Welcome Guest ( Log In | Register )

3 Pages  1 2 3 >Bottom

Outline · [ Standard ] · Linear+

> Major data breach uncovered in Ministry of Educati

views
     
TSFatalExe
post Jun 9 2018, 04:32 PM, updated 8y ago

On my way
****
Senior Member
695 posts

Joined: Jan 2008


PETALING JAYA: The Education Ministry's online school examination analysis system, Sistem Analisis Peperiksaan Sekolah (SAPS), sapsnkra.moe.gov.my/ibubapa2/index.php), has been taken down.

The Star received an anonymous e-mail claiming that the site, introduced in July 2011 to centralise examination results from all states, is vulnerable to an attack called SQL Injection.

This technique, according to the tip-off, allows an attacker to retrieve student data stored on the site, covering approximately 10,000 national primary schools and secondary schools.

The e-mail alleged that 4.9 million student details, along with their parents' MyKad numbers, could be compromised. The e-mail also carried a large attachment containing multiple text files with what looked like student records.


The anonymous sender claimed to have reached out to the ministry.

Cyber security responsive services senior vice president for CyberSecurity Malaysia, Dr Aswami Ariffin, said this exploit is simple to take advantage of since the connection to the site is unsecure.

"So to mitigate, the system owner must reconfigure the system with a secure connection. This setup is compulsory especially when it involves database at the backend," he said.

However, he said, while CyberSecurity Malaysia is a trusted government agency that would be able to assist in securing government websites, it is up to the system owner to engage its services.

"It is advisable for the system owner to conduct a web penetration test so that the security weaknesses could be uncovered and reconfigured," he said.

The e-mail also claimed that the site suffered from other problems, including passwords being stored in plain text, adding that most users used simple passwords such as 1234567.

"Any website today should go through vulnerability assessment prior to launch. No new website will be vulnerable to SQL injection attack if vulnerability assessment and fixes are done properly," said IT security services company LGMS founder CF Fong.

He claimed that government websites are prone to attacks because the necessary security measures are usually not taken.

"Common issues we had in the previous administration was that security assessments were not done, or were outsourced to unqualified vendors," said Fong.

The SAPS aims to measure students' academic performance and enable better administration.

Teachers are required to key in students' examination and test results into this database, allowing parents to have real-time access to their children's academic results.

https://www.thestar.com.my/news/nation/2018...nalysis-system/
DValentine
post Jun 9 2018, 04:34 PM

Enthusiast
*****
Junior Member
773 posts

Joined: Dec 2010
From: isudahinsap.flac


pakar it mali explain sql injection

cikai website maintained by cikai admin

satu lagi projek kerajaan barisan nasional


SAY IT PROUDLY

This post has been edited by DValentine: Jun 9 2018, 04:36 PM
acbc
post Jun 9 2018, 04:37 PM

Look at all my stars!!
*******
Senior Member
9,048 posts

Joined: Jan 2003
Hire amateurs to set up websites sure use simple passwords or settings.
SUSmooney
post Jun 9 2018, 04:39 PM

Getting Started
**
Junior Member
180 posts

Joined: Dec 2011
From: Gingerbread house


Wawasan 2020
SUSmemekfalui
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
245 posts

Joined: Oct 2004


Berapa Kali Kali Kali subcon sampai budak rempit jaga site

Hidup BN
ZerOne01
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
124 posts

Joined: Feb 2007
From: Pahang




QUOTE(DValentine @ Jun 9 2018, 04:34 PM)
pakar it mali explain sql injection
*
tl;dr getting database records without the need of proper access by inserting commands into unsecured/unprotected text fields or address bar.

