The APNIC registrar, responsible for the distribution of IP addresses in the Asia-Pacific region, reported an incident in which a SQL dump of the Whois service was exposed, including confidential data and password hashes. Notably, this is not the first leak of personal data at APNIC — in 2017, the Whois database was also made publicly accessible due to staff oversight.
During the implementation of RDAP support, intended to replace the WHOIS protocol, APNIC staff uploaded the SQL dump of the database used in the Whois service to Google Cloud storage but did not restrict access. Due to a configuration error, the SQL dump was publicly available for three months, and this fact was only discovered on June 4, when an independent security researcher brought it to attention and notified the registrar of the issue.
The SQL dump contained 'auth' attributes, which included password hashes for modifying Maintainer and Incident Response Team (IRT) objects, as well as some confidential information about clients that is not displayed in Whois during regular queries (typically additional contact details and notes about the user). In the event of password recovery, attackers could have altered the content of the fields with parameters for block owners in Whois. (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community. The Maintainer object defines the entity responsible for modifying the group of records related through the 'mnt-by' attribute, while the IRT object contains contact details of the administrators responsible for responding to problem notifications. The information about the hashing algorithm used for passwords is not provided, but in 2017, outdated algorithms MD5 and CRYPT-PW (8-character passwords with hashes based on the UNIX crypt function) were used for hashing.
After the incident was discovered, APNIC initiated a password reset for objects in Whois. On APNIC's side, no signs of illegitimate actions have been found so far, but there is no guarantee that the data did not fall into the hands of malicious actors, as complete access logs for files in Google Cloud are lacking. As with the previous incident, APNIC promised to conduct an audit and make changes to technological processes to prevent similar leaks in the future.
Source: opennet.ru
