Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security ) [Project Leader]

The Web Hacking Incidents Database
Last update:07 November 2007

List of incidents of class Misconfiguration

Other WASC threat classifications:
Abuse of Functionality, Brute Force, Content Spoofing, Credential/Session Prediction, Cross-site Scripting, Defacement, Denial of Service, Directory Indexing, HTTP Response Splitting, Information Leakage, Insufficient Anti-automation, Insufficient Authentication, Insufficient Authorization, Insufficient Process Validation, Insufficient Session Expiration, Known Vulnerabity, Misconfiguration, OS Commanding, Other, Path Traversal, Phishing, Predictable Resource Location, Redirection, SQL Injection, Unknown, Weak Password Recovery Validation, Worm


There are 3 incidents of class Misconfiguration
WHID 2007-04: College glitch avails student information to public
Date: 10 March 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authentication, Misconfiguration

A student at a community college in Sacramento who was "Googling" himself last month found disconcerting information when he typed his name into the popular Internet search engine

References:

WHID 2007-03: UI put staff data on Web
Date: 10 March 2007
Incident Type: Security Breach
WASC Threat Classification: Insufficient Authentication, Misconfiguration

Personal information for about 2,700 University of Idaho employees was inadvertently posted at the school's Web site for 19 days in February, though officials say it was not easy to access and there's no reason yet to believe it was misused.

References:

WHID 2007-07: Westerly Hospital data breach affects 2,000
Date: 02 March 2007
Incident Type: Security Breach
WASC Threat Classification: Misconfiguration

Personal information about 2,000 patients was mistakenly published on the hospital's web site. The leakage was discovered only when a patient found her information when "Googling" herself.

The information included personal data such as social security numbers, birth dates, address, phone number, insurance numbers and in some cases the reason for the visit.

References:




This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

© Copyright 2005, Web Application Security Consortium. All rights reserved.