Nebraska court vulnerability pointed out as example at hacker conference (2024)

Live

WATCH LIVE TONIGHT: Democratic National Convention continues in Chicago

Alert Top Story

  • Lori Pilger
  • 0

The Nebraska Supreme Court found itself in an unwelcome spotlight as an example of what not to do at last weekend's Def Con.

At a talk Saturday in Las Vegas at an annual security conference that draws thousands of hackers, researchers and professionals, Bill Demirkapipointed out that 15,000 developer secrets were hard-coded into the state's court software and other website issues he was able to find that can make systems more vulnerable to cyberattacks.

The independent security researcher who gained attention as a teenager in 2019for exposing vulnerabilities in his high school's software works now to find security problems.

In his talk, Demirkapi said he was able to find hundreds of username and password details linked to Nebraska’s Supreme Court and its IT systems.

He also said he was able to obtain the details needed to gain access to Stanford University’s Slack channels and over a thousand authentication keys of OpenAI customers.

People are also reading…

Still, it was a group Nebraska State Court Administrator Corey Steel would rather not have been among.

This week, he said it came as a bit of a surprise, though he got a brief heads-up a day earlier from the researcher.

It's never welcome news to be used in an example like this, Steel said.

But, thankfully, nothing bad happened as a result of the vulnerability, which was discovered back in December 2022.

Nebraska court vulnerability pointed out as example at hacker conference (1)

Steel said the researcher notified the court then that he had found a document on the dark web that could make their systems vulnerable to attack.

Steel said a programmer who worked for the state had saved a file of passwords to some court systems in a cloud vault, which the researcher was able to hack.

"It just so happened one document of ours — and it was only one document — was uploaded to the dark web," he said.

When they were notified, they immediately changed all passwords, even though some already were outdated. He said then they worked with the Office of the Chief Information Officer, which did a vulnerability test to make sure no one was accessing those systems from an IP address not owned by the courts.

"It showed that there was no outsider IP address using those passwords to infiltrate the systems," he said.

Not surprisingly, Steel said it was a huge relief.

"It's difficult, because you feel sometimes that you're one step behind," he said of the ever-evolving cyberthreats online.

But, in this case, it worked out.

"We were able to get on top of it right away and close the loophole and make sure that nothing was infiltrated and that no information was disseminated from any of our systems," Steel said.

He said he was thankful it was brought to their attention because it allowed them to act to make sure the court's systems were secure.

"It also strengthened the system in a sense," Steel said, "because it made us continue to review policies, procedures and implement new strategies to make sure that we are secure."

In this year's State of the Judiciary Address, Chief Justice Mike Heavican told state lawmakers of the need to upgrade protection for the court's online records.

"Much like banks, retail outlets, and health care providers, we handle a large amount of confidential information online — including bank account numbers, Social Security numbers, credit card information, and other financial details," he said.

They also store sensitive information on paternity and child custody and criminal case data, he said.

Heavican said the Kansas court system, which fell victim to a foreign cyberattack last fall, "serves as a warning for the rest of us."

"Without needed upgrades we must consider ourselves equally vulnerable," he told lawmakers.

Top Journal Star photos for August 2024

Nebraska court vulnerability pointed out as example at hacker conference (2)

Nebraska court vulnerability pointed out as example at hacker conference (3)

Nebraska court vulnerability pointed out as example at hacker conference (4)

Nebraska court vulnerability pointed out as example at hacker conference (5)

Nebraska court vulnerability pointed out as example at hacker conference (6)

Nebraska court vulnerability pointed out as example at hacker conference (7)

Nebraska court vulnerability pointed out as example at hacker conference (8)

Nebraska court vulnerability pointed out as example at hacker conference (9)

Nebraska court vulnerability pointed out as example at hacker conference (10)

Nebraska court vulnerability pointed out as example at hacker conference (11)

Nebraska court vulnerability pointed out as example at hacker conference (12)

Nebraska court vulnerability pointed out as example at hacker conference (13)

Nebraska court vulnerability pointed out as example at hacker conference (14)

Nebraska court vulnerability pointed out as example at hacker conference (15)

