Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

> Major data breach uncovered in Ministry of Educati

views
     
TSFatalExe
post Jun 9 2018, 04:32 PM, updated 8y ago

On my way
****
Senior Member
695 posts

Joined: Jan 2008


PETALING JAYA: The Education Ministry's online school examination analysis system, Sistem Analisis Peperiksaan Sekolah (SAPS), sapsnkra.moe.gov.my/ibubapa2/index.php), has been taken down.

The Star received an anonymous e-mail claiming that the site, introduced in July 2011 to centralise examination results from all states, is vulnerable to an attack called SQL Injection.

This technique, according to the tip-off, allows an attacker to retrieve student data stored on the site, covering approximately 10,000 national primary schools and secondary schools.

The e-mail alleged that 4.9 million student details, along with their parents' MyKad numbers, could be compromised. The e-mail also carried a large attachment containing multiple text files with what looked like student records.


The anonymous sender claimed to have reached out to the ministry.

Cyber security responsive services senior vice president for CyberSecurity Malaysia, Dr Aswami Ariffin, said this exploit is simple to take advantage of since the connection to the site is unsecure.

"So to mitigate, the system owner must reconfigure the system with a secure connection. This setup is compulsory especially when it involves database at the backend," he said.

However, he said, while CyberSecurity Malaysia is a trusted government agency that would be able to assist in securing government websites, it is up to the system owner to engage its services.

"It is advisable for the system owner to conduct a web penetration test so that the security weaknesses could be uncovered and reconfigured," he said.

The e-mail also claimed that the site suffered from other problems, including passwords being stored in plain text, adding that most users used simple passwords such as 1234567.

"Any website today should go through vulnerability assessment prior to launch. No new website will be vulnerable to SQL injection attack if vulnerability assessment and fixes are done properly," said IT security services company LGMS founder CF Fong.

He claimed that government websites are prone to attacks because the necessary security measures are usually not taken.

"Common issues we had in the previous administration was that security assessments were not done, or were outsourced to unqualified vendors," said Fong.

The SAPS aims to measure students' academic performance and enable better administration.

Teachers are required to key in students' examination and test results into this database, allowing parents to have real-time access to their children's academic results.

https://www.thestar.com.my/news/nation/2018...nalysis-system/
DValentine
post Jun 9 2018, 04:34 PM

Enthusiast
*****
Junior Member
773 posts

Joined: Dec 2010
From: isudahinsap.flac


pakar it mali explain sql injection

cikai website maintained by cikai admin

satu lagi projek kerajaan barisan nasional


SAY IT PROUDLY

This post has been edited by DValentine: Jun 9 2018, 04:36 PM
acbc
post Jun 9 2018, 04:37 PM

Look at all my stars!!
*******
Senior Member
9,048 posts

Joined: Jan 2003
Hire amateurs to set up websites sure use simple passwords or settings.
SUSmooney
post Jun 9 2018, 04:39 PM

Getting Started
**
Junior Member
180 posts

Joined: Dec 2011
From: Gingerbread house


Wawasan 2020
SUSmemekfalui
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
245 posts

Joined: Oct 2004


Berapa Kali Kali Kali subcon sampai budak rempit jaga site

Hidup BN
ZerOne01
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
124 posts

Joined: Feb 2007
From: Pahang




QUOTE(DValentine @ Jun 9 2018, 04:34 PM)
pakar it mali explain sql injection
*
tl;dr getting database records without the need of proper access by inserting commands into unsecured/unprotected text fields or address bar.

This post has been edited by ZerOne01: Jun 9 2018, 04:46 PM
OldSchoolJoke
post Jun 9 2018, 04:40 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
username: admin
password: admin
tictac88
post Jun 9 2018, 04:42 PM

Getting Started
**
Junior Member
191 posts

Joined: Apr 2016
die lah breach here breach there no more secret liao. soon we will find out how sadsoul really look like
ZeroSOFInfinity
post Jun 9 2018, 04:47 PM

Look at all my stars!!
*******
Senior Member
3,703 posts

Joined: Oct 2005


QUOTE(OldSchoolJoke @ Jun 9 2018, 04:40 PM)
username: admin
password: admin
*
Too hard. It's actually....

username: BN
password: 123
statikinetic
post Jun 9 2018, 04:48 PM

BaneCat
*******
Senior Member
2,940 posts

Joined: Jan 2010
WTF something as basic as SQL injection also not covered ah....

