Папын албан ёсны залбирлын аппликейшн 700 мянган хэрэглэгчийн мэдээллийг алджээ

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Ватиканы “Click To Pray” аппликейшн нь аюулгүй байдлын ноцтой цоорхойгоос болж 700 мянга гаруй хэрэглэгчийн хувийн мэдээллийг ил болгосон байна.

“BobDaHacker” хэмээх цагаан малгайт хакерын илрүүлснээр, уг аппликейшн нь хэрэглэгчийн ID дугаарыг дарааллаар нь өөрчлөх замаар бусад хүний нэр, имэйл хаяг, улс орон, төрсөн огноо зэрэг мэдээллийг хэн ч авах боломжтой байжээ. Энэхүү аюулгүй байдлын сул тал нь ямар ч баталгаажуулалтгүй, энгийн API хүсэлтээр мэдээлэл татах боломж олгож байсан нь хэрэглэгчдийг фишинг халдлагад өртөх өндөр эрсдэлд оруулсан байна.

Хакер энэ оны нэгдүгээр сард Ватиканы холбогдох хүмүүст энэ талаар мэдэгдсэн ч долоон сарын турш ямар ч хариу аваагүй гэв. Эцэст нь тэрээр асуудлыг олон нийтэд дэлгэсний дараа л холбогдох албаныхан аюулгүй байдлын нөхөөсийг хийж, зөвшөөрөлгүй мэдээлэл татах боломжийг хаажээ.

Техникийн хувьд уг аппликейшн нь “Node.js”-ийн “Express” фрэймворк дээр суурилсан байсан бөгөөд хэрэглэгчдийн мэдээллийг хязгаарлалтгүйгээр татах боломжтой байсан нь аюулгүй байдлын хувьд маш сул байсныг харуулж байна. Хэдийгээр одоо аюулгүй байдлын цоорхойг зассан ч энэ хэрэг нь албан ёсны аппликейшнүүдийн аюулгүй байдалд анхаарах шаардлагатайг сануулсан үйл явдал боллоо.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

On January 20, 2019, Pope Francis delivered his weekly Angelus to St Peter’s Square from a window in the Vatican’s Apostolic Palace. In it, he enjoined the faithful to join him on the Church’s then-new Click To Pray app—helpfully modelled by a nearby priest, wielding a tablet. Hundreds of thousands of people signed up in the years that followed.

But maybe they shouldn’t have, because it turns out the Click To Pray app was, until very recently, absolutely rife with info-leaking security holes. White-hat hacker BobDaHacker revealed in a July 24 blog post (via The Register) that “The Pope’s official app exposes 700,000+ user emails.” The vulnerability has since been fixed, but it seems only after BobDaHacker went public with their investigation—inquiries made by the hacker and by journalists stretching back to January this year went unanswered.

The vulnerability itself was pretty simple. When you sign up for Click To Pray, the site hands your user account an ID number. The first guy to sign up was one, the next was two, and so on, all the way into the hundreds of thousands.

Problem is, by visiting https://api.clicktopray.org/user/users/[ID number goes here], you could retrieve the name and email address, plus some other info, for whoever had the ID number you inputted. “No authorization check. No ownership validation. Just increment the number and get someone else’s data. The Lord provides,” writes BobDaHacker.

“Email address. First name. Last name. Country. Date of birth (or as their backend calls it, borned_date, because apparently bad grammar isn’t a sacrament). Role. Whether the account has been deleted. All of it, for any user, no questions asked,” they continue. “The response headers also have X-Powered-By: Express because the Vatican is running its prayer infrastructure on the framework you learn in week two of a Node.js bootcamp.” I’m not smart enough to understand that, but it sounds witheringly funny.

A cherry on the parfait is that Click To Pray didn’t rate limit access, meaning it would be trifling for a malicious actor to scrape the details of every single one of the app’s users in the blink of an eye. As BobDaHacker points out, the kind of people who are going to be using the Pope’s iPad app are likely “older, less tech-savvy, and deeply trusting of anything associated with the Vatican,” which makes this data into “a phishing goldmine.

“Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link. Grandma is clicking that. Every time.” To make matters worse, emails from the app sparked a warning that “This email has failed its domain’s authentication requirements,” meaning that “the real emails from Click To Pray already look like phishing.”

The good news is: the problem now seems to be fixed, albeit very belatedly. “I found this in early January 2026 and on January 3rd I emailed nine people,” says BobDaHacker, listing various Vatican and Click To Pray-related emails. “No response. From any of them.”

It was only when BobDaHacker brought the information to a journalist and wrote their blog post that anything seemed to change. “Seven months of silence, and then, without a word to me, GET /user/users/{id} quietly stopped handing out the good stuff,” they wrote. “The authorization check is there now: request your own user ID and you still get your email back, request someone else’s and you get a public profile.” I’ve even signed up for the app myself—see you there—and the email I received did not set off any alarm bells in my client. Thank god.

2026 games: All the upcoming games
Best PC games: Our all-time favorites
Free PC games: Freebie fest
Best FPS games: Finest gunplay
Best RPGs: Grand adventures
Best co-op games: Better together

- Зар сурталчилгаа -

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img