HomeSecurityBlisk browser: User data leak via exposed server

Blisk browser: User data leak via exposed server

A browser developer and vendor data userhas exposed by leaving an Elasticsearch server exposed to the internet without a password. The leak is attributed to Blisk , an Estonian company that develops the popular Blisk browser.

The Blisk browser is Chromium-based and is aimed at the community of developers involved in application development, etc. It has many tools suitable for programming, device preview capabilities, and tools that allow collaboration between experts to implement projects.

The Blisk browser was launched in May 2016 and is constantly being developed, with more and more users preferring it. On its website, it is stated that it is used by more than 40,000 companies, including some big companies such as HP, Xerox, NASA, Unicef, Deloitte, UEFA, Vice News and Pandora.

Last December, the company suffered a data breach due to an oversight. The data was discovered on December 2, 2019, when Noam Rotem and Ran Locar, two researchers at vpnMentor, discovered an Elasticsearch server of the company that had been left exposed on the internet.

Blisk browser: User data leak via exposed server

Researchers found personal data for thousands of developers who used the Blisk browser.

In total, they found 2.9 million files (3.4 GB of data), which remained exposed online.

The data was mainly log entries for actions taken by developers within the browser (e.g., registering a profile or inviting friends).

The exposed data included email addresses and user-agent strings.

vpnMentor said it notified Blisk on December 4. The next day, the company secured the server.

The Blisk browser team confirmed the leak. However, they said that despite this significant flaw, no sensitive information such as passwords, financial details or personally identifiable information (PII) such as names, phone numbers, etc. was leaked .This information was not stored on this server.

However, according to the researchers, this data, which was on the server, could be used by hackers for various purposes.

The data could be used to target developers working for private companies. However, until now, we don't know if any malicious hackers the exposed data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS