网易首页 > 网易教育 > 移民频道 > 正文

澳洲16岁少年骇入政府官网 民众资料遭曝光

0
分享至
澳大利亚维州1名16岁的少年日前轻易地骇入维州公共交通局(PTV)的网站,取得网站使用者的个人机密资料,暴露维省政府网站安全性不足问题。


Joshua Rogers成功骇进维州公共交通局PTV网站,暴露了该网站的脆弱性。Simon Schluter摄

网易教育讯 据《悉尼先驱晨报》报道,澳大利亚维州1名16岁的少年日前轻易地骇入维州公共交通局(PTV)的网站,取得网站使用者的个人机密资料,暴露维省政府网站安全性不足问题。

维州公共交通运输网站提供火车、公交车及电车票价和时刻表查询,例如即将在墨尔本举行的澳洲网球公开赛交通方式,并可使用在线myki充值服务。

目前仍在学的罗杰斯(Joshua Rogers)自称是网络安全研究者,侵入网站动机在于改善网络安全性。他以简易的黑客手法发现这个网站数据库,包含使用者姓名、生日、住址、住家和手机号码,以及电子邮件和信用卡部分卡号等资料,约有60万笔资料。

网络安全专家柯尼克(Phil Kernick)指出,罗杰斯所使用的黑客方式十分简单,罗杰斯或许不是第一个骇入该网站的人,这些资料可能已被别人取得。柯尼克对于政府单位研发出如此漏洞百出的网站感到十分失望。

网络安全控管公司主管米勒(Ty Miller)则担忧这些个人资料被不肖人士取得而作非法使用,例如以此资料向银行作身分确认,便可重新设定账号密码,或直接进行转帐交易等。

罗杰斯去年12月26日以电子邮件联系维州公共交通运输网站,告知他所发现的网络安全漏洞,1个礼拜后未获回应,目前此案已交由维省警方处理。

维州公共交通运输网站表示,目前个人资料已无法透过在线系统取得。而该数据库并未与myki在线储值账户连结,因此信用卡卡号等相关信息都不在数据库中。


Personal information about public transport users in Victoria has been exposed to potential identity theft because government authority Public Transport Victoria failed to secure its website.

The security flaw in the PTV website was discovered by schoolboy Joshua Rogers, 16, who used a simple hacking technique to unearth a database containing the personal records of customers of the former Metlink online store.

The database includes full names, addresses, home and mobile phone numbers, email addresses, dates of birth, seniors card ID numbers, and nine-digit extracts of credit card numbers.

Joshua contacted PTV last month to warn it of the site's vulnerabilities. On Tuesday it referred the matter to the police.

Joshua, a self-described ''white hat'' security researcher, said he was motivated by a desire to improve online security. He first contacted PTV by email on Boxing Day, but received no response. He later contacted Fairfax Media.

More than a week after Joshua made contact with PTV, it still had not responded, but this week it referred the matter to Victoria Police and Privacy Victoria following inquiries by Fairfax Media.

The method Joshua used to enter PTV's site has been described by cyber security experts as one that is easy to guard against.

It is not known if others have previously hacked the website, which is the primary online source for information about train, tram and bus timetables, myki, and current and planned public transport projects. Metlink was the Transport Department's ''shop front'' for public transport users before Public Transport Victoria's formation in 2012. An estimated 600,000 entries were found in the database.

Phil Kernick, of cyber security consultancy CQR, said PTV had failed to take proper care to secure its site from potential hacking.

''It's truly disappointing that a government agency has developed a website which has these sorts of flaws,'' Mr Kernick said.

''So if this kid found it, he was probably not the first one. Someone else was probably able to find it too, which means that this information may already be out there.''

Ty Miller, director of Threat Intelligence, which locates security flaws in websites so they can be fixed, said the type of personal information hidden on PTV's site was sought by criminal hackers.

''Most of the stuff is personally identifiable information that is often used for things like identity theft, for example, ringing up your bank, and then answering their basic questions - like, 'what's your birthday, what's your address','' Mr Miller said. ''That then allows you to maybe reset a password for internet banking and then make fraudulent transactions.''

Fairfax Media gave PTV time to secure its site before publishing.

A spokesman said the personal data was no longer accessible or available via any online system. He added that the database was not linked to myki online accounts and that no usable credit card details were stored in the database.

相关推荐
热点推荐
官方披露:已任湖北省委统战部二级巡视员的李涛严重违纪违法

官方披露:已任湖北省委统战部二级巡视员的李涛严重违纪违法

澎湃新闻
2024-04-19 21:26:27
糊里糊涂!小马科斯陷美国甜蜜陷阱,里外不是人,才想着找补

糊里糊涂!小马科斯陷美国甜蜜陷阱,里外不是人,才想着找补

陆弃
2024-04-19 11:11:03
高中校花在我手下气喘吁吁,只因我假装成盲人按摩师,但这不算完

高中校花在我手下气喘吁吁,只因我假装成盲人按摩师,但这不算完

茶馆说书人
2023-09-08 11:52:28
民意不可欺!道德警察重返街头,伊朗民众喊话以色列:打他们

民意不可欺!道德警察重返街头,伊朗民众喊话以色列:打他们

娱宙观
2024-04-17 09:59:47
85年王震坚决反对中顾委副主任排名,薄一波得知怒道:就这样定了

85年王震坚决反对中顾委副主任排名,薄一波得知怒道:就这样定了

历史典录
2024-04-19 10:16:34
热火绿军对决选谁?奥尼尔:巴特勒伤了 我选凯尔特人

热火绿军对决选谁?奥尼尔:巴特勒伤了 我选凯尔特人

直播吧
2024-04-20 12:56:19
妻子和男闺蜜旅游,3岁女儿饿到吃洗衣粉,丈夫98个电话无人接

妻子和男闺蜜旅游,3岁女儿饿到吃洗衣粉,丈夫98个电话无人接

纸鸢奇谭
2024-04-19 16:33:34
“哈啤”被香港消委会检出呕吐毒素后,企业负责人第一时间表态!

“哈啤”被香港消委会检出呕吐毒素后,企业负责人第一时间表态!

王晓爱体彩
2024-04-19 23:04:43
南海出事,美在菲部署中导,不到一天,中方承诺支持古巴军队建设

南海出事,美在菲部署中导,不到一天,中方承诺支持古巴军队建设

天下事田上知
2024-04-19 16:10:50
美国加速收割越南,万亿越南资金撤出,越南或将衰退20年

美国加速收割越南,万亿越南资金撤出,越南或将衰退20年

关权教授聊经济
2024-04-19 19:30:03
撒切尔夫人年轻时的照片,美若天仙,真是挑不出一丁点毛病

撒切尔夫人年轻时的照片,美若天仙,真是挑不出一丁点毛病

喜文多见01
2024-04-15 12:20:07
郭美美高价甩卖二手包业绩惨淡,叫价2000,卖了一晚销售额为0!

郭美美高价甩卖二手包业绩惨淡,叫价2000,卖了一晚销售额为0!

娱圈小愚
2024-04-19 15:10:15
惊!研二学生疑遭舍友投毒致死真相曝光

惊!研二学生疑遭舍友投毒致死真相曝光

缤纷马儿
2024-04-20 07:34:45
泰国队倒下,0-5惨败给西亚劲旅,无缘2连胜,但排名依然令人羡慕

泰国队倒下,0-5惨败给西亚劲旅,无缘2连胜,但排名依然令人羡慕

侧身凌空斩
2024-04-20 05:11:04
广西一男子医科大跳楼,疑似重病没钱治疗。围观群众大喊不要跳

广西一男子医科大跳楼,疑似重病没钱治疗。围观群众大喊不要跳

美食阿鳕
2024-04-20 05:14:46
为啥马拉松火得一塌糊涂,连小县城都抢着办?网友:马路印钞机!

为啥马拉松火得一塌糊涂,连小县城都抢着办?网友:马路印钞机!

杂谈哥闲谈
2024-04-17 22:30:53
16国南海军演,将击沉中国造军舰,不到24小时,中国双航母出动

16国南海军演,将击沉中国造军舰,不到24小时,中国双航母出动

说天说地说实事
2024-04-19 15:45:30
专家:对俄战争已然失败

专家:对俄战争已然失败

俄罗斯卫星通讯社
2024-01-22 15:13:11
以色列对伊朗发起袭击,当天正值伊朗最高领袖哈梅内伊85岁生日

以色列对伊朗发起袭击,当天正值伊朗最高领袖哈梅内伊85岁生日

极目新闻
2024-04-19 16:14:34
章泽天亮相意大利品牌活动,气质不输章子怡,刘强东也压不住了

章泽天亮相意大利品牌活动,气质不输章子怡,刘强东也压不住了

娱乐圈酸柠檬
2024-04-20 03:43:33
2024-04-20 13:42:44

头条要闻

美国罕见出动12架B-2隐身轰炸机 被指在威慑潜在对手

头条要闻

美国罕见出动12架B-2隐身轰炸机 被指在威慑潜在对手

体育要闻

米切尔这次对线不会输了吧

娱乐要闻

北影节开幕之夜,内娱女星千娇百媚

财经要闻

新华资管香港的秘密:猛投地产或致巨亏

科技要闻

华为今年最关键的事曝光!Pura 70有新消息

汽车要闻

78.9万的极氪009光辉 让加价MPV无话可说

态度原创

手机
家居
房产
健康
教育

手机要闻

Google Pixel 9 Pro 上手实拍图片泄露

家居要闻

光影浮动 色块碰撞与线条起伏的情感呼应

房产要闻

官方喊话,广州公寓或将走向终结?

这2种水果可降低高血压死亡风险

教育要闻

民俗文化解锁文旅“新玩法”,学学解锁相关单词

无障碍浏览 进入关怀版
×