{"id":22906,"date":"2025-05-26T14:48:05","date_gmt":"2025-05-26T13:48:05","guid":{"rendered":"http:\/\/dubawa.org\/dir\/?p=22906"},"modified":"2025-05-26T14:48:07","modified_gmt":"2025-05-26T13:48:07","slug":"claim-efcc-website-volatile-misleading","status":"publish","type":"post","link":"https:\/\/dubawa.org\/dir\/claim-efcc-website-volatile-misleading\/","title":{"rendered":"Claim EFCC website volatile, misleading"},"content":{"rendered":"\n<p class=\"has-cyan-bluish-gray-background-color has-background wp-block-paragraph\"><strong>Claim: A man <a href=\"https:\/\/x.com\/iam_enriched\/status\/1920798737997111729\">claims<\/a> that because ports 21, 80, and 443 are open on the EFCC website, anyone can easily hack and delete data.<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" width=\"136\" height=\"59\" data-attachment-id=\"21059\" data-permalink=\"https:\/\/dubawa.org\/dir\/national-elections-commission-did-not-dismiss-over-sixty-employees\/misleading-29\/\" data-orig-file=\"https:\/\/i0.wp.com\/dubawa.org\/dir\/wp-content\/uploads\/2024\/12\/MISLEADING.png?fit=136%2C59&amp;ssl=1\" data-orig-size=\"136,59\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"MISLEADING\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/dubawa.org\/dir\/wp-content\/uploads\/2024\/12\/MISLEADING.png?fit=136%2C59&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/dubawa.org\/dir\/wp-content\/uploads\/2024\/12\/MISLEADING.png?resize=136%2C59\" alt=\"\" class=\"wp-image-21059\" title=\"\"><\/figure>\n<\/div>\n\n\n<p class=\"has-background wp-block-paragraph\" style=\"background-color:#b88700\"><strong>Verdict: Misleading. DUBAWA spoke with cybersecurity experts and reviewed port security to find that an open port is not always vulnerable.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Full Text<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On May 9, an X user, <a href=\"https:\/\/x.com\/iam_enriched\">@iam_enriched<\/a>, shared a video (archived <a href=\"https:\/\/archive.ph\/mLWie\" target=\"_blank\" rel=\"noopener\">here<\/a>) of a man alleging that the website of the <a href=\"https:\/\/www.efcc.gov.ng\/efcc\/\" target=\"_blank\" rel=\"noopener\">Economic and Financial Crimes Commission (EFCC)<\/a>, Nigeria\u2019s federal anti-graft agency, was susceptible to attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2018EFCC database is weak, can be deleted\u2019 is superimposed on the video as the unnamed man speaks first about how the fraudulent <a href=\"https:\/\/www.efcc.gov.ng\/efcc\/news-and-information\/news-release\/10994-cbex-efcc-intensifies-search-for-wanted-persons\" target=\"_blank\" rel=\"noopener\">CBEX platform<\/a> has open ports, and then about how the anti-graft agency investigating it also had open ports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cHow can we explain that EFCC\u2019s website is not secure? How come a government institution\u2019s database is not secure? This is the Port 80 TCP of CBEX. This is where they get your information from. It is open. cbex.cx is even more secure. They actually uploaded their website on Cloudflare, which is one of the strongest firewalls to protect their <a href=\"https:\/\/cbex.cx\/pc\/#\/\" target=\"_blank\" rel=\"noopener\">website<\/a>,\u201d he claimed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis is <a href=\"http:\/\/efcc.gov.ng\" target=\"_blank\" rel=\"noopener\">efcc.gov.ng<\/a>. If you look at the port of EFCC, it has port 21 open, port 80 is open, 443 is open\u2026. What does this mean in the world of cybersecurity? When port 21 is open, it simply means that it is an FTP port. This means they are uploading people\u2019s data. It means if they catch a fraudulent person, they send your data. They did not close the outbound,\u201d he added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He claimed anyone with little hacking skills can delete their information from the EFCC database.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/x.com\/iam_enriched\/status\/1920798737997111729\">post<\/a> by @iam_enriched as of May 23 has received thousands of engagements, including over 1,200 likes, 490 reposts, 194 replies, and 784 bookmarks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This claim suggests that the EFCC\u2019s website puts users\u2019 data at risk of a hack and is susceptible to abuse by persons with criminal intent. This major concern prompted us to verify.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Verification<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DUBAWA performed an online search to verify what ports 21, 80, and 443 were. We <a href=\"https:\/\/testbook.com\/question-answer\/what-is-the-port-number-for-file-transfer-protoco--61a9e24a157c50cd8e0d6559#:~:text=Port%20numbers%2021%20and%2020,(via%20the%20Data%20channel).\" target=\"_blank\" rel=\"noopener\"><strong>found<\/strong><\/a> that Port 21 connects two computers, allowing Port 20 to share data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned in the video, FTP refers to File Transfer Protocol, a protocol that allows file-sharing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nord VPN, a globally recognised Virtual Private Network, <a href=\"https:\/\/nordvpn.com\/cybersecurity\/glossary\/port-80\/\" target=\"_blank\" rel=\"noopener\"><strong>describes<\/strong><\/a> Port 80 as \u201cthe default network port for web servers using HTTP. It operates on the application layer of the TCP\/IP networking model and serves as the communication gateway for HTTP requests and responses between client computers and servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhenever a web browser requests a web page from a server, it typically uses Port 80.