FTP Server at LSUHealth New Orleans
samsclass.info
samsclass.info
There are countless examples of people getting burned rather than rewarded or even thanked for bringing to attention some sort of flaw. My advice is do not bother. There is almost no upside for you and likely very significant downsides.
Second this motion. The number of vendors or administrators who respond well to security or privacy reports is tiny.
Some approximate data from my own emails. I've reported just over 120 security or privacy bugs over the past 4-5 years that this email address goes back (using my real name). I tag the emails, but searching "from:me vulnerability" brings them up. It is like a scoreboard of horrible vendors and site administrators.
From the most recent 100, there are around 25 with no reply at all. I know that some of those, such as government sites were followed up on the phone. Of those with a "(1)" in the thread meaning an additional message, most are me sending a reminder or trying to work out who to contact.
There are then a group of replies where they confirm receipt of the email, but then never confirm the actual contents of what i've reported. Scanning the threads, this looks like another 30 or so emails.
Then there is the group who confirm or deny the bug or parts but get into prolonged technical arguments, with around a dozen threads stretching beyond 10+ emails into arguments about if it is a bug or not.
Last group is those who get the bugs fixed and respond well. In these cases there are only a very small number where the threads are short - most involve long conversations. Some of these are still open - I just reminded myself that I have an open privacy issue with a large web company that still hasn't been fixed. That thread is 30+ emails long.
Overall more than half either didn't reply or didn't confirm the bug (silently fixed or not). There is a messy middle full of long threads and replies that are full of frustration and then only a tiny number of reports where they just get fixed with minimal effort (and you know who these companies are).
There is not a single instance of a non-software company responding well to a bug report (usually from a custom web app), and that includes some well known brands (banks, etc.). The number of good experiences I could count on one hand.
In terms of vendors, recent examples are a 20+ email thread over 3 weeks debating a vendor about severity of a group of bugs (still ongoing), two reasonably well-known vendors with no reply and a well-known vendor who only fixed after more than a month.
You can work out before reporting an issue who the good vendors are. They have a page dedicated to security with contact info, a key and a proper reporting program (preferably with a bounty). With everyone else, you are working for free, wasting your time, not making the internet any more secure and run the risk of getting into trouble - in some countries that could involve legal trouble (there have been a number of raids as a result of security reports in Australia, and the government head of privacy here said there is no such things as a white hat report).
whole range of options, researchers usually find what they prefer and how they prefer to do it organically and opinions (broadly) tend to shift the longer you have been in the field.
To be clear, we have absolutely zero evidence that the IT staff at the hospital ever accused him of anything or claimed he did anything wrong. Apparently they didn't respond and tell him thanks, but given that they knew who it was, if the hospital thought it was a crime, surely they would have contacted the authorities.
In any case, neither article named the professor until he came forward, so I'm not sure how even the extremely mild misinterpretations of the case could be called libel, exactly.
All in all, this isn't exactly a cut-and-dried case of curious white-hat smeared by the government and media. There are plenty of those to go around. We needn't invent more.
[1] http://www.thenewsstar.com/story/news/local/2014/08/19/conwa...
[2] http://www.scmagazine.com/professor-hacks-university-health-...
http://samsclass.info/125/proj11/LSU-HIPAA2.pdf
I had the same initial question about why he was reacting so strongly but people sending letters to your college administration demanding action is something of an existential threat to someone who teaches ethical hacking.
I'd be pretty annoyed to see that written about me after I had emailed the server owners and informed them that they were hosting patients' personal data on an open ftp server. It'd merely be piss-poor coming from some random local newspaper, and we often tend to dismiss it because technology is complicated egghead stuff; but, this is a website that claims its audience is "IT Professionals" which makes it really irresponsible and the reporter ought to know better. caveat: Given that the professor's story is legit.
They removed that information from the site and probably no one with ill intent accessed it. However, the security situation at that institution would be in better shape today if there had been an open discussion about this leak and its implications. Because I didn't feel comfortable approaching decision makers about this without risking retaliation against me, that discussion never happened.
A student in Montreal was expelled after informing the college where he studied that there was a security flaw http://business.financialpost.com/2013/07/17/montreal-studen...
http://news.nationalpost.com/2013/01/20/youth-expelled-from-...
