post Office style private prosecutions), but clearly there has to be limits and where there are limits arrogant types will occasionally cross those limits.

Re: The problem is law is old and tech is new

Doctor Syntax

And regarding Horizon, just read what a judge is capable of understanding, at least is expert witnesses have provided evidence:

https://www.judiciary.uk/wp-content/uploads/2022/07/bates-v-post-office-appendix-1-1.pdf

Not Surprised

Will Godfrey

Remember folks, the first thing we do is shoot the messenger.

claimed

I feel like the word “reasonable” needs to get into these laws. Is it reasonable for me to be able to type admin/admin on my ISP page to make sure they’re not fucking idiots and my data is safe (ish)? I think so. Does it constitute hacking to go down to my local council office and walk in the front door without an appointment? No. It’s not breaking and entering if all I have to do is push the door open, that’s a failure of the institution to secure the important public assets.

Where we draw the line on reasonable, is what judges are for, but we can’t just have: you were not authorized therefore you’re a criminal. If I didn’t see any indication of security that would prevent me from walking in, how was I to know I wasn’t allowed? If there is a note by the door that says “door code is 1111”, I mean, I just think a receptionist has left that there as they can’t be assed to open the door. You’re telling me I’m not allowed to read a note and make a reasonable interpretation?

If I found a text password in a dodgy exe, who’s to say I can’t save myself a heap of trouble and just bypass that exe to get *my* data without all the trouble? If I didn’t know the origin of the exe, I could well assume it was built specifically for the client who’s brought me in to make it work (get the data)!

What constitutes a password, by the definition of the law? admin/admin is secure then? or would the judge call me a criminal for that specialist hacking knowledge?

Lipdorn

Bit different from walking into a building. I think one can reasonable expect the local community to adhere to the principle that they shouldn't enter unauthorized areas. One can also, obviously, apprehend and prosecute such people easier if they're in your jurisdiction.

With the internet you are exposed to all walks of life. Including those from enemy countries over whom you might have no jurisdiction. Not like anyone can do much about North Korean hackers. In this case, one should reward people that identify vulnerabilities in your systems (assuming they did not exploit those vulnerabilities).

In my opinion, this is how one can identify companies that actually care about security and those that just do the bare minimum required by law.

Blazde

assuming they did not exploit those vulnerabilities

He did that though, that was his mistake.

Anonymous Anti-ANC South African Coward

This reminds me of the "Johannesburg job" - city of Johannesburg's billing system had a flaw (URL manipulation) which was not fixed even when reported.

Chap who discovered it, went public with the knowledge, and a whole host of curious types visited the CoJ website and had a shufty at the URL manipulation thing. In desperation CoJ shut the webserver down.

City threatened with legal and court action, but nothing came of it.

But they fixed the vulnerability.

Seems like security consultants now have to toss a coin and decide on whether to report a vulnerability and risk getting taken to court, or keep quiet about it and hope it never get abused...

Pascal Monett

Well it certainly seems that security consultants in Germany will need a signed contract from their client giving them permission to do a security review of their website.

Given how Modern Solution reacted in a very Dark Ages way, I doubt that that would happen.

So the solution is triple the fines for companies who shoot the messenger, then get their databases hacked by some miscreant.

Necrohamster

If a district court in Germany is similar to anywhere else, they deal with low-level everyday stuff like speeding tickets and shoplifting. I'd hardly expect a district court judge to have a grasp of IT security, although FTA it seems like they made the correct decision (for whatever reason) originally but a higher court told them to look again.

Time for an appeal...although appeals cost money.

Pascal Monett

The higher court looked again, but forgot to ask the right questions.

I sincerely hope that the appeal will succeed, that Modern Solutions will be found guilty of negligence and fined for all court costs and an indemnity for abusing the hacker's good faith.

Wait, what?

peteC7x

Screw them then. Next time just post the damn thing somewhere and let them get screwed. This is what happens when good people try to the right thing. No more mr nice guy!

Modern Solutions?

Michael H.F. Wilkinson

Modern Screw-up, more likely. They can hardly claim blaming the messenger is modern, after all

"Where shall I begin, please your Majesty?" he asked. "Begin at the
beginning," the King said, gravely, "and go on till you come to the end: then
stop."
Alice's Adventures in Wonderland, Lewis Carroll