Offensichtlich war es nach dem Login möglich, die Daten aller angemeldeten User zu sehen - inklusive Adresse, Telefonnummer und Geburtsdatum. Der Beschreibung der StZ zufolge wohl durch einfache Änderung eines Links. Besonders kritisch ist natürlich, dass es sich bei den Angemeldeten zumeist um Kinder und Jugendliche handeln dürfte - dass die gesamten Daten einsehbar waren, war geradezu ein Freifahrschein für Pädophile.
Umso schlimmer, dass der Sender auf die Mail des Vaters, der die Lücke entdeckt hatte, tagelang nicht reagierte und erst aktiv wurde, als die Zeitung nachfragte. Gerade wenn es um Kinder geht, sollte man besonders sensibel sein und nicht mauern und aussitzen. Die Schutzfunktion, dass die Anmeldung erst durch Bestätigung durch die Eltern aktiv wurde, wurde dadurch auf jeden Fall völlig nutzlos.
Update: Der KiKa hat die Seite mittlerweile komplett deaktiviert, um sie nun auf Herz und Nieren zu prüfen. Laut einem neuen Bericht der StZ wurde der Fehler durch einen einzigen Klick verursacht.
"Es war ein einziges Häkchen falsch gesetzt, deshalb war der betroffene Bereich nicht geschützt", sagte die Sprecherin, "es war schlicht menschliches Versagen.
Die Mail, mit der der Sender gewarnt wurde, ist offensichtlich in einem Spam-Filter hängengeblieben, der Sender hat den Finder der Lücke mittlerweile offenbar kontaktiert.





Kommentare
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/plugins/serendipity_plugin_comments/serendipity_plugin_comments.php on line 252
Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /www/htdocs/w00b3989/include/plugin_api.inc.php on line 1041