Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

91–100 of 155 posts

Re: The unattributable “db8151dd” data breach

#91
post #37

Earlier quoted context omitted.

BambooHR is written in PHP and as it is widely known PHP allows incompetent programmers to create insecure websites. The majority of BambooHR pages are loaded by referencing a page ID, for example, you can access this URL [1] to render a form that allows you to send documents to arbitrary e-mail addresses, and this URL [2] allows you to edit your own profile. So far so good, if you are a competent PHP programmer (or…

> PHP allows incompetent programmers to create insecure websites. The points you bring up are good but my first instinct was to distrust you as you opened with that. I don't believe any specific shortcoming of PHP makes these issues more or less likely. Anyone can make an insecure website in any language. Secondly I don't think I quite agree with the ethics of dropping a security vulnerability in a public forum. I th…

Bare PHP (without any framework) and the tons of bad advice surrounding it make it easier to screw up than other languages where it's very hard to do web development without a framework so most beginners start off with a framework directly which provides structure and guard-rails against doing insecure things.

Re: The unattributable “db8151dd” data breach

#93

It’s contact data from iOS and android phones probably scraped via some malware app/apps

Contact data doesn’t contain CRM references

Could it be that CRMs had their own contacts integrations which synced CRM data into someone's contacts, where a different app then scraped it and got pwned?

Re: The unattributable “db8151dd” data breach

#94

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

Did you have guarduty or VPC flow logs turned on?

Re: The unattributable “db8151dd” data breach

#95
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

The biggest contribution HIBP makes is in teaching people not to reuse passwords (and use a password manager instead).

Re: The unattributable “db8151dd” data breach

#96

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…

As of this writing, I don't think it's been determined yet whose organization this data came from, has it? All we have so far is a similarity in data format/structure.

Re: The unattributable “db8151dd” data breach

#97

Earlier quoted context omitted.

Oh man, what is even going on with that raid forum.

A quick glance suggests there's barely any skill in there and it's all bottom-feeders so you'd expect this to be an easy bust for law enforcement worldwide and yet they seem to be happily operating with total impunity for quite some time.

Noobs and relatively skill makes me think H O N E Y P O T

Re: The unattributable “db8151dd” data breach

#98

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…

> If you have any operations regarding customers in Europe, you need to notify your relevant Data Protection Authority

The entire company is in the EU. The need to reach out to their DPA ASAP.

Re: The unattributable “db8151dd” data breach

#99

Earlier quoted context omitted.

It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…

As of this writing, I don't think it's been determined yet whose organization this data came from, has it? All we have so far is a similarity in data format/structure.

Almost all their employees have their emails in the breach :

https://covve.com/about

email format is .@covve.com

Re: The unattributable “db8151dd” data breach

#100
post #30

> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.

I got notified that I'm in this breach, and I honestly don't know what (if anything) I can do with this information, which implies "If it's not actionable, why bother telling me at all?"

Unique passwords per site, with a password manager? Done a long time ago. Should I change some of them? OK, which ones? there are hundreds.

Details of what else about me is in this breech? Not clear where I can find that.

Post reply on HN