3 ms·
>It's unknown if anyone has taken advantage of the vulnerability (yet) and, as of July 1, the database was still accessible with no password protection. And th
by class4behavior 7y ago
>It's unknown if anyone has taken advantage of the vulnerability (yet) and, as of July 1, the database was still accessible with no password protection.
And this article had been published today... The database had been closed a day later on July 2.
Here the the original report instead of a Forbes article: https://www.vpnmentor.com/blog/report-orvibo-leak/ https://www.vpnmentor.com/blog/report-orvibo-leak/
- canofbars 7y agoIt most certainly has been taken advantage of. Bots crawl the internet checking for services on default ports without a password. I was an victim of this recently when I got reports that my web app was down and when I investigated it I saw there was a password on redis preventing the app from connecting. I then found out the redis docker container was accepting connections from the outer internet with no password and someone had connected in and set a password on it (Probably just to alert me to the fact it was exposed). Thankfully there was basically nothing in redis so no user data was exposed.