Skip to content

250,000 Polish Sites With Holes, Among Them Two Thirds of the Courts: the Vendor Will Not Fix the Software Because It Is „Obsolete”

1 min read
Share
250,000 Polish Sites With Holes, Among Them Two Thirds of the Courts: the Vendor Will Not Fix the Software Because It Is „Obsolete”

Two Polish security researchers decided to check how vulnerable their country's internet is. Not on commission from a ministry, not for money - but, as they put it themselves, out of a feeling that the country they live in should be safer. The result they presented at the Def Con conference in Las Vegas is damning: over 10,000 public institutions and around 250,000 sites with security flaws.

Among them are airports, hospitals and government offices. These are not theoretical weaknesses on some forgotten server, but systems through which people's daily lives pass.

Robert Kruczek and Kamil Szczurowski found critical flaws in the content management system Pad CMS, used widely across the Polish administration. Through it they got into over 300 public sites without needing a password. The vendor did not fix the software - the reason being that it has already been declared obsolete and is no longer maintained.

That is the sentence that stings most. The software is not vulnerable because some attacker was a genius, but because the company that sold it decided it was no longer their obligation, and the institutions that bought it carried on using it as if nothing had happened.

The second flaw gave them access to the sites of around two thirds of the Polish judiciary - approximately 245 courts. The two reported their findings to the state through official channels.

What they describe next is the part anyone who has worked with institutions in the Balkans will recognise instantly. Some of the errors were extremely simple to exploit, but were not taken seriously - several software vendors treated the reports as a nuisance. Not as a problem to be solved, but as something ruining their day.

The additional problem they point to is systemic: Poland has no established programmes for rewarding people who report flaws, nor any clear route for reporting a bug in the first place. So two people who want to help have to work out for themselves who to contact.

All of this is happening while Poland is trying to strengthen its cyber defences after a wave of suspected Russian attacks on its energy and water suppliers. Some of those attacks went through exactly this kind of weak protection. That is the context - a country that knows it is a target, and still has a quarter of a million sites with holes in them.

At the end of their talk, Kruczek and Szczurowski said the gruelling work had been worth it, because thanks to it we are all „a little safer”. The tone is modest. There is another way to read it: it took the effort of two enthusiasts to find out what the institutions could have checked themselves, with budget money, at any time.