The Star Malaysia

Details of 4.9 million students may have been hacked

- By SANDHYA MENON, SHARMILA NAIR and QISHIN TARIQ newsdesk@thestar.com.my

KUALA LUMPUR: The Education Ministry’s online school examinatio­n analysis system, Sistem Analisis Peperiksaa­n Sekolah (SAPS), has been taken down.

This followed a tip-off to various media that the sapsnkra.moe.gov.my/ibubapa2/index.php site, introduced in July 2011 to centralise examinatio­n results from all states, was vulnerable to an attack called SQL Injection.

The technique is said to enable an attacker to retrieve student data stored on the site, which covers approximat­ely 10,000 national primary and secondary schools.

The tip-off via e-mail alleged that 4.9 million students’ details, along with their parents’ MyK ad numbers, were compromise­d.

It also carried a large attachment containing multiple text files with what looked like student records.

The Education Ministry could not be reached for comments.

Cyber Security Malaysia senior vice-president Dr As wami Ariffin said this exploit was simple to take advantage of as the connection to the site was not secured.

“So, to mitigate, the system owner must reconfigur­e the system with a secure connection.

“This set-up is compulsory especially when it involves database at the back end,” he said.

Aswami said while Cyber Security Malaysia was a trusted government agency that would be able to assist in securing government websites, it was up to the system owner to engage its services.

“It is advisable for the system owner to conduct a web penetratio­n test so that security weaknesses could be uncovered and reconfigur­ed,” he said.

IT security services company LGMS founder C.F. Fong said websites would not be vulnerable to the SQL injection attack if vulnerabil­ity assessment and fixes were done properly.

Newspapers in English

Newspapers from Malaysia