Nebraska court vulnerability pointed out as example at hacker conference (16)

Nebraska court vulnerability pointed out as example at hacker conference (17)

Nebraska court vulnerability pointed out as example at hacker conference (18)

Nebraska court vulnerability pointed out as example at hacker conference (19)

Nebraska court vulnerability pointed out as example at hacker conference (20)

Nebraska court vulnerability pointed out as example at hacker conference (21)

Nebraska court vulnerability pointed out as example at hacker conference (22)

Nebraska court vulnerability pointed out as example at hacker conference (23)

Nebraska court vulnerability pointed out as example at hacker conference (24)

Nebraska court vulnerability pointed out as example at hacker conference (25)

Nebraska court vulnerability pointed out as example at hacker conference (26)

Nebraska court vulnerability pointed out as example at hacker conference (27)

Nebraska court vulnerability pointed out as example at hacker conference (28)

Reach the writer at 402-473-7237 or lpilger@journalstar.com.

On Twitter @LJSpilger

0 Comments

'); var s = document.createElement('script'); s.setAttribute('src', 'https://assets.revcontent.com/master/delivery.js'); document.body.appendChild(s); window.removeEventListener('scroll', throttledRevContent); __tnt.log('Load Rev Content'); } } }, 100); window.addEventListener('scroll', throttledRevContent); }

Sign up for our Crime & Courts newsletter

Get the latest in local public safety news with this weekly email.

Nebraska court vulnerability pointed out as example at hacker conference (2024)
Top Articles
Fit Kitty Coco Bae
Harveys Southend Auto Cars
Funny Roblox Id Codes 2023
Golden Abyss - Chapter 5 - Lunar_Angel
Www.paystubportal.com/7-11 Login
Joi Databas
DPhil Research - List of thesis titles
Shs Games 1V1 Lol
Evil Dead Rise Showtimes Near Massena Movieplex
Steamy Afternoon With Handsome Fernando
Which aspects are important in sales |#1 Prospection
Detroit Lions 50 50
18443168434
Zürich Stadion Letzigrund detailed interactive seating plan with seat & row numbers | Sitzplan Saalplan with Sitzplatz & Reihen Nummerierung
Grace Caroline Deepfake
978-0137606801
Nwi Arrests Lake County
Justified Official Series Trailer
London Ups Store
Committees Of Correspondence | Encyclopedia.com
Pizza Hut In Dinuba
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
Free Online Games on CrazyGames | Play Now!
Sizewise Stat Login
VERHUURD: Barentszstraat 12 in 'S-Gravenhage 2518 XG: Woonhuis.
Jet Ski Rental Conneaut Lake Pa
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Ups Print Store Near Me
C&T Wok Menu - Morrisville, NC Restaurant
How Taraswrld Leaks Exposed the Dark Side of TikTok Fame
Dashboard Unt
Access a Shared Resource | Computing for Arts + Sciences
Speechwire Login
Healthy Kaiserpermanente Org Sign On
Restored Republic
3473372961
Craigslist Gigs Norfolk
Litter-Robot 3 Pinch Contact & DFI Kit
Moxfield Deck Builder
Senior Houses For Sale Near Me
Whitehall Preparatory And Fitness Academy Calendar
Trivago Myrtle Beach Hotels
Anya Banerjee Feet
Three V Plymouth
Poe Self Chill
Senior Houses For Sale Near Me
Funkin' on the Heights
Vci Classified Paducah
Www Pig11 Net
Ty Glass Sentenced
Latest Posts
Article information

Author: Otha Schamberger

Last Updated:

Views: 5695

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Otha Schamberger

Birthday: 1999-08-15

Address: Suite 490 606 Hammes Ferry, Carterhaven, IL 62290

Phone: +8557035444877

Job: Forward IT Agent

Hobby: Fishing, Flying, Jewelry making, Digital arts, Sand art, Parkour, tabletop games

Introduction: My name is Otha Schamberger, I am a vast, good, healthy, cheerful, energetic, gorgeous, magnificent person who loves writing and wants to share my knowledge and understanding with you.