News: 1655367192

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Elasticsearch server with no password or encryption leaks a million records

(2022/06/16)


Researchers at security product recommendation service Safety Detectives claim they’ve found almost a million customer records wide open on an Elasticsearch server run by Malaysian point-of-sale software vendor StoreHub.

Safety Detectives’ [1]report states it found a StoreHub sever that stored unencrypted data and was not password protected. The security company’s researchers were therefore able to waltz in and access 1.7 billion records describing the affairs of nearly a million people, in a trove totalling over a terabyte.

StoreHub’s wares offer point of sale and online ordering, and the vendor therefore stores data about businesses that run its product and individual buyers’ activities.

[2]

Safety Detectives wrote that full names, phone numbers, physical addresses, email addresses, and even device types were among the exposed data.

[3]

[4]

Customers’ orders, plus the locations they ordered from and the times at which they ordered, were also open to the world. Safety Detectives asserts that order details included “partially masked credit card information.”

Information about StoreHub users’ staff was also exposed.

[5]

So were access tokens that could allow miscreants to alter users’ StoreHub-powered sites.

Safety Detectives’ post says it found the exposed server on January 12th and promptly reported it, then followed up – but StoreHub did not respond. On January 27th the security company decided to contact StoreHub’s host – AWS – and Malaysia’s Computer Emergency Response Team. The server was secured by February 2nd.

[6]Bank had no firewall license, intrusion or phishing protection – guess the rest

[7]Malaysia-linked DragonForce hacktivists attack Indian targets

[8]Foxconn forms JV to build chip fab in Malaysia

A statement from StoreHub sent to The Register disputes Safety Detectives' timeline - the company says it was alerted on February 3rd - but does not dispute the existence of the unsecured server.

"Upon being informed of the occurrence on an Amazon Web Services (AWS) Elasticsearch instance, StoreHub took immediate action to patch and rectify the vulnerability within 24 hours." The company also revoked tokens in the dataset.

The company conducted an investigation it states revealed "that no sensitive financial data or passwords were contained in the vulnerability." The statement is silent on whether the exposed data was accessed.

[9]

StoreHub has now engaged a security consultancy to "verify and prevent future potential vulnerabilities" and has pledged to do much better in future.

Safety Detectives has generously described the cause of this mess as a “misconfigured” server.

Malaysian law may be less lenient, as it [10]provides for substantial fines for non-compliance with data protection laws.

StoreHub could also find itself in trouble beyond its home country, as it operates across several South-East Asian nations. ®

Get our [11]Tech Resources



[1] https://www.safetydetectives.com/news/storehub-leak-report/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yqr-Q2xeEeQZ-qAn-N-7rwAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yqr-Q2xeEeQZ-qAn-N-7rwAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yqr-Q2xeEeQZ-qAn-N-7rwAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yqr-Q2xeEeQZ-qAn-N-7rwAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/04/05/mahesh_bank_no_firewall_attack/

[7] https://www.theregister.com/2022/06/15/dragonforce_malaysia_india_attacks/

[8] https://www.theregister.com/2022/05/18/foxconn_dnex_malaysia_fab_jv/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yqr-Q2xeEeQZ-qAn-N-7rwAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://resourcehub.bakermckenzie.com/en/resources/data-privacy-security/asia-pacific/malaysia/topics/penalties-for-non-compliance

[11] https://whitepapers.theregister.com/



Clue's in the name

andy 103

You just can't have a camel cased 2-word company name that ends "Hub" and be taken seriously.

It's associated with one thing with a notable orange and black logo.

In terms of this particular story though... crikey.

Re: Clue's in the name

Tom 38

GitHub doesn't have orange on its logo? Instructions unclear.

Re: Clue's in the name

andy 103

@Tom 38 To give you some numbers on how relatively few people use GitHub here are some stats...

GitHub: 32 million visitors / month

PornHub: 2.4 billion visitors / month

Yep, turns out porn is more popular than code.

A "misconfigured" server

Pascal Monett

Nice.

I'll have to remember that the next time I need to explain why somebody fucked up.

"I am convinced that the manufacturers of carpet odor removing powder have
included encapsulated time released cat urine in their products. This
technology must be what prevented its distribution during my mom's reign. My
carpet smells like piss, and I don't have a cat. Better go by some more."
-- timw@zeb.USWest.COM, in alt.conspiracy