Earlier quoted context omitted.
BambooHR is written in PHP and as it is widely known PHP allows incompetent programmers to create insecure websites. The majority of BambooHR pages are loaded by referencing a page ID, for example, you can access this URL [1] to render a form that allows you to send documents to arbitrary e-mail addresses, and this URL [2] allows you to edit your own profile. So far so good, if you are a competent PHP programmer (or…
> PHP allows incompetent programmers to create insecure websites. The points you bring up are good but my first instinct was to distrust you as you opened with that. I don't believe any specific shortcoming of PHP makes these issues more or less likely. Anyone can make an insecure website in any language. Secondly I don't think I quite agree with the ethics of dropping a security vulnerability in a public forum. I th…
The unattributable “db8151dd” data breach
91–100 of 155 posts
Re: The unattributable “db8151dd” data breach
#92Re: The unattributable “db8151dd” data breach
#93It’s contact data from iOS and android phones probably scraped via some malware app/apps
Contact data doesn’t contain CRM references
Re: The unattributable “db8151dd” data breach
#94Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
Re: The unattributable “db8151dd” data breach
#95I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?
Re: The unattributable “db8151dd” data breach
#96Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…
Re: The unattributable “db8151dd” data breach
#97Earlier quoted context omitted.
Oh man, what is even going on with that raid forum.
A quick glance suggests there's barely any skill in there and it's all bottom-feeders so you'd expect this to be an easy bust for law enforcement worldwide and yet they seem to be happily operating with total impunity for quite some time.
Re: The unattributable “db8151dd” data breach
#98Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…
The entire company is in the EU. The need to reach out to their DPA ASAP.
Re: The unattributable “db8151dd” data breach
#99Earlier quoted context omitted.
It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any o…
As of this writing, I don't think it's been determined yet whose organization this data came from, has it? All we have so far is a similarity in data format/structure.
email format is .@covve.com
Re: The unattributable “db8151dd” data breach
#100> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.
Unique passwords per site, with a password manager? Done a long time ago. Should I change some of them? OK, which ones? there are hundreds.
Details of what else about me is in this breech? Not clear where I can find that.