State of Ohio Cloud Database Porn-Bombed
By Peter Berton
COLUMBUS, Ohio – Combine a state government database tracking oil and gas wells, an FTP interface with no password protection and someone wanting to store videos in the cloud, and what do you get? If you’re the Ohio Department of Natural Resources, you find yourself embarrassed by the sudden public revelation your database contains porn.
The department discovered two porn videos and several music files stored in its Risk Based Data Management System. The system was designed to store data for the more than 100,000 wells permitted since 1980.
According to spokeswoman Eileen Corson, the videos and music files were uploaded via an unprotected FTP site normally used by oil and gas companies to transfer maps and other large files to the database. Corson explained that because the database lies outside the department’s firewall — and therefore is not connected to the internal network — no one saw any reason to password-protect the FTP server.
The assumption was proven erroneous on Feb. 21, when an unknown individual uploaded the files, which were not discovered until March. Compounding the matter, instead of alerting the department, the person who discovered the unauthorized uploads contacted the local newspaper.
“Someone was using [the database] as cloud storage,” Corson told The Columbus Dispatch. “Unfortunately, that happens.”
The department removed the offending files and added password-protection to the server.