Just in:
Travelodge Myeongdong Namsan: The Latest Addition to Seoul’s Hospitality Scene // National Media Council Delegation Endorses Bu Tinah Island Model // Ad Blockers Gain New Purpose in Fight Against Government Spyware // Urgent Plea for De-escalation in the Region Issued by the UAE // UAE Braces for Intensifying Weather System This Week // Over 100,000 Workers Benefit from New Wage Protection System // Migrant Workers Continue To Suffer, Now In The Name Of Election // With record scale, China’s consumer products expo shares opportunities and market with world // UAQ Ruler Extends Sympathies to Oman Following Devastating Floods // GOOD Vision Unveils K-Shape™: A Revolutionary Corneal Topographer at The International Exhibition of Inventions of Geneva // Leverkusen Triumph in Bundesliga Upset // Hong Kong Over-the-Counter Crypto Trading Seeks Clarity in Licensing Framework // HDBank to pay 25% dividend in cash, stocks and aim for high growth in 2024 // World Trade Charts New Course After Three Decades // Stepping into the Metaverse: Adidas Partners with Stepn for NFT Collection // Aramco Vice President addresses Aramco’s sustainability initiatives at One Earth Summit // Old ‘Ghoshnas’ Dressed Up In ‘Sankalps’ Is BJP’s 2024 Election Manifesto // DFS CIRCLE Celebrates First Anniversary: Journey to ‘Collect the World’ with Exclusive Gifts designed by the trending illustrator, matsui, and Destination-unique Collectibles! // Malicious Repositories Lurk in GitHub Search // CUHK Tops QS World University Rankings, Solidifying Its Global Research Leadership: Secures Top Positions in Hong Kong with 8 Subjects and 19* Subjects Among Top 50 //
HomeTalking PointPanama Papers leak traced to faulty plugins

Panama Papers leak traced to faulty plugins

|Arabian Post Special| The Mossack Fonseca (MF) data breach that made Panama Papers, the biggest data leak to journalists in history,  possible has been traced to a vulnerable version of a plugin used to create sliders in website designs.

According to leading cyber security firm Wordfence, Mossack Fonseca was running WordPress, one of the  most popular website platforms in use, with a vulnerable version of Revoluiton Slider and the WordPress server was on the same network as their email servers when the breach occurred.

The security firm has released new information describing how the attackers may have breached the MF email servers via WordPress and Revolution Slider and presented how the attackers probably gained access to client documents via Drupal, another popular platform. Panama Papers covered some 4.8 million emails.

ADVERTISEMENT

According to Süddeutsche Zeitung, the German publication that originally received the Panama Papers leak, the breakdown of the data structure of the Panama Papers includes over 4 million emails, 3 million database formats, 2 million pdf files, 1 million images and over 320,000 text documents.:

Email is by far the largest chunk of data in the MF breach. Last week MF sent an email to its clients saying that it had experienced unauthorized access of its email servers, confirming that the servers were compromised and making it clear this was in fact a hack.

Wordfence showed how trivially easy it was to hack into the MF WordPress website via the vulnerable version of Revolution Slider that they were running. Once you gain access to a WordPress website, you can view the contents of wp-config.php which stores the WordPress database credentials in clear text. The attacker would have used this to access the database.

MF was running the WP SMTP plugin which provides the site the ability to send mail from the website via a mail server. This plugin stores email server address and login information in plain text in the WordPress database. The login information stored is a mail server SMTP login for sending email.

Once an attacker had access to WordPress, the wp-config.php file which contains the database credentials and then the WordPress database, they can see the mail server address and a username and password to sign-in and begin to send email. They would also have had whatever other privileges were conferred on that account.

MF was also running the ALO EasyMail Newsletter plugin which provides list management functionality. One of the functions it provides is to receive bounced emails from a mail server and automatically remove those bounced mails from the subscriber list. To do this, the plugin needs access to read emails from the email server. This plugin also stores email server login information in the WordPress database in plain text. In this case the login information provides the ability to receive mail via POP or IMAP from the mail server.

Once the attacker also had access to this data, after gaining access to the WordPress database via Revolution Slider, they would have been able to sign-into the email server and would be able to read emails via POP or IMAP.

