A Danish graduate student said he was searching for research material on an IEEE FTP server last week when he stumbled upon the usernames and passwords of about 100,000 members of the professional association.
In a blog post on Tuesday, Radu Dragusin, a teaching assistant and computer science grad student at the University of Copenhagen, said the data appears to have been publicly available for at least a month before he found it.
The login credentials freely available on the site belonged to IEEE members from organizations such as NASA, Stanford University, Apple and Google, Dragusin said.
In addition to usernames and passwords, Dragusin said he was able to access more than 100GB of web server log data containing detailed information on 350 million-plus HTTP requests made by IEEE members over one month.
By accessing the log data, he said he could inspect IEEE.org pages that were accessed by logged in members, and determine when the pages were accessed and from where.
In an email to Computerworld, Dragusin said he discovered the data when looking for free research material from IEEE.
"I was merely surfing the public IEEE FTP server to see if they have a repository of freely available research articles," Dragusin said. "If you go on the FTP server yourself, you will see that the 'uploads' directory is among the most recently modified ones, so I opened it."
The directory contained many more directories including one containing the word "Akamai," which Dragusin said he knew was the name of a well-known content delivery network. He downloaded and decompressed one of the many GNU Zipped Archive files contained in the directory and then discovered detailed web-server logs.
At that point he downloaded everything in the Akamai directory and found more than 100GB of uncompressed log data.
"This looked interesting, because logs are not supposed to be public, as they often contain personal data," Dragusin said. "As a researcher, I saw the opportunity to study the logs to gain some insights into IEEE members, many of whom are researchers and engineers."
A closer inspection of the data showed that many of the log entries contained usernames and passwords.
That finding "was highly unusual and of course transformed this into a serious data breach," he said.
According to Dragusin, the files on the FTP server had been freely accessible since at least August 17.
Information on a Russian site that indexes FTP listings suggests that similar log data was publicly available some time last year as well, he added.
The breach is embarrassing for IEEE as it's a mistake -- storing login credentials in plain text -- that novice security professionals should know to avoid.
Sign up for CIO Asia eNewsletters.