Hit enter to search or ESC to close
Identity InsiderIdentity InsiderIdentity Insider
  • News
  • Blogs
Identity Insider
Unprotected MongoDB Account Exposes 200K Files
News

Unprotected MongoDB Account Exposes 200K Files

By AdminSeptember 7, 2018 No Comments

A security researcher has discovered yet another misconfigured MongoDB installation online, this time exposing over 200,000 highly sensitive corporate documents.

The 142GB MongoDB account was hosted on Amazon Web Services (AWS) infrastructure in the US and belonged to global document recognition and content capture software developer ABBYY, according to former Kromtech man Bob Diachenko.

Unfortunately, the account was left totally unprotected, with no password or log-in, meaning anyone with internet access could theoretically have gained entry.

“The biggest concern was the fact MongoDB in question also contained a large chunk of scanned documents (more than 200,000 contracts, NDAs, memos, letters and other internal documentation, properly OCR’d and stored) which apparently were stored by ABBYY partners using their administration console,” he explained.

The firm’s head of information security replied to Diachenko’s email requesting more info.

“Database access has been disabled soon after I sent him the IP address (two days after my initial notification), but questions still remain as of how long it has been left without password/login, who else got access to it and would they notify their customers on the incident,” he added.

A statement sent to the researcher following the incident claimed the “temporary data breach” affected just one of the developer’s customers, and that a “full corrective security review of our infrastructure, processes and procedures” has been undertaken.

ABBYY lists major global companies and governments among its customer base, including Deloitte, McDonald’s, Volkswagen and the Reserve Bank of Australia.

The firm is fortunate Diachenko found the trove of documents rather than online attackers who last year twice ran major campaigns in which data was stolen from exposed servers before being ransomed. It’s believed tens of thousands of victims were involved.

 

Source: www.infosecurity-magazine.com
Author: Phil Muncaster UK / EMEA News Reporter , Infosecurity Magazine

Tags:

MongoDBMongoDB Account ExposesMongoDB Account Exposes 200K Filesprotected MongoDB Account
Admin

Admin

Sign up for Newsletter


Trending Now

  • Adding ‘I Am’ to IAM September 4, 2018
  • Shady Ethics in the IAM Industry September 20, 2018
  • Adaptive Authentication – The Hacker’s Waterloo August 24, 2018
  • Previous Post4 Benefits of a World with Less Privacy

  • Next PostAdding ‘I Am’ to IAM

Related Posts

News
September 21, 2018

Government Website in India Hacked by Crypto Mining

Admin
Current-Trends-in-Identity-and-Access-Management News
September 7, 2018

Current Trends in Identity and Access Management: July 2017

Admin
News
September 7, 2018

Say Goodbye to Passwords, the Future of Authentication is Here

Admin

2025 © All Right Reserved. Powered by Cross Identity

  • News
  • Blogs