This post has been edited by ZerOne01: Jun 9 2018, 04:46 PM
OldSchoolJoke
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
username: admin
password: admin
tictac88
post Jun 9 2018, 04:42 PM

Getting Started
**
Junior Member
191 posts

Joined: Apr 2016
die lah breach here breach there no more secret liao. soon we will find out how sadsoul really look like
ZeroSOFInfinity
post Jun 9 2018, 04:47 PM

Look at all my stars!!
*******
Senior Member
3,703 posts

Joined: Oct 2005


QUOTE(OldSchoolJoke @ Jun 9 2018, 04:40 PM)
username: admin
password: admin
*
Too hard. It's actually....

username: BN
password: 123
statikinetic
post Jun 9 2018, 04:48 PM

BaneCat
*******
Senior Member
2,940 posts

Joined: Jan 2010
WTF something as basic as SQL injection also not covered ah....

Like can build a house but tak pasang pintu.
OldSchoolJoke
post Jun 9 2018, 04:49 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
QUOTE(tictac88 @ Jun 9 2018, 04:42 PM)
die lah breach here breach there no more secret liao. soon we will find out how sadsoul really look like
*
hope lowyat got breach so we know whose dupe belong to who.
Kedekut
post Jun 9 2018, 04:49 PM

Getting Started
**
Junior Member
140 posts

Joined: May 2009
QUOTE(FatalExe @ Jun 9 2018, 04:32 PM)
This technique, according to the tip-off, allows an attacker to retrieve student data stored on the site, covering approximately 10,000 national primary schools and secondary schools.

The e-mail alleged that 4.9 million student details, along with their parents' MyKad numbers, could be compromised. The e-mail also carried a large attachment containing multiple text files with what looked like student records.


The e-mail also claimed that the site suffered from other problems, including passwords being stored in plain text, adding that most users used simple passwords such as 1234567.
*
This is bad. blink.gif doh.gif
lawliet88
post Jun 9 2018, 04:50 PM

Enthusiast
*****
Junior Member
993 posts

Joined: May 2010
From: Cheras For PPL to Live 1


LOL not even simple encryption for password
iskull
post Jun 9 2018, 04:50 PM

Getting Started
**
Junior Member
66 posts

Joined: Jun 2016
thats what happen when money kene songlap kerja bagi intern buat
ChessRook
post Jun 9 2018, 04:52 PM

Casual
***
Junior Member
375 posts

Joined: Mar 2018
Why don't have server side validation and encryption of password. No strong password enforcement when user register? Who actually got the contract? Is this open tender?
DValentine
post Jun 9 2018, 04:52 PM

Enthusiast
*****
Junior Member
773 posts

Joined: Dec 2010
From: isudahinsap.flac


QUOTE(memekfalui @ Jun 9 2018, 04:40 PM)
Berapa Kali Kali Kali subcon sampai budak rempit jaga site

Hidup BN
*
SCREAM IT

SATU LAGI PROJEK KERAJAAN BARISAN NASIONAL

repeat 3 times
DarkNite
post Jun 9 2018, 04:59 PM

ФĻĐ ИΞШB!Ξ
********
All Stars
11,058 posts

Joined: Jun 2008
QUOTE(iskull @ Jun 9 2018, 04:50 PM)
thats what happen when money kene songlap kerja bagi intern buat
*
Songlap!
Jgn x songlap!
Dulu, kini and..... Oh wait!. laugh.gif
petirbuas
post Jun 9 2018, 05:12 PM

( 。◕ ‿‿ ◕。)
*****
Senior Member
898 posts

Joined: Dec 2009
From: The Internet



QUOTE(ChessRook @ Jun 9 2018, 04:52 PM)
Why don't have server side validation and encryption of password. No strong password enforcement when user register? Who actually got the contract? Is this open tender?
*
lol u know they subcon like crazy and the work is being done by freshie right?

They're not even doing this secretly.
RicoT
post Jun 9 2018, 05:17 PM

Getting Started
**
Junior Member
200 posts

Joined: Feb 2009
So will be responsible when rich fag kids kena kidnap because of all the information?
kerolzarmyfanboy
post Jun 9 2018, 05:26 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
im surprised nobody sue any of them using PDPA... quick cash yo

3 Pages  1 2 3 >
Bump Topic Add ReplyOptions New Topic
 

Change to:
| Lo-Fi Version
0.0157sec    0.56    6 queries    GZIP Disabled
Time is now: 11th December 2025 - 05:22 AM