Feeds

Ministry of Defence leaks counter terrorism traffic

Bulgarians lurking

SANS - Survey on application security programs

For the past 20 months, the Ministry of Defence has been generous enough to provide detailed information about visits to its Counter Terrorism Science & Technology site.

We're not sure, exactly, what to make of the logs showing some of the site's most popular pages and most prolific visitors. On the one hand, such details aren't exactly state secrets. Then again, what possible benefit can come from volunteering statistics that show that the Bulgarian IP address 85.187.138.185 was the top visitor for the month of March, having accessed 668 files for a total of 3.5 MB worth of data?

Until late last week, usage stats as measured by an analysis program called Webalizer were freely available from April, 2006 through this month. We're guessing the disclosure was not intentional, because the information was quickly removed about a day after MOD admins were informed of the public pages. (The information is still available in search engine caches by using search strings such as http://www.ctcentre.mod.uk/usage/usage_200604.html, http://www.ctcentre.mod.uk/usage/usage_200605.html and so on.)

Besides showing top visitors, they list some of the site's most popular pages for each month. Last month, for instance, the Counter Terrorism site had just north of 15,000 page impressions ,and its fourth most popular URL was this one relating to potential suppliers.

To be sure, disclosures such as these aren't likely to lead to the kinds of security nightmares that result when, say, a consultant "loses" a laptop containing personal information belonging to hundreds of thousands of individuals. At the same time, seeming innocuous information like this can be precisely the kind of fodder gathered in footprinting exercises, in which attackers learn as much as possible about sites they intend to penetrate. Loose lips sink ships, as the saying goes.

"I think I can reasonably say that any conventional enterprise or government entity most likely intends to have policies in place that would consider IP addresses of visitors to be information not intended to be casually shared on the public internet," says security researcher Rodney Thayer of Canola & Jones.

The MOD is by no means the only website that has made its Webalizer logs available to the world. Running this search reveals tens, possibly thousands, of sites that allow anyone to view usage statistics. NASA, the US Army and a UK Hospital are among them. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.