RSSAmplifier

Blog

Rainbowtabl.es

Wandering the Internet

rainbowtabl.esRSS feed ↗15 posts

Latest posts

DomainHunter: A Distributed System for Identifying Potentially Malicious Domains

DomainHunter is a distributed system built on Cloudflare Workers designed to help security teams identify, analyze, and respond to potentially malicious domains.

iOS and Android Web Cam App Adorcam Leaks 124 Million Rows of Customer Data

Summary: An ElasticSearch database was discovered that was leaking the customer information related to Adorcam – a power iOS and Android web camera application. The app provides a P2P connection for IP web camera brands such as Zeeporte and Umino . The leaked data includes user email addresses,

Thai Database Leaks 8.3 Billion Internet Records

Summary: I recently discovered an exposed ElasticSearch database when browsing BinaryEdge and Shodan . This database appears to be controlled by a subsidiary of a major Thailand-based mobile network operator named Advanced Info Service (AIS) . According to Wikipedia , AIS is "Thailand's largest

Glynk Android App Leaks 2 Billion Rows of Customer Data

Summary: Glynk is an Android app with more than 1 million installs . According to their own description: "The Glynk application builds a like-minded network for every user based on interests, opinions, location among many other parameters." Glynk has also been leaking 2.2 billion rows

Honda Motor Company leaks database with 134 million rows of employee computer data

Summary: I was searching Shodan yet again when I discovered an ElasticSearch database without any authentication. The data contained within this database was related to the internal network and computers of Honda Motor Company. The information available in the database appeared to be something like a inventory of

9.5 billion rows of email metadata leaked by Shanghai Jiao Tong University

Summary: While searching Shodan , I recently discovered an ElasticSearch database without any authentication. This database contained metadata related to a huge amount of emails. It was eventually confirmed that this server and the email metadata was controlled by a large university located in China. I would like to thank

Steps To Recovery Addiction Treatment Center Leaking PII

Summary: Recently I discovered an improperly secured ElasticSearch database that contained personally identifiable information ( PII ) related to individuals who had received medical treatment at an addiction treatment center. This data appears to cover patient data from mid 2016 - late 2018, and amounts to roughly 4.9 million rows

Kanopy.com leaking API and website access logs

Summary kanopy.com has been leaking huge volumes of website access logs as well as API logs via an exposed ElasticSearch database. The database was publicly accessible without any type of authentication. After numerous emails beginning Sunday March 17th and messages on social media they have yet to reply.

South Korean Android delivery apps found to be leaking passwords and financial data

An ElasticSearch database (with Kibana front-end) was discovered. This server did not have any type of authentication. Numerous notifications have been sent to the email address indicated in the Google Store, but no reply has been received. These Android apps were recently updated (January 24, 2019) so they are

Online casino group leaks information on 108 million bets, including user details

I didn't write up this leak here, but: https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/ and https://www.bleepingcomputer.com/news/security/online-casino-database-leaks-details-of-over-100-million-bets/ From ZDNet: "An online casino

VOIPO.com Data Leak

Summary An improperly secured ElasticSearch database was recently discovered containing a huge volume of VOIP call logs, SMS/MMS message logs, and plaintext internal system credentials. This database was discovered using Shodan . Following a brief investigation, it was determined this database was controlled by VOIPO , a VOIP provider

Real-time location information leaked by 27 Indian government agencies

Summary Recently I discovered an improperly secured ElasticSearch server, Kibana server, and InfluxDB administrative page that was associated with a significant amount of data. After investigating the type of content contained on this server it became apparent this was data related to a number

3,000 Permanent Account Number (PAN) cards and National ID (Aadhaar) cards leaked from India

Summary In the normal course of scanning for open/exposed/vulnerable Amazon S3 buckets, I discovered a bucket containing roughly 3,000 imaged of Permanent Account Number (PAN) cards and National ID (Aadhaar) cards from India. After concluding the images and PDFs appeared to be sensitive identification documents I immediately

Arik Air - grounded by an Amazon S3 leak

Summary In the normal course of scanning for open/exposed/vulnerable Amazon S3 buckets I discovered a bucket containing a large number of CSV files. This is not all that odd. What made this bucket particularly interesting was that following a brief investigation it became immediately apparent the bucket appeared

Web of Tech Support Scam Domains

TL;DR: at least 2,102 tech support scam (TSS) domains. Initial domain I came across: hXXp://ghryuiefdao{.}tk/?number=888-348-1742&bluer=1 2018-07-22 UPDATE: Freenom (the registrar) killed all of the 2,075 .tk domains. dig ghryuiefdao.tk | grep "status" ;; ->