[ISN] Student Files Are Exposed on Web Site

InfoSec News alerts at infosecnews.org
Wed Aug 20 06:37:51 CDT 2008


http://www.nytimes.com/2008/08/19/technology/19review.html

By BRAD STONE
The New York Times
August 18, 2008

The Princeton Review, the test-preparatory firm, accidentally published 
the personal data and standardized test scores of tens of thousands of 
Florida students on its Web site, where they were available for seven 
weeks.

A flaw in configuring the site allowed anyone to type in a relatively 
simple Web address and have unfettered access to hundreds of files on 
the company’s computer network, including educational materials and 
internal communications.

Another test-preparatory company said it stumbled on the files while 
doing competitive research. This company provided The New York Times 
with the Web address of the internal files on the condition that it not 
be named. The Times informed the Princeton Review of the problem on 
Monday, and the company promptly shut off access to that portion of its 
site.

[...]



More information about the ISN mailing list