DomainHunter: A Distributed System for Identifying Potentially Malicious Domains
DomainHunter is a distributed system built on Cloudflare Workers designed to help security teams identify, analyze, and respond to potentially malicious domains.
Wandering the Internet
DomainHunter is a distributed system built on Cloudflare Workers designed to help security teams identify, analyze, and respond to potentially malicious domains.
Summary: An ElasticSearch database was discovered that was leaking the customer information related to Adorcam – a power iOS and Android web camera application. The app provides a P2P connection for IP web camera brands such as Zeeporte and Umino . The leaked data includes user email addresses,
Summary: I recently discovered an exposed ElasticSearch database when browsing BinaryEdge and Shodan . This database appears to be controlled by a subsidiary of a major Thailand-based mobile network operator named Advanced Info Service (AIS) . According to Wikipedia , AIS is "Thailand's largest
Summary: Glynk is an Android app with more than 1 million installs . According to their own description: "The Glynk application builds a like-minded network for every user based on interests, opinions, location among many other parameters." Glynk has also been leaking 2.2 billion rows
Summary: I was searching Shodan yet again when I discovered an ElasticSearch database without any authentication. The data contained within this database was related to the internal network and computers of Honda Motor Company. The information available in the database appeared to be something like a inventory of
Summary: While searching Shodan , I recently discovered an ElasticSearch database without any authentication. This database contained metadata related to a huge amount of emails. It was eventually confirmed that this server and the email metadata was controlled by a large university located in China. I would like to thank
Summary: Recently I discovered an improperly secured ElasticSearch database that contained personally identifiable information ( PII ) related to individuals who had received medical treatment at an addiction treatment center. This data appears to cover patient data from mid 2016 - late 2018, and amounts to roughly 4.9 million rows
Summary kanopy.com has been leaking huge volumes of website access logs as well as API logs via an exposed ElasticSearch database. The database was publicly accessible without any type of authentication. After numerous emails beginning Sunday March 17th and messages on social media they have yet to reply.
An ElasticSearch database (with Kibana front-end) was discovered. This server did not have any type of authentication. Numerous notifications have been sent to the email address indicated in the Google Store, but no reply has been received. These Android apps were recently updated (January 24, 2019) so they are
I didn't write up this leak here, but: https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/ and https://www.bleepingcomputer.com/news/security/online-casino-database-leaks-details-of-over-100-million-bets/ From ZDNet: "An online casino
Summary An improperly secured ElasticSearch database was recently discovered containing a huge volume of VOIP call logs, SMS/MMS message logs, and plaintext internal system credentials. This database was discovered using Shodan . Following a brief investigation, it was determined this database was controlled by VOIPO , a VOIP provider
Summary Recently I discovered an improperly secured ElasticSearch server, Kibana server, and InfluxDB administrative page that was associated with a significant amount of data. After investigating the type of content contained on this server it became apparent this was data related to a number
Summary In the normal course of scanning for open/exposed/vulnerable Amazon S3 buckets, I discovered a bucket containing roughly 3,000 imaged of Permanent Account Number (PAN) cards and National ID (Aadhaar) cards from India. After concluding the images and PDFs appeared to be sensitive identification documents I immediately
Summary In the normal course of scanning for open/exposed/vulnerable Amazon S3 buckets I discovered a bucket containing a large number of CSV files. This is not all that odd. What made this bucket particularly interesting was that following a brief investigation it became immediately apparent the bucket appeared
TL;DR: at least 2,102 tech support scam (TSS) domains. Initial domain I came across: hXXp://ghryuiefdao{.}tk/?number=888-348-1742&bluer=1 2018-07-22 UPDATE: Freenom (the registrar) killed all of the 2,075 .tk domains. dig ghryuiefdao.tk | grep "status" ;; ->