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The platform does, however, warn that \u201cPort 80 is often a target for cyberattacks, including unauthorised access, data interception, and other malicious activities. Due to this, it\u2019s essential to secure Port 80 and monitor and control the traffic passing through it.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It does not say anything about closing the port.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nord VPN says that Port 443 is similar to Port 80, but while Port 80 allows for transmission of unencrypted data, Port 443 deals with encrypted data, keeping it hidden and inaccessible to anyone with unauthorised access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To further confirm how risky it was that the EFCC\u2019s website had these ports open, DUBAWA spoke with Madumere Chukwuka, PhD, a cybersecurity expert and researcher at King&#8217;s College, London.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chukwuka said the video did not expose any lapses, as having the ports open does not reflect any gaps until they are exploited.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cJust because ports like 80 (HTTP), 443 (HTTPS), and 21 (FTP) are open doesn\u2019t automatically mean there\u2019s a vulnerability,\u201d he explained. \u201cThese are standard service ports required for websites (80\/443) and file transfers (21).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhat really determines if a system is vulnerable is how securely these services are configured and whether they\u2019re running with known vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cFor example, Port 443 isn\u2019t a problem unless the HTTPS server is misconfigured or uses outdated Transport Layer Security (TLS) versions. Port 21 is only risky if anonymous access is allowed or if weak credentials are used. Port 80 isn\u2019t inherently vulnerable, but running outdated web applications could be.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSo, the presence of open ports just shows that services are reachable\u2014it\u2019s the service vulnerabilities and weak configurations behind them that matter for security.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chukwuka further explained that ports operate like doors and are not porous on their own unless the framework behind them is weak.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThink of open ports as doors; they only become a problem if what\u2019s behind them is weak or exposed. So yes, unpatched versions and misconfigurations can be exploited, but simply having the port open isn\u2019t enough for an attack,\u201d he added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adebisi Mololuwa, an Information Security Analyst and instructor at Torilo Academy, agreed with Chukwuka\u2019s submission.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He said, \u201cThe post is misleading and lacks a fundamental understanding of cybersecurity concepts. The creator of the video clearly doesn\u2019t grasp how open ports and security measures actually work.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The claim that the open ports meant the EFCC\u2019s website was susceptible to cyberattacks is misleading. Open ports are common for websites, and weaker frameworks are needed for a website to be vulnerable.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Claim: A man claims that because ports 21, 80, and 443 are open on the EFCC website, anyone can easily hack and delete data. Verdict: Misleading. DUBAWA spoke with cybersecurity experts and reviewed port security to find that an open port is not always vulnerable. Full Text On May 9, an X user, @iam_enriched, shared a video (archived here) of a man alleging that the website of the Economic and Financial Crimes Commission (EFCC), Nigeria\u2019s federal anti-graft agency, was susceptible to attacks. \u2018EFCC database is weak, can be deleted\u2019 is superimposed on the video as the unnamed man speaks first about how the fraudulent CBEX platform has open ports, and then about how the anti-graft agency investigating it also had open ports. \u201cHow can we explain that EFCC\u2019s website is not secure? How come a government institution\u2019s database is not secure? This is the Port 80 TCP of CBEX. This is where they get your information from. It is open. cbex.cx is even more secure. They actually uploaded their website on Cloudflare, which is one of the strongest firewalls to protect their website,\u201d he claimed. \u201cThis is efcc.gov.ng. If you look at the port of EFCC, it has port 21 open, port 80 is open, 443 is open\u2026. What does this mean in the world of cybersecurity? When port 21 is open, it simply means that it is an FTP port. This means they are uploading people\u2019s data. It means if they catch a fraudulent person, they send your data. They did not close the outbound,\u201d he added. He claimed anyone with little hacking skills can delete their information from the EFCC database.&nbsp; The post by @iam_enriched as of May 23 has received thousands of engagements, including over 1,200 likes, 490 reposts, 194 replies, and 784 bookmarks. This claim suggests that the EFCC\u2019s website puts users\u2019 data at risk of a hack and is susceptible to abuse by persons with criminal intent. This major concern prompted us to verify.