Sunday, March 7, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Netanyahu’s party exposes data on over 6.4 million Israelis

February 10, 2020
in Internet Security
Netanyahu’s party exposes data on over 6.4 million Israelis
585
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

A misconfiguration in an election day app developed by Likud, the party of Israeli prime minister Benjamin Netanyahu, may have potentially exposed and compromised the personal details of almost 6,5 million Israeli citizens.

The leak was discovered and detailed today by Ran Bar-Zik, an Israeli-born frontend developer for Verizon Media.

You might also like

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

Linux distributions: All the talent and hard work that goes into building a good one

It is unclear if the exposed server and data was harvested by unauthorized parties before Bar-Zik’s discovery and public disclosure. Local Israeli media like Haaretz, Calcalist, and Ynet confirmed Bar-Zik’s findings.

How the leak was discovered

According to Bar-Zik, he discovered the leak while performing a security audit of Elector, an app developed by Elector Software for Lukid, an Israeli political party led by the country’s current prime minister Benjamin Netanyahu.

Bar-Zik said he looked into the app after local media surfaced several privacy-related issues about the app in recent weeks, such as problems with the app allowing users to register other users for SMS-delivered news without their consent.

According to local media, the Lukid party ordered the app to allow political supporters to sign up for news and updates during the upcoming Israeli legislative election, to be held on March 2, next month.

The app was made available for download on the elector.co.il website.


Image: Ran Bar-Zik

In a blog post today, Bar-Zik said this website contained more information than it should.

The developer said the site’s source code included a link to an API endpoint that was supposed to be used to authenticate the site’s administrators.

israel-2.png

Image: Ran Bar-Zik

Bar-Zik said the website’s developers left this API endpoint exposed online without a password, allowing anyone to query it without restriction.

Sending queries to the API endpoint returned details about the site’s administrators, including cleartext passwords.

israel-3.png

Image: Ran Bar-Zik

Bar-Zik said that he used credentials returned by the API to gain access to the site’s backend.

israel-4.png

Image: Ran Bar-Zik

What the database contained

This backend appeared to provide access to a database that contained the personal details of 6,453,254 Israeli citizens, eligible to vote in the upcoming election, Bar-Zik said.

Local media claimed the database was an official copy of Israel’s voter registration database, which each political party receives before an election so they could prepare upcoming campaigns.

According to Haaretz, for each entry in this database, there was information like a full name, phone number, ID card numbers, home addresses, gender, age, and political preferences.

At the time of writing, the Electoral app’s official website has been taken down and removed from the cache of search engine like Google and Bing, to prevent further access to the site’s source code and admin API endpoint.

In his blog post, Bar-Zik said the app’s developers failed because they left an API endpoint exposed without a password and then failed again when they didn’t secure admin accounts with a two-factor authentication mechanism.

Last year, ZDNet reported about similar leaks that exposed the voter databases of entire countries, namely Chile and Ecuador.

However, this one is much worse, largely due to Israel’s position in the Middle East and its tensed relations with neighboring Arab countries.

Credit: Zdnet

Previous Post

Mastering Machine Learning Algorithms Second Edition

Next Post

Humans vs. Machines – the Future of Communication

Related Posts

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now
Internet Security

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

March 7, 2021
Linux distributions: All the talent and hard work that goes into building a good one
Internet Security

Linux distributions: All the talent and hard work that goes into building a good one

March 7, 2021
Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool
Internet Security

Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool

March 7, 2021
Cyberattack shuts down online learning at 15 UK schools
Internet Security

Cyberattack shuts down online learning at 15 UK schools

March 6, 2021
Next Post
Humans vs. Machines – the Future of Communication

Humans vs. Machines – the Future of Communication

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews
Machine Learning

Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews

March 7, 2021
CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now
Internet Security

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

March 7, 2021
Why do Machine Learning strategies fail and how to deal with them?
Machine Learning

Why do Machine Learning strategies fail and how to deal with them?

March 7, 2021
Linux distributions: All the talent and hard work that goes into building a good one
Internet Security

Linux distributions: All the talent and hard work that goes into building a good one

March 7, 2021
Enhance your gaming experience with this sound algorithm software
Machine Learning

Enhance your gaming experience with this sound algorithm software

March 7, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud March 7, 2021
  • Researchers at Utrecht University Develop an Open-Source Machine Learning (ML) Framework Called ASReview to Help Researchers Carry Out Systematic Reviews March 7, 2021
  • CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now March 7, 2021
  • Why do Machine Learning strategies fail and how to deal with them? March 7, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates