How I used a Google query to mine passwords from dozens of public Trello boards
medium.freecodecamp.org
medium.freecodecamp.org
site:vk.com/doc "@gmail.com"
As it turns out, vk.com (and other large social networks) are used for discreetly sharing large lists of credentials. These are publicly crawled by Google but do not typically end up on lists of email or password breaches. You can find many credentials this way that are not (for example) in the haveibeenpwned database.More generally this is why "google dorking" can be a sophisticated reconnaissance method for collecting a variety of data that is technically public but not intentionally so.
vk.com is huge.
SimilarWeb ranks it on position eight for worldwide traffic, this is right after Twitter and above Instagram and Wikipedia.
About:
"VKontakte (or VK for short) is a social media networking site. Like most social media networks you can add friends, gain followers, and post photos of your food and your cat. VK, like Facebook also gives companies the ability to create their own pages for marketing purposes."
https://www.echosec.net/what-is-vk-and-why-should-you-care/
Still don't understand why so many logins are being publicly exposed there.
• VK is the most popular website in Russia.
• There are many hackers in Russia.
Connect the points.
The first two links I clicked gave me lists of emails.
The third one gave me a list of colon-delimited emails and passwords.
https://vk.com/doc-75521656_324259084
That's a massive blunder.It’s funny and sad at the same time.
> the access key for amazon s3 is:
User XXXXXXX
Access Key ID: XXXXXXXXXXXXXXXXXXX
Secret Access Key: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> Let me know when you've recorded these and I'll delete the comment.(blacked out by me)
Or fitgoapp, which has publicly accessible services, with passwords "fitgo" and "fitgoapp" (also visible on trello).
Just go through the entire list of queries at https://www.exploit-db.com/google-hacking-database/ you’ll find so many exposed passwords, it’s crazy. No one ever properly protects their keys and passwords.
The purview of GDPR is personally identifiable information, whereas these are vulnerability details and passwords. If companies were storing their user lists in Trello boards that might be a bit different, but the examples in this blog post do not seem to be related to user data. They are also being volunteered by the companies using Trello, not Trello itself, so a potential violation would probably be levying fees against individual companies.
It also doesn't strike me as a security vulnerability because it's not a technical failure in Trello's software. This is closer to accidentally publishing AWS keys on Github or opening a phishing email, and in neither case would GitHub or (say) Gmail be responsible for that. There are proactive steps they can take to mitigate this kind of mistake (as GitHub and Gmail do), and it's arguable Trello should do the same, but it doesn't seem like a compliance or security failure whatsoever.
And personal data also applied to employee data, or your partners data.
If the set up is public, is there enough visual cues to the everyday user that the set up is public?