&nbsp; Verification DUBAWA performed an online search to verify what ports 21, 80, and 443 were. We found that Port 21 connects two computers, allowing Port 20 to share data. As mentioned in the video, FTP refers to File Transfer Protocol, a protocol that allows file-sharing. Nord VPN, a globally recognised Virtual Private Network, describes Port 80 as \u201cthe default network port for web servers using HTTP. It operates on the application layer of the TCP\/IP networking model and serves as the communication gateway for HTTP requests and responses between client computers and servers. \u201cWhenever a web browser requests a web page from a server, it typically uses Port 80.\u201d The platform does, however, warn that \u201cPort 80 is often a target for cyberattacks, including unauthorised access, data interception, and other malicious activities. Due to this, it\u2019s essential to secure Port 80 and monitor and control the traffic passing through it.\u201d It does not say anything about closing the port. Nord VPN says that Port 443 is similar to Port 80, but while Port 80 allows for transmission of unencrypted data, Port 443 deals with encrypted data, keeping it hidden and inaccessible to anyone with unauthorised access. To further confirm how risky it was that the EFCC\u2019s website had these ports open, DUBAWA spoke with Madumere Chukwuka, PhD, a cybersecurity expert and researcher at King&#8217;s College, London. Chukwuka said the video did not expose any lapses, as having the ports open does not reflect any gaps until they are exploited. \u201cJust because ports like 80 (HTTP), 443 (HTTPS), and 21 (FTP) are open doesn\u2019t automatically mean there\u2019s a vulnerability,\u201d he explained. \u201cThese are standard service ports required for websites (80\/443) and file transfers (21). \u201cWhat really determines if a system is vulnerable is how securely these services are configured and whether they\u2019re running with known vulnerabilities. \u201cFor example, Port 443 isn\u2019t a problem unless the HTTPS server is misconfigured or uses outdated Transport Layer Security (TLS) versions. Port 21 is only risky if anonymous access is allowed or if weak credentials are used. Port 80 isn\u2019t inherently vulnerable, but running outdated web applications could be. \u201cSo, the presence of open ports just shows that services are reachable\u2014it\u2019s the service vulnerabilities and weak configurations behind them that matter for security.\u201d Chukwuka further explained that ports operate like doors and are not porous on their own unless the framework behind them is weak. \u201cThink of open ports as doors; they only become a problem if what\u2019s behind them is weak or exposed. So yes, unpatched versions and misconfigurations can be exploited, but simply having the port open isn\u2019t enough for an attack,\u201d he added. Adebisi Mololuwa, an Information Security Analyst and instructor at Torilo Academy, agreed with Chukwuka\u2019s submission.&nbsp; He said, \u201cThe post is misleading and lacks a fundamental understanding of cybersecurity concepts. The creator of the video clearly doesn\u2019t grasp how open ports and security measures actually work.\u201d Conclusion The claim that the open ports meant the EFCC\u2019s website was susceptible to cyberattacks is misleading. Open ports are common for websites, and weaker frameworks are needed for a website to be vulnerable.<\/p>\n","protected":false},"author":1,"featured_media":22908,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"hannibal_claim_source":"","hannibal_source_label":"","hannibal_card_color":"blue","_jetpack_memberships_contains_paid_content":false,"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"default","_twitter_share_type":"default","_linkedin_share_type":"default","_pinterest_share_type":"default","_linkedin_share_type_page":"","_instagram_share_type":"default","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_bluesky_share_type":"","_mastodon_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[1571,3812,3815,119],"tags":[],"verdict":[],"ppma_author":[4462],"class_list":["post-22906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fact-check","category-headline","category-homepage","category-security"],"jetpack_shortlink":"https:\/\/wp.me\/p8R6dE-5Xs","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"authors":[{"term_id":4462,"user_id":0,"is_guest":1,"slug":"daniel-ojukwu","display_name":"Daniel Ojukwu","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&r=g","author_category":"","user_url":"","last_name":"","first_name":"","job_title":"","description":""}],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/dubawa.org\/dir\/wp-content\/uploads\/2025\/05\/EFFC-image.png?fit=1099%2C1090&ssl=1","_links":{"self":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts\/22906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/comments?post=22906"}],"version-history":[{"count":1,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts\/22906\/revisions"}],"predecessor-version":[{"id":22909,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts\/22906\/revisions\/22909"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/media\/22908"}],"wp:attachment":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/media?parent=22906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/categories?post=22906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/tags?post=22906"},{"taxonomy":"verdict","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/verdict?post=22906"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/ppma_author?post=22906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}