elsiegee40 Posted October 13, 2021 Posted October 13, 2021 https://www.theregister.com/2021/10/12/schools_marketing_company_database_credentials_exposed/ An email marketing company claiming to hold details on a million UK teachers and school admin personnel was potentially exposing those to the public internet thanks to a misconfigured error page on its website. Not only that, but the Schools Marketing Company (SMC) seemingly dismissed the findings of the infosec company which spotted the flaw when the infoseccers tried to draw its attention to the problem. An email shown to The Register by Pen Test Partners, described by the firm's consultant Andrew Tierney as "the most arrogant response I've ever had to a disclosure," said the company wasn't interested in hearing about the vulnerability. What Tierney said he stumbled across was a server error message that displayed an awful lot of information to the public internet, including what appeared to be database usernames and passwords. Upon reporting this to Leytonstone-based SMC, however, things didn't go as expected, said PTP. After repeated efforts to contact the company, a senior IT employee eventually replied to say: “Thank you for your email, and the subsequent one, and the one after that. You mention the word 'Chasing', what exactly are you 'chasing'? You sent us an email, we were not interested in discussing the contents of the email and as far as we are concerned the matter is closed. Please do not continue to contact us except to acknowledge this email.” El Reg has seen the full email, complete with names and signature blocks. SMC's response surprised Tierney, who told The Register: "We've disclosed hundreds of issues over the years, but this ranks as one of the worst responses to date. The most obvious issue – the error page – is easier to fix than sending a snarky response. It's a bit worrying for a company that claims to hold contact details of over a million school staff." It is unclear for how long the credentials were in the public domain but it was long enough for them to be indexed by the Internet Archive's Wayback Machine. Thankfully, it appears the firm ultimately acted on the infoseccers' warnings. Although The Register shared the Wayback Machine link with the SMC last week, the company did not initially reply – but as of yesterday morning the page at that URL displayed the message "Sorry. This URL has been excluded from the Wayback Machine." Exposing the database username and password means anyone who could gain access to the firm's internet-facing login page could then read and copy its contents. The Schools Marketing Company website boasts that it is "GDPR and PECR compliant, registered with the Information Commissioner (ICO) since 2007" and that it has "over one million personal, school emails for UK teachers and staff, working in over 250 job function areas in schools." Most companies receiving a disclosure from a reputable firm tend to take it seriously – with the best in the industry having proper vuln disclosure policies and a security.txt file. That being said SMC did act on the disclosure. The ICO has been made aware of the potential breach and confirmed that Schools Marketing Company is a registered data processor. The regulator has the power to investigate and can issue fines if it believes wrongdoing or malpractice was involved in any proven data breach. The Schools Marketing Company's system manager Tom Glasson today sent us a statement via email: "We have no prior relationship with Pen Test Partners and we do not hold any confidential information on any of our servers, however, we took the matter seriously and have taken and are taking steps to ensure security of our systems as we always have done. "There is no indication that any systems or information we hold have / has been compromised," he added. 4
3s-gtech Posted October 13, 2021 Posted October 13, 2021 "Schools Marketing Company" - where to start with that one. I can imagine that their emails are solicited and welcome in inboxes across the land. What a professional response. 3
elsiegee40 Posted October 13, 2021 Author Posted October 13, 2021 "Schools Marketing Company" - where to start with that one. I can imagine that their emails are solicited and welcome in inboxes across the land. What a professional response. Yes, it does take my mind back to a certain thread [emoji1] http://www.edugeek.net/forums/behind-red-door/203774-blocking-marketing-emails.html However, the point is that there’s been a DP breach and they didn’t appear to take it seriously when told 1
mavhc Posted October 13, 2021 Posted October 13, 2021 Interesting that just an email address counts as personal information if it includes your name. Thus letting anyone see your personal address book database is a data breach. Are you allowed to tell anyone else someone's email address?
StevieM Posted October 13, 2021 Posted October 13, 2021 Interesting that just an email address counts as personal information if it includes your name. Thus letting anyone see your personal address book database is a data breach. Are you allowed to tell anyone else someone's email address? I had something similar, but on a much smaller scale, with a very popular school website provider while I was trialling their CMS back in June. When I was logged in, I was able to access the names and email addresses of others who had also trialled it. When I reported this to them, it was acknowledged that, while it was a useful feature for schools, it wasn’t appropriate for the demo site. Older accounts have been purged and a request made to devs to hide other users details. Fast forward 4 months to this week and I received an email asking if I was still interested in a new school website. Out of curiosity, I tried logging into the demo site. All the users were still visible. I could even download a CSV of about 270 previous users dating back to 2018. I may even have some Edugeeks’ details, as lots have given this company a thumbs up. I’m going to email them again, this week, attaching the CSV.
elsiegee40 Posted October 13, 2021 Author Posted October 13, 2021 Interesting that just an email address counts as personal information if it includes your name. Thus letting anyone see your personal address book database is a data breach. GDPR does not apply to personal or domestic activity. Are you allowed to tell anyone else someone's email address? Not in a commercial context and it’s ill advised in a personal context. If A wants B’s email address or phone number you ask A for their email or phone number and say you will ask B to contact them. It’s then B’s choice whether they want to communicate with A. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now