Like can build a house but tak pasang pintu.
OldSchoolJoke
post Jun 9 2018, 04:49 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
QUOTE(tictac88 @ Jun 9 2018, 04:42 PM)
die lah breach here breach there no more secret liao. soon we will find out how sadsoul really look like
*
hope lowyat got breach so we know whose dupe belong to who.
Kedekut
post Jun 9 2018, 04:49 PM

Getting Started
**
Junior Member
140 posts

Joined: May 2009
QUOTE(FatalExe @ Jun 9 2018, 04:32 PM)
This technique, according to the tip-off, allows an attacker to retrieve student data stored on the site, covering approximately 10,000 national primary schools and secondary schools.

The e-mail alleged that 4.9 million student details, along with their parents' MyKad numbers, could be compromised. The e-mail also carried a large attachment containing multiple text files with what looked like student records.


The e-mail also claimed that the site suffered from other problems, including passwords being stored in plain text, adding that most users used simple passwords such as 1234567.
*
This is bad. blink.gif doh.gif
lawliet88
post Jun 9 2018, 04:50 PM

Enthusiast
*****
Junior Member
993 posts

Joined: May 2010
From: Cheras For PPL to Live 1


LOL not even simple encryption for password
iskull
post Jun 9 2018, 04:50 PM

Getting Started
**
Junior Member
66 posts

Joined: Jun 2016
thats what happen when money kene songlap kerja bagi intern buat
ChessRook
post Jun 9 2018, 04:52 PM

Casual
***
Junior Member
375 posts

Joined: Mar 2018
Why don't have server side validation and encryption of password. No strong password enforcement when user register? Who actually got the contract? Is this open tender?
DValentine
post Jun 9 2018, 04:52 PM

Enthusiast
*****
Junior Member
773 posts

Joined: Dec 2010
From: isudahinsap.flac


QUOTE(memekfalui @ Jun 9 2018, 04:40 PM)
Berapa Kali Kali Kali subcon sampai budak rempit jaga site

Hidup BN
*
SCREAM IT

SATU LAGI PROJEK KERAJAAN BARISAN NASIONAL

repeat 3 times
DarkNite
post Jun 9 2018, 04:59 PM

ФĻĐ ИΞШB!Ξ
********
All Stars
11,058 posts

Joined: Jun 2008
QUOTE(iskull @ Jun 9 2018, 04:50 PM)
thats what happen when money kene songlap kerja bagi intern buat
*
Songlap!
Jgn x songlap!
Dulu, kini and..... Oh wait!. laugh.gif
petirbuas
post Jun 9 2018, 05:12 PM

( 。◕ ‿‿ ◕。)
*****
Senior Member
898 posts

Joined: Dec 2009
From: The Internet



QUOTE(ChessRook @ Jun 9 2018, 04:52 PM)
Why don't have server side validation and encryption of password. No strong password enforcement when user register? Who actually got the contract? Is this open tender?
*
lol u know they subcon like crazy and the work is being done by freshie right?

They're not even doing this secretly.
RicoT
post Jun 9 2018, 05:17 PM

Getting Started
**
Junior Member
200 posts

Joined: Feb 2009
So will be responsible when rich fag kids kena kidnap because of all the information?
kerolzarmyfanboy
post Jun 9 2018, 05:26 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
im surprised nobody sue any of them using PDPA... quick cash yo
alanyuppie
post Jun 9 2018, 05:31 PM

Look at all my stars!!
*******
Senior Member
2,834 posts

Joined: Jul 2006
From: here


Hmmm...


Attached thumbnail(s)
Attached Image
LamboSama
post Jun 9 2018, 05:33 PM

Enthusiast
*****
Junior Member
769 posts

Joined: Aug 2011
So many cyber breach yet still got dumbass thinks entry/exit keeping people's fingerprint is a good idea. laugh.gif
QUOTE(kerolzarmyfanboy @ Jun 9 2018, 05:26 PM)
im surprised nobody sue any of them using PDPA... quick cash yo
*
This is not murica. Confirm no win.
Or else govt already take action laugh.gif
teehk_tee
post Jun 9 2018, 05:35 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

Salah maszlee?
annoymous1234
post Jun 9 2018, 05:36 PM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

telco, and then astro, now this. malaysia boleh!
dagnarus
post Jun 9 2018, 05:38 PM

