India’s national logistics portal exposed sensitive personal data, trade records


Source: techcrunch.com techcrunch.com

Key Topics in this News Article:

News Snapshot:

India’s state-owned logistics portal has fixed misconfigurations and vulnerabilities that exposed sensitive personal data and various state and private trade records. Called the National Logistics Portal-Marine, the website made the sensitive and private data public due to misconfigured Amazon S3 buckets. It also carried a JavaScript file that included login credentials into the web source code. Security researcher Bob Diachenko found the issues with the Indian portal through the open-source security tool TruffleHog. Diachenko told TechCrunch that the exposed data included full names, nationality, date of birth, gender, passport numbers, passport issuing authority and expiration date that various crew members...