But if you suspect you could get burned for pointing it out, you can take steps to mitigate it. Anonymity for example. Then again if you are in it for the fame and recognition, getting burned is a risk you are taking out of vanity.
If I find a bug in a piece of software, or something misconfigured, I tend to report it and move on. I don't try to hide my identity before reporting it. A security vulnerability is just a bug or misconfiguration, that happens to be exploitable for nefarious purposes. The responsible thing to do is to notify those responsible, and anonymity doesn't help with that; they may need to follow up to ask questions to find out more details about it.
While there are some people in the security community who are prima donnas, who try to hype them selves and their exploits to gain recognition, this case does not appear to have anything to do with that. This is someone who sent a private email to those responsible, and then started seeing articles online and getting complaints emailed to his college about irresponsible hacking of other institutions websites in front of students.
The fact is that journalists today are too busy writing linkbait headlines and getting page clicks to bother with details like accuracy or ethics. Researchers need to look at stories like this one and realize that journalists are not your friends, even if they write nice things about you or hang out with you at parties.
This journalist probably thought he was doing this guy a favor by writing about him.
Most everyone looks the other way in this business and there's a large amount of lying about credentials & experience to land jobs.
Years ago I realised that security bug reporting is a painful experience at best, from about 2006 I decided I'd stop tracking and reporting software security bugs that I find, which while not the optimal solution has made my life a lot less stressful.
It's not clear to be that LSU is responsible for anything more than shitty security. It's possible that they told the newspaper lies, but it's also possible that they told them the truth and that the newspaper misreported. I think reporting them for a HIPAA retaliation may have been premature, unless you know more about this situation than you wrote on your site (as opposed to reporting a HIPAA violation, which this clearly is).
But best of luck going after the newspapers. I'm getting sick of these "journalists" making up lies about the central figures in their stories without bothering to even check with them first to get their side of the story.
EDIT: Aaand, apparently, neither publication has an ombudsman, which tells you a lot already. Not a big surprise with SCMagazine, which is some kind of trade magazine, but it's too bad that even a small-circulation newspaper like the News Star wouldn't have one.
Management tells the lawyers and PR which forwards it to the "news" who just go for the most sensationalist story possible.
Hope he wins any lawsuit and more importantly his reputation back somehow.
I'm not even sure what would have been the better course here other than to have CC'ed other people on the email.
ps. No way in heck I am going to click on them but those filenames seem to appear in google cache elsewhere.
Unless lives are at stake due to the security lapse, it's pretty clear to me that the only reasonable response is to go "oh, that's interesting" and then close your browser window and never tell a soul.
edit - the folk saying that this guy was stupid for doing anything are completely irresponsible.
Naming and shaming typically gets some kind of a response. Keeping quiet does not.
I know not everyone agrees with full disclosure but I assert there is a time and a place, and after a demonstration like this one, IMO this university is one of those places.
Edit: typo
I mean aren't real journalists meant to check sources and get both sides of a story (or outside of America anyway)?
No, they are meant to sell as much ads as possible.
The journalists I know do indeed meet society's expectations for fairness and accuracy, and make calls and pound beats, but there are also a lot more people who project themselves as journalists who are a long way from this ideal. Sadly market pressures mean there are a lot of the latter about.
[1] the original article said it was an unnamed professor of Computer Science at City College
> At press time, Sam Bowne had not responded to a Thursday email and Friday phone call from SCMagazine.com for comment.
"Oh we meant it wasn't lost, as in it wasn't deleted off our servers!"
I've only encountered two non-respondents. Everyone else has thanked and patched within a month and I even gained employment from one encounter! Yet to get a reward, however I do this for a hobby, rather than money.
Although one day I hope to do this professionally! There isn't much work in New Zealand for it though.
EDIT: To clarify, my process is: report to vendor with suggested patches, follow-up 1 week later if no response, follow-up two weeks after response to see if it's patched, ask permission to use my bug report publicly. In some cases there'll be a phone call from the respondent to ask about my background and see what my intentions are. Occasionally they schedule a coffee/meeting.
As for the reporting side of this (note I did not use the word 'Journalism'...)..this is the quality level that has become the standard in the world of junk news. One must have the sensationalism in the title to get the click...that's it. The actual quality of the content is pretty much irrelevant..
As one example, if he describes a named or identifiable person as a "liar" online, the subject could sue for defamation of character if it turns out that they didn't know what they said was false (which fails the definition of "lying"). That's a simple case where an extreme, emotional term places someone in a false light.
http://en.wikipedia.org/wiki/False_light
Remember, in this litigous society, no one is immune from legal actions, even those clearly wronged, as the facts seem to indicate in this case.
it is better to sell the vulnerability in the underground forums
But what we really need are some damn whistleblower protections for cybersecurity - buzz-wordy enough for government funding and command centers, but no actual help for the people who want to help because it feels like the right thing to do.
> HIPAA explicitly forbids LSU from retaliating against me for reporting a HIPAA violation, so I filed a federal complaint against them for their illegal retaliation.
"Apparently, committing libel is a common thing for them, and they are comfotable completely ignoring the protests of their victims."
I understand that he's likely under tremendous stress as a result of the allegations that LSU has made, but I'm a bit concerned that in his expression of shock and outrage he has turned to making what appear to be potentially libelous statements of his own.
I hope that his goal of having the accusations withdrawn is not hindered by this momentary slip into hyperbole.
Given the fact that many of us believe that the two magazines do not really care about what happened, as much as they prefer getting clicks - a view which is supported by the course of action this story took - it's not a far-fetched claim at all. Especially for a man in his position.
NOTE: They didn't took any action even when notified. The only way for them to remove the article would a letter from a lawyer (or at least that's what I'm getting).
Being a victim of their incompetence does not give him free license to imagine ways he things that they are incompetent and then express them as fact.
They have not yet taken any action. It's just as likely that they haven't seen his tweet.
They are certainly in the wrong here. But his jab at their moral standing weakens his position, and given the state of business <-> individual relations when it comes to disclosing security vulnerabilities, he wants his position to be as strong as possible in case they do turn out to be malicious and attempt to make the case that he violated their security.
He has not said;
"committing libel is a common thing for them"
He has said;
"My comments on the SC Magazine article were deleted. The "journalist" who invented the article has not altered it or contacted me in any way.
The two CEOs have also remained silent.
Apparently, committing libel is a common thing for them, and they are comfotable completely ignoring the protests of their victims."
The word "Apparently" is doing a lot of heavy lifting here.
It is essentially saying "In light of this stated behaviour, it would seem reasonable to assume that...".
He is not making a statement of bald fact however, which is what you are presenting it as by removing the context. Amusingly, you are possibly being slightly libellous here by suggesting that he is.
I thought you'd get more meat from his reference to their crimes. Libel is civil.
That's true, but in many cases like this, on weighing the evidence and seeing evidence for mutual libels, the judge will throw out both actions. The professor should have consulted an attorney before calling people liars -- all the subjects need to do is show that they didn't publish statements that they knew were false (thus failing the definition of "lie"). Failing a reasonable test of due diligence may be deplorable, but it doesn't make one a liar.
> I thought you'd get more meat from his reference to their crimes. Libel is civil.
All true. One of the ironies of modern times is that a civil action can do more to undermine one's life than a criminal one, depending on the circumstances.
"Professor hacks University Health Conway in demonstration for class"
While the follow-up is titled as "Professor says..."
"Professor says Google search, not hacking, yielded medical info"
http://www.scmagazine.com/professor-says-google-search-not-h...
He doesn't seem to realize all that matters to the blog is getting page views...
Think of a brick-and-mortar analogy. You queue up at airport security, you go through, and you notice that their procedures are such that one COULD bring a banned item through and potentially not get spotted. You inform the appropriate authorities that you think there might be a weakness, and you say how and why.
This is probably not going to get you in trouble.
Another scenario: You go through security and make a mental note (as above) of a potential vulnerability. You (as above) report it to the appropriate authorities. Now some time in the future you are going through airport security and you wonder to yourself "I wonder if they fixed it". So you decide to test it out. You bring a banned item through. You get caught. You are in trouble but you say in response "but I was the guy who informed you of the vulnerability and I was just checking to see if it was fixed".
Good luck with that.
My feeling is that if you notice a potential (or actual) vulnerability as part of a everyday, normal use case of a website, or a web service, or network, then fine, you can report it, and you likely won't get into trouble.
On the other hand if you additionally decide to test the system in such a way that could be misconstrued as an attack, then you will probably get into trouble.
Another analogy: you walk into Macy's and on your way in you notice that the security system they are using is outdated, and you know it is vulnerable --- (made up silly example) you know that if you break in while holding a tuna sandwich, the alarm will not go off. So that night after the store is closed and locked, you break in, while holding a tuna sandwich, and you take a pair of $300 shoes. The next day you go to the store and you say "look guys, I was able to break into your store and steal these $300 shoes." You think they will thank you? or will they call the police?
Better analogy to what happened: Imagine you steal the $300 shoes with your new fangled trick and the mall security do not notice at all. You come back the next morning with the $300 shoes in-tow and then they call the police.
The guys with the open FTP server clearly don't give 2 fucks about your privacy, but in a sue-happy atmosphere they're trying to place the blame on someone else.
... or applied some logic. Instead of contacting them directly he could have:
* broadcasted it to the world (maybe a reporter!) that the FTP server was insecure * do/say nothing
if I found it by accident, I'm sure malicious actors can find it as well.
If anything, I think this shows the hospital gave the professor a lot more benefit of the doubt than I would have expected.
The professor did himself no favors with his email:
I am Sam Bowne, an instructor at City College
San Francisco, and I found two security problems
on your server with a Google search.
Your FTP server has been compromised, and some
files named "w0000000t" were added to it.
If I'm the IT administrator who receives this message, then after reading the first two sentences, I've already jumped to the conclusion that this professor is the individual who compromised my server! "Hi, I found security issues with your server, and now it's compromised!"Sure, once you've read the intro by the professor, the meaning is clear, but think of yourself as a sysadmin getting this email, without the context of "I just found this, I had nothing to do with it" in your brain, and how are you going to react? Once the idea that the sender of this email is a hacker who broke into your server has entered your mind, it's going to be very hard to interpret it differently. Given that, the guy got treated pretty nicely by the story and the hospital in the end.
No, as far as we know the articles were based on the University Health legal notice http://www.uhsystem.com/Conway/FINAL%20Conway%20-%20Press%20..., which does NOT contain Sam's name.
Can you accuse someone of libel if the accused is unnamed?
This doesn't take away from the fact that the claims in the report are false, of course.
Only if the unnamed person can be identified. If a person is unnamed, or given a made-up name, and readers cannot associate the name with a real person, the it's not libel.
Many legal actions revolve around this issue. A plaintiff says, "I'm the person this article is about!" while simultaneously claiming, "The article doesn't describe me accurately!" Only one of those can be true.
"Sure, once you've read the intro by the professor, the meaning is clear, but think of yourself as a sysadmin getting this email, without the context of 'I just found this, I had nothing to do with it' in your brain, and how are you going to react? Once the idea that the sender of this email is a hacker who broke into your server has entered your mind, it's going to be very hard to interpret it differently. Given that[...]"
I can't give you that. I've been a sysadmin, and I've gotten emails about things that were misconfigured. Without the intro, the meaning is clear. Even assuming that the professor had added the w00000t files as a PoC, the note is still a nice gesture and a tip, not an indication of terrorism. Interpreting it another way seems a sign of stupidity IMO.
The email starts with his name and place of work. If you read that and think that Sam Bowne, City College, San Fransisco is trying to destroy your servers, you may not be good at thinking.
The "w0000000t" file is apparently part of a mass
compromise of Microsoft FTP servers, which was found
but not explained by a French security company named
QuarkLabs in this slide
Nothing in the message implied that the professor was responsible for anything other than trying to be helpful.If you can easily believe that a professor a) attacked your server, then b) wrote you a smarmy read-between-the-lines email claiming-but-not-claiming responsibility for it, you are a fool. If you can accept/forgive anyone in a system/data-administrative role for the same, you are a fool.
This is not how professionals work. This how good people lead their lives. This is how idiots and bureaucrats win.
There is little to nothing that can be done about this. It's all about narratives, sensationalism, and agendas today.
Just take a look at the media stories about Ukraine where everyone (in US media) just makes shit up and presents it as the truth. No one questions anything.
Or the Michael Brown shooting. Where the media (CNN, MSNBC) pushed their narrative once more, completely ignoring all facts surrounding the event.
It goes on and on and on, with almost every major story being so biased, misleading, and twisted, that it might as well be seen as a complete fabrication...
Here is another good example of security related stories being "misleading" - http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudul...
Big ships. With funnels and everything.