Saturday, July 2, 2022
No Result
View All Result
Donate
Sandra Talk Show
  • HOME
  • BROWSEHOT
    • LATEST
    • TRENDING
    • NEWSHot
  • LIVE TVNEW
  • VIDEOS
  • ENTERTAINMENTNEW
  • FEATURES
  • OTHER
    • ADVERTISE
    • PRIVACY POLICY
No Result
View All Result
Sandra Talk Show
Home Browse

Update! Our Servers Not Hacked – NIMC Responds To Hacker’s Claims

6 months ago
in Browse
A A
0
Share on FacebookShare on Twitter
ADVERTISEMENT

The issue of data security has been at the forefront since the federal government introduced the national identity database.

In December 2021, Isa Pantami, minister of communications and digital economy, had announced that 71 million Nigerians had been captured on the database.

As more Nigerians registered, is the NIN database free from hackers?

On Monday, a hacker identified as Sam claimed he successfully found a bug on the server of Nigeria’s National Identity Management Commission (NIMC) — revealing how easy it was for him to breach the server and access the personal information of millions of people.

According to Sam, he came across these data while sourcing for something else to help him decompile some applications he was working on.

“As usual, I am hunting for something in the source code of the application, As the scope is huge, So I collected all the applications and decompiled them all at once with apktool with this command: find . -iname “*.apk” -exec apktool d -o {}_out {} \;” he said.

“Now I started to look for something juicy in decompiled files, but as there are about 50+ applications, I can’t look at each of them manually right? I just got an idea of nuclei, and boom I knew there are templates for android applications, I just downloaded them and, started nuclei on the whole directory,

“After 18–19 mins of a run, Nuclei gave an output saying S3 Bucket Found, I tried to access it via AWS CLI, and it’s like: Acess denied, No luck there.

“Then after a few mins of running, I’ve got one more output for s3 bucket, I casually tried to access it without any hope, and damn! the s3 bucket is full of juice.

“And I was just like: I just simply got access to their data of internal files, Users, and everything they have, I can download everything, Even the whole bucket.”

The hacker also posted the data he obtained in the process — a copy of the national identity slip from NIMC but defaced it to hide vital information.

A security expert explained that Amazon secures S3 buckets by default but for a bucket to be publicly accessible to any hacker, as was the case with Sam, someone must have leaked it.

Hours later, the hacker recanted that the leaked sever was not from any Nigerian portal but Tecno Mobile.

He said he reported the case to Tecno, and the bug fixed.

He also edited the article published on Medium and removed a copy of the national ID posted as a screenshot in the story — but failed to explain why he mentioned Nigeria’s ID database in the previous version.

Speaking with TheCable on the development, Boye Adegoke, senior program manager at Paradigm Initiative, said there is the possibility of negligence on the part of NIMC.

“If the story is true, it is negligence on the part of NIMC, but what is more worrisome is the fact that after this, what happens next? Are we going to talk and act as if nothing happened? Will someone get punished?” Adegoke asked.

The data privacy activist noted that the approach and attitude of NIMC toward the management of national data is poor.

“I wouldn’t really be surprised if this is true because I have always believed that the cyber security approach and our attitude show we don’t understand the process and how it works,” he added.

In a statement on Tuesday, NIMC said its servers are secure for identity management and optimised.

“The National Identity Management Commission (NIMC) wishes to inform the public that its servers were not breached but are fully optimised at the highest international security levels as the custodian of the most important national database for Nigeria,” the statement reads.

“The NIMC Director-General stated that the Commission does not use nor store information on the AWS cloud platform or any public cloud despite the usefulness of the NIMC Mobile App available to the public for accessing their NIN on the go.”

Tobiloba Ayinde

RelatedPosts

Classmate of Blossom Chukwujekwu’s new wife defends her age and body size

1 month ago

Davido’s Baby Mama Chioma Wows Many As She Joins The ‘Low-Cut Gang’

1 month ago

Nigerian Railway Corporation cancels resumption of Abuja-Kaduna train service

1 month ago

Alleged Blasphemy: Mob overpowered DSS operatives who tried to save Deborah Samuel – Gov Tambuwal

1 month ago

Drama As Actress Kemi Apesin Acts As Hook Up Client To Nab Online Troll Who Bashed Her

2 months ago

‘I can’t forget how you stood for me when someone didn’t want to work with me’-Toyin Abraham celebrates Ini Edo’s 40th birthday

2 months ago

“You are a bully , always been and always will be, you derive joy from the pains of other women” – Caroline Danjuma drags Linda Ikeji yet again

2 months ago

Nnamdi Kanu’s American lawyer drags Malami, Justice Nyako, Buhari before International Criminal Court

3 months ago

Not All Relationships End Because The Man Left – Ehi Ogbehor Weighs In Nkechi Blessing’s Saga Cites Herself As An Example

3 months ago

Kourtney Kardashian shares behind-the-scenes photos from her Las Vegas wedding to Travis Barker

3 months ago
Load More
Share130Tweet81SendShareShare

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

  • Contact

© 2021 Sandra Talk Show.

No Result
View All Result
  • HOME
  • BROWSE
    • LATEST
    • TRENDING
    • NEWS
  • LIVE TV
  • VIDEOS
  • ENTERTAINMENT
  • FEATURES
  • OTHER
    • ADVERTISE
    • PRIVACY POLICY
  • Login
  • Sign Up

© 2021 Sandra Talk Show.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Accept