Misconfigured FTP, SMB, Rsync, and S3 Buckets Exposing 1.5B Files
gbhackers.com
gbhackers.com
> Publicly exposed data contains a large amount of the employee data such as Payroll files (707,960) and Tax Return files (64,048). More than 2 Million of files that contain personal health information like MRIs based in Italy exposed.
> The exposed data includes the Source Code, Patient List accounted about 95,434 and 4,548 respectively. Exposed data is a goldmine for attackers they can use the publicly available data to launch cyber attacks. the exposed information cut’s off their reconnaissance.
> Shockingly some highly sensitive information’s such as security audit reports, network infrastructure details and penetration testing reports are stored online publicly.
But it's not clear really how much percentage of 1.5B files was actually sensitive.
Also, shameless plug for my tool if you want to go bucket hunting: https://github.com/sa7mon/S3Scanner
Mis-configured access control on file storage and sharing services has always been quite prevalent. From a users perspective, a lax ACL just means everything works :)
In "the olden days" of corporates behind firewalls, the issues were still there but they were hidden from casual view by NAT and perimeter firewalls.
Now people operate directly on cloud services their mistakes are easy to find.
Whilst perimeter firewalls were never the security panancea that some thought they were, they did have some use in hiding all the other security issues from casual discovery :)
Not necessarily. As you mentioned yourself the cloud era just exposed existing bad practices. Perhaps over time that's even a net positive because people might start to take security more seriously.
> But I'll argue that Accessibility is actually more important than Security because dialing Accessibility to zero means you have no product at all, whereas dialing Security to zero can still get you a reasonably successful product such as the Playstation Network.
He means "usability" when he says "accessibility".
https://blog.steve.fi/secure_your_rsync_shares__please_.html
Discussed here at the time:
The fact that a high number of such attempts come over Tor is disappointing, but should surprise nobody.
I've no desire to blacklist Tor exit nodes as such, but I'm going to go out of my way to whitelist them when they are a source of malicious traffic