Casual
***
Junior Member
328 posts

Joined: Jul 2008


Habisla, my data andy kids data sudah kena. Bodo punya it contractor
haturaya
post Jun 9 2018, 05:40 PM

Look at all my stars!!
Group Icon
Elite
2,554 posts

Joined: Jan 2003
QUOTE(acbc @ Jun 9 2018, 04:37 PM)
Hire amateurs to set up websites sure use simple passwords or settings.
*
sub-sub-subcon to intern. Nuf said. whistling.gif
Kedekut
post Jun 9 2018, 05:54 PM

Getting Started
**
Junior Member
140 posts

Joined: May 2009
QUOTE(RicoT @ Jun 9 2018, 05:17 PM)
So will be responsible when rich fag kids kena kidnap because of all the information?
*
More HT and scams too.

This post has been edited by Kedekut: Jun 9 2018, 05:55 PM
crumpetss
post Jun 9 2018, 05:57 PM

dummie
****
Senior Member
523 posts

Joined: Aug 2017
From: some place

what dafark
SQL Injection????
bruh
ChessRook
post Jun 9 2018, 06:12 PM

Casual
***
Junior Member
375 posts

Joined: Mar 2018
QUOTE(petirbuas @ Jun 9 2018, 05:12 PM)
lol u know they subcon like crazy and the work is being done by freshie right?

They're not even doing this secretly.
*
bye.gif there goes my tax money
billylks
post Jun 9 2018, 06:17 PM

Getting Started
**
Junior Member
180 posts

Joined: May 2010


Lol still got SQL injection ka nowadays?

Must be .net programmers.

Edited: oh php programmers

This post has been edited by billylks: Jun 9 2018, 06:18 PM
D-Frog
post Jun 9 2018, 06:19 PM

Look at all my stars!!
*******
Senior Member
2,983 posts

Joined: Nov 2011
QUOTE(petirbuas @ Jun 9 2018, 05:12 PM)
lol u know they subcon like crazy and the work is being done by freshie right?

They're not even doing this secretly.
*
Freshie like me know there is existing libraries to encrypt the password on the server side.
LOL.
So many existing libraries to prevent such things from happening.
cj7
post Jun 9 2018, 06:28 PM

Casual
***
Junior Member
357 posts

Joined: Mar 2008
cyber security malaysia.. fail something as basic as sql injection. I wouldn't surprise if telco data breached happen to be same cause.
k!nex
post Jun 9 2018, 06:29 PM

Restless stars
*******
Senior Member
3,389 posts

Joined: Mar 2007
From: KL


QUOTE(DValentine @ Jun 9 2018, 04:34 PM)
pakar it mali explain sql injection

cikai website maintained by cikai admin

satu lagi projek kerajaan barisan nasional
SAY IT PROUDLY
*
The commoner no need to know the details. It is enough to know that a hacker can manipulate student marks due to this vulnerability. Full stop.
Quantum Geist
post Jun 9 2018, 06:37 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(billylks @ Jun 9 2018, 06:17 PM)
Lol still got SQL injection ka nowadays?

Must be .net programmers.

Edited: oh php programmers
*
In dot net if use entity framework should prevent against sql injections. I bet the php code is running on and old version pre mysqli and pdo, or tge coder only knows how to use insecure mysql functions
TruboXL
post Jun 9 2018, 07:24 PM

Keep on keeping on! 👍
******
Senior Member
1,050 posts

Joined: Jan 2016
From: Land of floods, Kota Tinggi


lol its okay just bunch not yet fb legal kids information leaked
arubin
post Jun 9 2018, 07:58 PM

Holy Pastafarian
****
Senior Member
670 posts

Joined: Oct 2007
From: Church of the Flying Spaghetti Monster


QUOTE(OldSchoolJoke @ Jun 9 2018, 04:40 PM)
username: admin
password: admin
*
QUOTE(ZeroSOFInfinity @ Jun 9 2018, 04:47 PM)
Too hard. It's actually....

username: BN
password: 123
*
SQL injection got nothing to do with username lar.

This xkcd comic explains it perfectly:
user posted image
olman
post Jun 9 2018, 08:00 PM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


Isnt most of gomen websites horrendous with security?

