Mysejahtera Spam Emails Otp Messages Not Due To Database Leak Health Ministry


 



The Health Ministry has denied that spam emails and unsolicited one-time passwords (OTPs) sent out from MySejahtera were due to a database leak.
Instead, it said the incidents were due to the abuse of the application programming interfaces (APIs), which are software intermediaries that allow two applications to talk to each other.
“Based on preliminary investigations and other necessary actions by the National Cyber Security Agency, the sending of the false emails and text messages are caused by abuse of the APIs and not a leak in the MySejahtera database,” the Health Ministry said in a statement today.
Earlier, full-stack developer Phakorn Kiong also told Malaysiakini that there were security vulnerabilities in MySejahtera involving the APIs which were causing the spam emails and OTP messages.
The Health Ministry explained that the MySejahtera check-in feature, which is meant for business premises and others to register for a check-in QR code, requires the applicant to enter their email address or phone number to get an OTP.


It said “irresponsible parties” have used random email addresses and phone numbers to trigger the process of registration.
“If the phone number or email address that was entered randomly does exist, MySejahtera will send an OTP to the owner of the phone number or email address to verify the registration,” it added.
Misuse of MySejahtera website
The Health Ministry said the help function on the MySejahtera website was also used to send spam emails randomly.
“Following these irresponsible actions, the MySejahtera team has increased the level of security for the application and the website to prevent the same incident,” it added.  
Kiong earlier explained that the MySejahtera website did not have any ‘locks’ to prevent outsiders from interfering with the APIs.
“In usual design, there are supposed to be 'keys' which the server can use to identify who is calling the server (as a form of authentication).
“The problem with this design is there are no 'locks' implemented. Anyone can come in and abuse the APIs,” he said.
The incident had received widespread attention since last night after many people reported receiving spam emails and unsolicited OTP messages purportedly from MySejahtera. - Mkini


Artikel ini hanyalah simpanan cache dari url asal penulis yang berkebarangkalian sudah terlalu lama atau sudah dibuang :

http://malaysiansmustknowthetruth.blogspot.com/2021/10/mysejahtera-spam-emails-otp-messages.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+MalaysiansMustKnowTheTruth+%28Malaysians+Mus

Kempen Promosi dan Iklan
Kami memerlukan jasa baik anda untuk menyokong kempen pengiklanan dalam website kami. Serba sedikit anda telah membantu kami untuk mengekalkan servis percuma aggregating ini kepada semua.

Anda juga boleh memberikan sumbangan anda kepada kami dengan menghubungi kami di sini
Mysejahtera Exploits Allow Others To Send Out Fake Emails Otp Messages Expert

Mysejahtera Exploits Allow Others To Send Out Fake Emails Otp Messages Expert

papar berkaitan - pada 20/10/2021 - jumlah : 240 hits
The MySejahtera app has been revealed to have security vulnerabilities that allow anyone to send out emails or one time passwords on behalf of the app leading to concerns over personal data breaches The MySejahtera team has since said they ...
Health Ministry Timah And Omar Whisky Labels Not Under Food Act And Food Regulations

Health Ministry Timah And Omar Whisky Labels Not Under Food Act And Food Regulations

papar berkaitan - pada 23/10/2021 - jumlah : 435 hits
Since the whisky brand took the limelight last week some groups and even the Minister in the Prime Minister s Department Idris Ahmad had called for the local alcoholic beverage company to immediately change its Timah brand and the picture u...
Education Ministry Told To Intervene For School Guards Not Paid Salaries

Education Ministry Told To Intervene For School Guards Not Paid Salaries

papar berkaitan - pada 20/10/2021 - jumlah : 211 hits
Jaringan Pekerja Kontrak Kerajaan has called on the Education Ministry to intervene over unpaid salaries owed to security guards in 10 government schools in Perlis It said the private company managing those schools have not paid salaries to...
Health Minister Invokes Act 342 Says Political Gatherings For Election Not Allowed From Tomorrow

