HomeinetNASA: SQL injection by Greek researchers

NASA: SQL injection by Greek researchers

Two Greek researchers managed to identify a security vulnerability on a NASA website (subdomain), which allowed them to perform SQL injection and gain access to the organization's database.

According to Greek researchers, the American space agency was notified in a timely manner of the security flaw, but to date, they have not made any repairs.

Researchers Dimitris Chatzidimitris and Anastasis Vasileiadhs report to Secnews.gr via email:NASA

“On August 29th, we identified a vulnerability while browsing a NASA page (https://www.jpl.nasα.gov/) related to various propulsion systems….

The vulnerability is of the SQL injection and the link to the specific weakness is:

Note from Secnews.gr: We do not list the link for obvious reasons, but we present some of the information we received by email:

Parameter: catId (GET)
Type: boolean-based blind
Database version: 5.1.61-community-lo

“This vulnerability gave us access to the databases of this website”

The researchers report:

"After this, we did not proceed further with any possible access to the server beyond the basics since we had already confirmed the weakness in the security of the page.".

Immediately on August 27th, we contacted them via the contact form on their page and informed them in detail so that they could proceed with fixing their security.

As of today, September 8, we have not received any response regarding this.

Security researchers:

Dimitris Chatzidimitris
Anastasis Vasileiadhs”

We present a screenshot of the database tables. We note that the tables also include those that list the website's user data (usernames and passwords).

See the image below (wp-users, contacts, Member, authors)

NASA: SQL injection by Greek researchers

_____________________________________

The information remains available to those directly interested, from the researchers themselves and from Secnews.gr.

Reporting on vulnerabilities discovered in organizations is considered extremely necessary (especially when they exist on high-traffic websites), and for us at Secnews.gr they are an immediate priority.

We hope that in this way, namely by directly exposing each vulnerability and not by "hiding" it, we contribute to a safer internet.

Of course, we have encountered many companies and organizations, both locally and globally, that instead of collaborating to resolve a vulnerability, initiate legal proceedings to prosecute researchers, carefully covering the security gap with the rug, trying to avoid negative impressions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS