Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
安全研究人员扫描波兰网络,发现法院、医院和机场面临黑客攻击风险
Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks, and quickly found that thousands of public agencies and websites were at risk of being hacked. 两名波兰安全研究人员想要了解本国互联网在面对潜在网络攻击时的脆弱程度,结果很快发现,数以千计的公共机构和网站正面临被黑客攻击的风险。
At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand the state of Poland’s public web out of a sense of patriotism and a desire to make it safer for everyone. 在上周五于拉斯维加斯举行的 Def Con 网络安全大会上,安全研究人员 Robert Kruczek 和 Kamil Szczurowski 表示,出于爱国情怀以及让网络环境对每个人都更安全的愿望,他们希望了解波兰公共网络的状态。
Before long, the duo discovered more than 10,000 affected public entities with 250,000 websites with security flaws, including airports, hospitals, and government offices. 不久之后,两人便发现了超过 10,000 个受影响的公共实体,涉及 25 万个存在安全漏洞的网站,其中包括机场、医院和政府办公室。
The researchers found that some of the vendors’ buggy software, coupled with a lack of bug bounties and ways to report security flaws, are putting Poland’s public services at risk of hijacks and other attacks. 研究人员发现,一些供应商软件中存在的缺陷,加上缺乏漏洞赏金计划和安全漏洞报告渠道,使得波兰的公共服务面临被劫持及其他攻击的风险。
The researchers also said that some bugs were incredibly easy to exploit but were not always taken seriously, with some vendors describing the bug reports as inconveniences. 研究人员还表示,有些漏洞极易被利用,但并未总是得到重视,甚至有供应商将漏洞报告描述为“麻烦”。
The research comes as Poland is trying to shore up its cyber defenses after a wave of suspected Russian hacks targeting the country’s energy and water providers. Some of the hacks have been carried out by taking advantage of weak cybersecurity. 这项研究正值波兰试图加强网络防御之际,此前该国能源和水务供应商遭遇了一波疑似来自俄罗斯的黑客攻击。其中一些攻击正是利用了薄弱的网络安全防护。
Kruczek and Szczurowski found several bugs in the widely used content management system Pad CMS, which website owners use to organize and display content. The two found critical vulnerabilities in one web system called Pad CMS, which allowed them to easily access over 300 public websites without needing a password. Kruczek 和 Szczurowski 在广泛使用的内容管理系统 Pad CMS 中发现了多个漏洞,该系统常被网站所有者用于组织和展示内容。两人在 Pad CMS 中发现了关键漏洞,使他们无需密码即可轻松访问 300 多个公共网站。
The software developer did not patch the software because it had become “end of life” and was no longer supported. Another bug allowed them to gain access to the websites of some two-thirds of Poland’s judiciary, or about 245 courts, they said. 该软件开发商并未修复这些漏洞,因为该软件已进入“生命周期终点”(EOL),不再提供支持。他们还表示,另一个漏洞使他们能够访问波兰约三分之二的司法机构网站,即约 245 家法院的网站。
The duo reported their findings to the government through various official channels. The researchers said during their talk that it was ultimately worth the hassle, saying that as a result we are “a little bit more safe.” 两人通过各种官方渠道向政府报告了他们的发现。研究人员在演讲中表示,这一切努力最终是值得的,并称其结果让我们“变得稍微安全了一些”。