HomeSecurity49 million unique emails exposed due to mishandling of credentials

49 million unique emails exposed due to credential mishandling

An Israeli marketing company exposed 49 million unique emails after gratuitous authentication commands for an Elasticsearch database, which was located on an unprotected web server.

In a vaguely worded update this week, Straffic, a private digital marketing company, said the incident was the result of a “security vulnerability” affecting one of servers .

But it's not the whole story, and this incident shows that huge databases are still at risk even when accessing them requires authentication.

49 million unique emails exposed due to credential mishandling

Unexpected vulnerability

Straffic is described as “a private network for connecting elite affiliates with CPA [cost per action] & CPL [cost per lead] from trusted advertisers.”.

In a short message on Wednesday, the company announced that “a security vulnerability was found on one of the servers we use to provide our services.”.

The incident involved an Elasticsearch database with 140GB of contact information consisting of names, phone numbers, and mailing addresses. While it was password, it appears that the credentials were not stored properly.

A security researcher who goes by the name 0m3n on Twitter found them in plain text on the web server. 0m3n - a DevOps engineer with a focus on security - decided to check the web server after receiving a link in a spam message.

Troy Hunt said that 70% of the emails in Straffic’s database were already on I Have Be Pwned, the data breach notification site he created. That means many of those emails “didn’t come from previous breaches,” he says in a response to Under the Breach on Twitter.

49 million unique emails exposed due to credential mishandling

Straffic says all of systems are currently secure and that they have found no evidence of data.

Indeed, security incidents can occur even when the best precautions are taken and are more likely to occur when database credentials are circulating on the internet, especially when they are in plain text.

Hunt, who is very familiar with data breach disclosures, points out that Straffic’s announcement lacks the basic information that should be available in such an announcement. It doesn’t provide details about the date of the incident (or at least an estimate), what caused it, how it happened, and how the parties involved were notified.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS