JAKARTA - Two Polish cybersecurity researchers have found vulnerabilities in about 250,000 sites belonging to more than 10,000 public entities. The findings include airport sites, hospitals, government offices, to courts.
TechCrunch, quoted Saturday, August 8, reported that Robert Kruczek and Kamil Szczurowski presented the results of the research at the Def Con cybersecurity conference in Las Vegas, Friday.
The two initially wanted to find out how vulnerable Polish public web services are to cyberattacks.
As a result, they found problematic software from a number of vendors, a lack of reporting channels for gaps, and the absence of bug bounty programs increased the risk.
Bug bounty is a program that rewards researchers who find and report security vulnerabilities.
According to Kruczek and Szczurowski, a number of vulnerabilities are even very easy to exploit. However, their reports are not always taken seriously. Some vendors are said to consider reports on the vulnerabilities as a nuisance.
The finding comes as Poland is strengthening its cyber defenses after a wave of alleged Russian attacks on energy and water providers.
TechCrunch noted that some of the previous attacks were carried out by exploiting cybersecurity weaknesses.
One of the critical gaps was found in Pad CMS, a widely used site management system.
The vulnerability in the software allowed the two researchers to access more than 300 public websites without a password.
The developer of Pad CMS did not fix the flaw because the software has reached end of life and is no longer supported.
Another gap allowed Kruczek and Szczurowski to access the sites of about two-thirds of Poland's judicial institutions, or about 245 courts.
The two then reported the findings to the government through various official channels.
The researchers said the effort was ultimately worth it. According to them, the results of the findings and reports made the security situation "a little safer."
The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)