5 ms·
How can an independent security researcher be aware of such a breach ?
by avishai2112 9y ago
How can an independent security researcher be aware of such a breach ?
- deleted 9y ago[deleted]
- sillysaurus3 9y agoIt's possible the researcher managed to get into a position to download the same database snapshot.
- blakesterz 9y agoCheck out his YouTube channel, he explains things quite often: https://www.youtube.com/channel/UCD6MWz4A61JaeGrvyoYl-rQ https://www.youtube.com/channel/UCD6MWz4A61JaeGrvyoYl-rQ And many blog posts explains what how he does it: https://www.troyhunt.com/ https://www.troyhunt.com/ Pretty sure this is the one he mentioned in his video today as having been given to him by someone else.
- cisanti 9y agoThey have contacts and ears in the underworld I suppose :=)
- jlgaddis 9y agoOne guy in particular, I can't recall his name (Chris Vickery, maybe?), has been behind A LOT of these "discoveries"; specifically, a bunch of Amazon S3 buckets that are misconfigured (WRT permissions) and wide open to anyone who wants to download the data. (I'll admit that I'm kinda curious as to how he enumerates all of them!) Based on the little information published, it sounds like that's what has happened in this case as well. The same guy has also found tons of wide open MongoDB instances and such. The guy you're referring to, Troy Hunt (HIBP) , writes about these cases but, AIUI, doesn't typically find them on his own. He's usually notified by the actual "researcher" -- this Chris guy in a lot of recent cases -- and they share the info with him.
- graystevens 9y agoYou can enumerate S3 buckets (and other cloud operators) by DNS bruteforce, or looking at how the company name them on their website and working through some common name. Did this recently and found 1000’s of public buckets.