Don't leave the keys in the door

They say opportunity makes the thief – which is why it is not worth disregarding the basic recommendations that the authors of Quick.Cms and Quick.Cart give users as part of an awareness campaign under the slogan "Protect your website from intruders!". Allow me a small comparison, because in my opinion securing a website is much like securing a home.

Is that really so, and what are the consequences for both parties?

  • Never leave the keys in the door on the outside.

    In other words, don't make the intruder's job easier. Leaving the default path and access details for the admin panel unchanged may mean that not a hacker, but simply someone familiar with the OpenSolution scripts, can – although they should not – enter the admin panel and cause damage.

    In the case of entering someone's home, the law is clear: Under Article 193 of the Polish Criminal Code, whoever intrudes into another person's house, flat, premises, room or fenced area, or fails to leave such a place despite the demand of an authorised person, is liable to a fine, restriction of liberty or imprisonment for up to one year.

    In the case of a break-in or intrusion into a website without the consent of an owner who has not changed the factory access settings for the admin panel, there is also no doubt:
    Article 287 § 1. Whoever, in order to obtain a financial benefit or to cause damage to another person, without authorisation, affects the automatic processing, collection or transmission of computer data, or changes, deletes or enters a new record of computer data, is liable to imprisonment from 3 months to 5 years. § 2. In a case of lesser gravity, the perpetrator is liable to a fine, restriction of liberty or imprisonment for up to one year.


    I asked my friends at legalniewsieci.pl for advice – and what did I learn?

    The Polish legislator ensures that our home computer is also duly protected by law. Criminal-law protection is provided by Article 267, introduced into the Criminal Code in 2008, which reads:

    §1. Whoever, without authorisation, gains access to information not intended for them by opening a sealed letter, connecting to a telecommunications network, or breaking or bypassing its electronic, magnetic, IT or other special security measures, is liable to a fine, restriction of liberty or imprisonment for up to 2 years.

    § 2. The same penalty applies to whoever, without authorisation, gains access to all or part of an IT system.

    § 3. The same penalty applies to whoever, in order to obtain information to which they are not entitled, installs or uses a listening, visual or other device or software.

    § 4. The same penalty applies to whoever discloses to another person information obtained in the manner specified in § 1–3.

    As Daniel Gatner assured us, it is worth becoming familiar with its wording, as well as with the other provisions on offences against the protection of information described in Chapter XXXIII of the Polish Criminal Code. Reading them makes it clear that the ordinary computer user – who uses a number of admin panels exposed to attack from outside every day – is not left defenceless, and that the phenomenon known as hacking has already found its place and regulation in the Polish legal system. Incidentally, it is worth pointing out that even interfering with access to an IT system in order to disable its protective function, without destroying it, is already an offence.


    Phew. All right. So what does this mean?
    In each of the examples quoted above the law is broken, and regardless of whether the perpetrator knows what they are doing or not, an offence is committed. Formally, if there is a login panel and authentication is required, we can sleep soundly. Anyone who enters the admin panel without our consent commits an offence, just like someone who crosses the threshold of our home without our consent. But does that guarantee our safety? So is it worth leaving the admin panel login and password unchanged? Is it worth not locking the door of your own home from the inside? Perhaps in a country governed by the Code of Hammurabi it would make sense. In the real world, anyone who values their privacy and their own safety, and doesn't have a squad of commandos, locks the door.

  • Never leave the keys under the doormat

    The default path to the admin panel is known to anyone who has ever worked with Quick.Cms or Quick.Cart. The authors recommend changing it before launching a website so as not to make things easier for potential intruders. This reduces the chance of a break-in even more than simply changing the login and password.
    Just as we take our key with us when we leave home and don't leave it in a well-known place with a note saying "the keys are under the doormat", on our own website we don't reveal the path to the admin panel. In fact, the path should be changed and kept in your head, not on a yellow sticky note on the monitor.

    There is no article in the Criminal Code covering user carelessness, and no lawyer can help with that. It is worth remembering, however, that whether an intruder uses the key from under the doormat or a crowbar, an intrusion is still an intrusion. The absence of damage after such an intrusion does not change how the act is classified. It may, however, be a mitigating circumstance when deciding on the perpetrator's sentence.

  • Never ignore warnings

    If the alarm in your home somehow goes off or something unusual happens, it usually displays messages about possible faults. You then call a specialist and ask what is going on. In the same way, the new versions of Quick.Cms EXT and Quick.Cart EXT include warning and information messages that are displayed after you log in to the admin panel:

    • if the default login and password have not been changed: Change the login and password in the configuration!
    • Last login: ... shows the date of the last login – useful if you remember when you last logged in.
    • The last backup is more than ... days old. Create a backup » – a reminder to make a backup in case of an intruder's interference.
    • Improve your website's security. Find out more in the recommendations. – admittedly a slogan, but thanks to the link you can always use the support materials in the documentation on opensolution.org.

    Messages, whether at home or in the admin panel, are not there for decoration. The authors have plenty of experience with clients who ran into serious trouble because they did not follow the recommendations. That is why, for the past year, OpenSolution has been running regular script security training for its Partners and awareness campaigns aimed at Quick.Cart and Quick.Cms users. Perhaps security companies should run similar campaigns, so that homeowners could feel more confident and their homes would be better – because consciously – protected.


  • Conclusion

    Following the rules above will go a long way towards protecting website owners – just like homeowners – from uninvited guests. Importantly, these are preventive measures that cost nothing but a moment of your time and a little imagination.


    If you would like to learn more about securing your website,
    please read the article in the guide prepared by OpenSolution


    The legal aspects discussed in this article were consulted
    with the lawyers of legalniewsieci.pl

    Legalniewsieci.pl

    author: Jarek Migoń
    grafiQa.pl


Add a comment

Formularz chroni reCAPTCHA – obowiązują Polityka prywatności i Warunki korzystania Google.

Share this address