Health Minister Invokes Act 342 Says Political Gatherings For Election Not Allowed From Tomorrow

papar berkaitan - pada 25/10/2021 - jumlah : 480 hits
The Ministry of Health today announced that it is prohibiting all activities gatherings or social meetings related to political campaigning for next month s Melaka polls Health Minister Khairy Jamaluddin cited the Prevention and Control of ...
Health Ministry Malaysia S Covid 19 Vaccine Development At Proof Of Concept Stage

Health Ministry Malaysia S Covid 19 Vaccine Development At Proof Of Concept Stage

papar berkaitan - pada 8/10/2021 - jumlah : 289 hits
PARLIAMENT The current status of the country s first Covid 19 vaccine development is at the laboratory or proof of concept stage the Dewan Rakyat was told today Deputy Health Minister II Aaron Ago Dagang said the research conducted for the ...
Health Ministry Addresses Two Deaths Involving Vaccinated Individuals

Health Ministry Addresses Two Deaths Involving Vaccinated Individuals

papar berkaitan - pada 24/10/2021 - jumlah : 185 hits
The Health Ministry has responded to two deaths involving vaccinated individuals The first was a 78 year old woman who tested positive for Covid 19 while in a nursing home in Kuala Lumpur In a statement yesterday Kuala Lumpur and Putrajaya ...
Health Ministry Plans To Meet With Anti Vaccine Groups

Health Ministry Plans To Meet With Anti Vaccine Groups

papar berkaitan - pada 19/10/2021 - jumlah : 227 hits
PARLIAMENT The Health Ministry plans to meet with anti vaccine groups to provide them with facts and information on the Covid 19 vaccine based on authentic clinical studies the Dewan Negara was told today Deputy Health Minister Dr Noor Azmi...
Malacca Election Health Ministry To Accept Whatever The Cabinet Decides

Malacca Election Health Ministry To Accept Whatever The Cabinet Decides

papar berkaitan - pada 8/10/2021 - jumlah : 213 hits
The Health Ministry will accept whatever decision the cabinet makes tomorrow on holding a state election in Malacca its minister Khairy Jamaluddin said Khairy told a press conference that the health authority will prepare whatever procedure...
Lala Kent Insists Demi Lovato S California Sober Approach Is Not Real And Disrespectful

Lala Kent Insists Demi Lovato S California Sober Approach Is Not Real And Disrespectful

papar berkaitan - pada 7/10/2021 - jumlah : 171 hits
Lala Kent Insists Demi Lovato s California Sober Approach Is Not Real and DisrespectfulSource https www aceshowbiz com news view 00178180 html LalaKentInsistsDemiLovato CaliforniaSoberApproachIsNotReal Disrespectful
Cultural Reasons Make Malaysians Target For Human Trafficking Says Firm

Makan Steamboat Dapat Henna Free

Cops Probing Into Foreigner S Death In Custody At Klia

15 Kafe Di Johor Bahru Instagrammble Muslim Friendly

15 Cozy Christmas Wreath Designs For A Warm Welcome

Is Tiong China S Tourism Minister Or Malaysia S Asks Wan Fayhsal

Suspek Buruan Kes Samun Toreh Dicekup

A Botched Shot


echo '';
Info Dan Sinopsis Drama Berepisod Lara Kasih Slot Samarinda TV3

Senarai Lagu Tugasan Konsert Minggu 2 Gegar Vaganza 2024 Musim 11

Keputusan Markah Peserta Konsert Minggu 1 Gegar Vaganza 2024 Musim 11

Senarai Lagu Tugasan Konsert Minggu 1 Gegar Vaganza 2024 Musim 11

Info Dan Sinopsis Drama Berepisod Dhia Kasyrani Slot Akasia TV3


Olahraga Terbaik Untuk Penderita Diabetes Tipe 2

Leveraging Zero Click Searches

Ibu Bapa Elak Pilih Kasih Dengan Anak Anak

Senarai Calon Top 5 Festival Filem Malaysia Ke 33

Resipi Sambal Goreng Jawa Paling Sedap Cara Masak Pun Mudah Je

Pertandingan Akhir Memasak Kisahkariku Berakhir Meriah Kari Ketam Jadi Pilihan Juri