Flawed API of US Postal Services Exposed 60 Million Users Data
A ruinous security flaw in Application program Interface of US Postal Services exposed personal data of over 60 million usersover the course of 2017 & 2018.
This vulnerability on USPC’s website allowed anyone with an account at usps.com to view personal information & account details of other users. In some cases, this flaw even allowed users to modify the details in the affected accounts. The leaked information included user name, user ID, e-mail address, account number, street addresses & contact numbers of the users.
An anonymous researcher discovered this problem a year ago & informed US Postal Services, however, USPC failed to pay heed to researcher’s warning at that time.
USPS patched this issue last week when a cyber security investigator, Krebs flagged it.
Insight into the API Defect
The root-cause of the vulnerability is hitched to an authentication weakness in the site’s Application program Interface- an array of tools that defines how different parts of an online application like Web Pages & Database should interact.
The API of US Postal Services involved in issue was tied to a Postal Service Initiative named as “Informed Visibility”. According to US Postal Services, it was designed to let advertisers, Bulk mail sending services & other businesses extend the frontiers of their profession by enabling them the access to near real-time tracking data.

Apart from exposing near real-time data about the mail campaigns & packages; the flaw enabled the logged in users access the accounts belonging to others & harvest their personal information. There are positives that compromised API would have let an attacker pull off anything from as many as 60 million USPS customer accounts.
Read More :- Click here
 
 
Comments
Post a Comment