Hosting Provider Leaked 63M Records Including Magento and WordPress Credentials
securethoughts.com
securethoughts.com
* For SMS 2FA you might leak the user's phone number which isn't good, but even if you "leak" the 2FA code it's transient and will very quickly be worthless
* For TOTP leaking the current TOTP code (either entered by a user or calculated locally) is transient again, but if you instead leak the seed (which you have) that's fatal.
* For other types of single use codes leaking a code that was successfully presented isn't a problem (it was single use and now won't work) but leaking codes you've generated (e.g. from a "new codes" page) is fatal.
* With WebAuthn you (the relying party) do not have any secret credentials at all, so you can leak everything you have and it makes no difference to the system's security so long as you implemented it correctly.
I mounted the computers with a Linux live disk and it turns out that the computers were used by a professional website development company that created websites for several prominent local businesses around the state.
There was no encryption used on the drives and I found the passwords and authentication tokens for their advertising accounts, LastPass password manager, passwords used by their FileZilla instance, the business American Express card and billing, Office 365, Email accounts etc.
A year ago I purchased a used 500Gb external drive from a local computer recycling center and when I ran an open-source recovery program on the drive I recovered several years of patient medical records.
The lack of security and privacy awareness of the people handling sensitive information is disturbing.
Seems to level up in the hacking world, you do whitehat stuff like this, but it could be that 90% of your work is blackhat. Why do 'researchers' risk exposing themselves like this (if the bulk of what you do is blackhat?). I'm not saying Mr Fowler is secretly a blackhat, but many people in the hacking scene are obviously blackhat judging by what they post on social media. You can infer that they like to get up to some sketchy stuff (again - risking exposing themselves to LE).
From the article.
The only way I can see myself accessing a computer and not breaking a law is through a genuine mistake i.e. mistyping an IP/url and somehow having the right username + password.
I prefer to stay 100% on the legal side. The only way I'll touch a computer is with a signed document from the owner giving me permission and with clear instruction on what I can and cannot do.
Wasn't the whole point of Meow to delete erroneously public-facing data to prevent malicious use?
Calling it a malicious script is ...debatable.
The Meow bot "intended to do harm", that is, to databases. Of course the creator might have had "lofty" goals and high hopes that this attack will encourage better database managers to harden their security practices in the future. But the Bot itself is definitely "malicious".
Hmm, but where is this password stored? This sounds like exactly what they were doing!
Thus this could be a missing or misconfigured log filter for PII.
Way too verbose logging. Should never have logged that.
The logging database (elasticsearch) was exposed to the internet without authentication. Free credentials for all.
It's interesting to observe the contrast between this and "We're a SaaS startup and we log every.single. RPC request across all services forever including performance data".
However you MUST NOT logs cookies or headers or content, because these can contain private information.
Last but not least, developers should never pass tokens/passwords in the request path because it will be systematically logged and leaked /api/token/abcdec. That should go into a header or the body.
For example: Accidentally open to the internet log server(as above). Attacker sends password reset request. Attacker checks log to steal token. Attacker now has stolen account until owner can't log in and does reset, or perhaps semi-permanently if attacker steals all tokens for said account and invalidates them before owner can use them.
If you believe you're verifying that the email went to your user, this isn't enough. Lots of systems parse URLs out of emails and follow them, you probably want to look for a a pre-existing session cookie, or insist the user log in from the verification page and confirm this is what they wanted.
Otherwise you've merely got two unrelated facts:
1. Some user of your system (maybe happy_pancake) says bob@example.com is their email address
2. Mail to bob@example.com is received by a machine or person which reads web pages.
It would be foolish to conclude from these facts that happy_pancake is actually bob@example.com or that bob@example.com wants to use your service.
It takes longer to read the docs and figure out that if you're not paying, security isn't default. In fact, it's a fair bit of configuration and reading to enable security properly if it's the first time you're using it.
Coupled with Docker popping holes all over your firewall, it's an easy way for a non-security aware operations engineer to leave data all over the internet.
If I'm not mistaken, Meow was created to delete data in instances like this to help protect against misconfigured instances.
Obviously, treat all attacks as if they are serious.. but wow.
I had noticed elasticsearch being the culprit in security advisories and reports of breaches, but it's easy to miss when you're busy with something else. Security has to be the default!
It's really quite strange that WordPress passwords are shown in cleartext. WordPress core is diligent about hashing passwords, using nonces, and all that sort of security work. Maybe some workflow uses HTTP GET for logins, in which case passwords land in the weblogs. But a web service company? Using more-or-less standard open source web apps? How hard would they have to try to do that?
"We take data security very seriously." Yeah.
https://docs.aws.amazon.com/AmazonECS/latest/developerguide/...
https://www.rayheffer.com/aws-secrets-manager-for-wordpress-...
Speaking as a person in the ISP world who's been doing this stuff since 1996, it's easy to run a terrible and shoddy ISP that works most of the time. It's much harder to do everything right and really care about network architecture, engineering and security.
They should not be allowed to get away with criminal security.