If you are, then you are definitely not alone! This has become a really hot topic for many Latvians after a hacker nick-named “Neo” (as in Matrix) has released sensitive information about salaries and bonuses of top managers of some state-owned companies, banks and even the police. These companies either received significant subsidies from the state or promised to cut on top management salaries and bonuses because of the economical situation. But as you can guess, unlike regular employees, the management actually received full bonuses and no pay cuts.
From a security perspective, this is also quite interesting story. A story of inadequate security, improper design and systems that can be exploited easily either because of programming bug or or lack of experience and expertise (one can only hope that there was no malicious intent). The data was obtained from an web system called EDS that is used for electronic submission of declarations for the Latvian State Revenue Service. This system is compulsory for all companies in Latvia since the beginning of this year but was optional since 2006. Unfortunately the system allowed even anonymous users to download data because of two serious problems:
1. document IDs were assigned sequentially, thus allowing the attacker to simply try lots of numbers in sequence
2. certain links did not have proper access control implemented, so it was possibly to simply request them in a form like this: https://www2.vid.gov.lv/eds/Pages/GetDuf.aspx?id=1
As you can see, to get access to the data was no rocket science. Unfortunately, even an audit of the State Revenue Service IT systems (that cost more than a million EUR) did not discover this issue. “Neo” was apparently much more clever and was taking all the necessary security measures, such as using public WiFi hotspots in the UK, chain of proxies etc. No surprise that he has already been nick-named “New Robin Hood” by some media. “Neo” and his group are even using Twitter to talk to public
Share | |






