Cloud computing Infrastructure-as-a-Service (IaaS) can provide an attractive option for businesses , but a security flaw can cost them dearly.
This was discovered after a recent Symantec, which found that incorrectly configured access permissions allow open access to a treasure trove of information stored in the cloud.
According to Symantec, researchers were able to identify more than 16,000 cloud by enumerating domain prefixes with dictionary words. Of the domains they discovered, 0.3% have folder structures that are easy to guess and could therefore be read by anyone. This leads to over 11,000 publicly accessible files containing everything from user personal information to credit card accounts!
As part of the experiment, Symantec used seven common words: backup, backups, archive, logs, database, databases, and VHDS.
“Not all of the data accessed was sensitive, but some certainly was,” according to a Symantec whitepaper titled “Mistakes in the IaaS could put your data at risk.” “For example, during our investigation, we found an account belonging to a payment processing company. The publicly accessible source lists include many “bacpac” files, which are backup copies of database files. Such files are goldmines for attackers, as they can contain countless sensitive information. In this case, it contained usernames, passwords, credit card transaction logs with the last four digits of each card, email addresses, and other account details.”
What Symantec's report wants to emphasize is the critical message - that the responsibility for implementing Infrastructure-as-a-Service security controls lies primarily with the cloud.