One of the key concepts in information security is the principle of least privilege. For example: User accounts should only have the access they need to do their job.  But it’s easy to imagine in a company with high powered clients, the same account that a customer relationship manager uses is also used to send list emails. This would ensure that the manager sees all replies in his or her inbox. If that was the case, the attacker would have gained access to a senior staff member’s email account when they stole these email server credentials.

 

ADVERTISEMENT

ADVERTISEMENT
Just in:
HDBank to pay 25% dividend in cash, stocks and aim for high growth in 2024 // Lifeblood for Yemen: UAE-Funded Hospital Brings Hope for Mothers and Children // Urgent Plea for De-escalation in the Region Issued by the UAE // GOOD Vision Unveils K-Shape™: A Revolutionary Corneal Topographer at The International Exhibition of Inventions of Geneva // DFS CIRCLE Celebrates First Anniversary: Journey to ‘Collect the World’ with Exclusive Gifts designed by the trending illustrator, matsui, and Destination-unique Collectibles! // Old ‘Ghoshnas’ Dressed Up In ‘Sankalps’ Is BJP’s 2024 Election Manifesto // Leaders of UAE and Jordan Collaborate on Mideast Issues // UK Poised for Crypto Regulations by July // K3 Legal in association with Fred Kan & Co opens first office in Hong Kong // Stepping into the Metaverse: Adidas Partners with Stepn for NFT Collection // CUHK Tops QS World University Rankings, Solidifying Its Global Research Leadership: Secures Top Positions in Hong Kong with 8 Subjects and 19* Subjects Among Top 50 // Travelodge Myeongdong Namsan: The Latest Addition to Seoul’s Hospitality Scene // World Trade Charts New Course After Three Decades // A Taste of Morocco Arrives at Dubai’s Global VillageThe aromatic spices and vibrant culture of Morocco have arrived at the Dubai Global Village, as the Moroccan pavilion officially opened its doors to the public. Spanning an impressive space, the pavilion promises to transport visitors to the heart of Morocco, offering a captivating glimpse into the country’s rich heritage, traditional crafts, and delectable cuisine.Stepping into the pavilion is akin to stepping onto the bustling streets of a Moroccan marketplace. The air is filled with the enticing aroma of fragrant tagines and freshly brewed mint tea, whetting the appetites of visitors. Colorful displays of intricately woven textiles, handcrafted pottery adorned with Berber designs, and gleaming brass lamps line the stalls, each piece a testament to the meticulous skill of Moroccan artisans.Visitors can embark on a sensory journey through Morocco, exploring the vibrant culture and traditions of the North African nation. Those seeking a retail adventure can browse through a curated selection of Moroccan goods, including hand-woven rugs, leather goods, and babouche slippers, all reflecting the country’s unique blend of Arabic, Berber, and European influences.Beyond shopping, the pavilion offers a chance to immerse oneself in Moroccan culture. Live music performances featuring traditional instruments like the oud and the darbuka fill the air, transporting visitors to a vibrant Marrakech marketplace. Artisans showcase their skills, demonstrating the age-old techniques of carpet weaving, pottery making, and metalwork, offering a glimpse into the heart of Moroccan craftsmanship.For those seeking a culinary adventure, the pavilion boasts a variety of restaurants serving up authentic Moroccan delicacies. Visitors can savor the fragrant flavors of tagines, simmered meats and vegetables in a conical clay pot, or sample the fluffy sweetness of baghrir, a type of semolina pancake drizzled with honey and argan oil. No Moroccan experience is complete without a steaming cup of mint tea, traditionally poured from a height to create a foamy head.The Moroccan pavilion at the Dubai Global Village is more than just a marketplace; it’s a portal to a captivating culture. Whether you’re tertarik (attracted) to the intricate craftsmanship, enticed by the flavorful cuisine, or captivated by the lively music, the pavilion offers a chance to experience the magic of Morocco firsthand. // LinkVector Launches Waitlist For Upcoming Internal Linking Tool Launch // UAE Braces for Intensifying Weather System This Week // LukFook Group Expanded Retail Footprint in Southeast Asia // Aramco Vice President addresses Aramco’s sustainability initiatives at One Earth Summit // UAQ Ruler Extends Sympathies to Oman Following Devastating Floods // Geopolitical Jitters Drive Gold Prices Up //