Nothing shocking, even loliyat harum site is safer lol

This post has been edited by olman: Jun 9 2018, 08:00 PM
zamanjaafar
post Jun 9 2018, 08:04 PM

NOT DUPIN' SINCE '03
******
Senior Member
1,122 posts

Joined: Jan 2003


Kerajaan PH ambil alih terus ada data breach

#BringBackBN
Ewww!
post Jun 10 2018, 01:17 AM

Look at all my stars!!
*******
Senior Member
2,033 posts

Joined: Jul 2016
From: Lol!




Ok fine, let's blame the Jews. Lol!
ctrl_alt_del
post Jun 10 2018, 01:24 AM

On my way
****
Senior Member
607 posts

Joined: Jan 2005


This is why, schools should never be allowed to use any online system. You only need a chalk, a pen, a blackboard and books.
mafioso
post Jun 10 2018, 01:31 AM

 
*******
Senior Member
6,155 posts

Joined: Jul 2012
From: Today, 00:01 AM
QUOTE(cuckoobird @ Jun 9 2018, 04:38 PM)
SELECT NAME FROM TABLE1;
ORDER BY NAME
*
DELETE FROM student_loans where STATUS=1












This post has been edited by mafioso: Jun 10 2018, 01:31 AM
pandah
post Jun 10 2018, 01:34 AM

Enthusiast
*****
Senior Member
719 posts

Joined: Jul 2011

dont even have secure connection meh

inb4 sudah bayar berbillion develop website wey
xperiaVuser
post Jun 10 2018, 01:54 AM

Regular
******
Senior Member
1,201 posts

Joined: Jul 2013
laugh.gif laugh.gif nothing to see

This post has been edited by xperiaVuser: Jun 10 2018, 02:51 AM
tareh
post Feb 7 2019, 10:45 AM

Getting Started
**
Junior Member
131 posts

Joined: Apr 2008


i have to put this out here.

my company was involved in a huge exercise in implementing SIEM (google that) in sensitive government agency to circumvent hacks, breeches, compromising third party apps/system/, etc etc. problem was, after dah built the war room and everything - sure can start seeing where were the holes was, mana network components yang tak hardened, the govt it self has no SOP or how-to to fix these holes. the easiest was to tutup the server yg compromised but nobody knows how to fix server without formatting the whole damn thing. itu senang, kalau network yg dah kena hack, jadi watering hole, they damn blur dont know what to do. so every night we can see la, like a bunch of data sampai 1GB keluar from the network to god knows where to god knows who. ada report but they themselves damn blur dont know what to do.

the new govt lagi champion, they suruh take down the SIEM. habis.

belum lagi targeted spoofing attack. but thats a story for another day.

This post has been edited by tareh: Feb 7 2019, 10:47 AM
SUSNachiino Etamay
post Feb 7 2019, 11:00 AM

Getting Started
**
Junior Member
93 posts

Joined: Aug 2014
takpalah

saya rasa ini salah opposition
JohnKekHow
post Feb 7 2019, 11:03 AM

Getting Started
**
Junior Member
155 posts

Joined: Mar 2015


QUOTE(tareh @ Feb 7 2019, 10:45 AM)
i have to put this out here.

my company was involved in a huge exercise in implementing SIEM (google that) in sensitive government agency to circumvent hacks, breeches, compromising third party apps/system/, etc etc. problem was, after dah built the war room and everything - sure can start seeing where were the holes was, mana network components yang tak hardened, the govt it self has no SOP or how-to to fix these holes. the easiest was to tutup the server yg compromised but nobody knows how to fix server without formatting the whole damn thing. itu senang, kalau network yg dah kena hack, jadi watering hole, they damn blur dont know what to do. so every night we can see la, like a bunch of data sampai 1GB keluar from the network to god knows where to god knows who. ada report but they themselves damn blur dont know what to do.

the new govt lagi champion, they suruh take down the SIEM. habis.

belum lagi targeted spoofing attack. but thats a story for another day.
*
What SIEM u use? QRadar? Archsight?
J1g54w
post Feb 7 2019, 11:07 AM

Regular
******
Senior Member
1,449 posts

Joined: Jul 2015
don't expect uproar because nobody gives af... that time Malaysian telco user data breached, almost whole population kena... name, IC, address, phone number, all leaked

nobody cared. in developed country, the whole nation will sue the telcos kaw kaw.

Bump Topic Add ReplyOptions New Topic
 

Change to:
| Lo-Fi Version
0.0236sec    0.49    6 queries    GZIP Disabled
Time is now: 10th December 2025 - 06:23 PM