Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

Remember I wrote on Habr and on my Telegram channel, how details of payments to the traffic police and the Federal Bailiffs Service by users of websites ended up publicly accessible оплатагибдд.рф, paygibdd.ru, gos-oplata.ru, штрафов.net and oplata-fssp.ru?

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

Just don't laugh, it's no joke — the same server with data from the same system was again open to the whole world.

So, let's get investigating…

Disclaimer: All information below is published solely for educational purposes. The author has not accessed any personal data of third parties or companies. The information is taken either from open sources or was provided to the author by anonymous well-wishers.

First, let me remind you of the timeline of events:

  • On April 12, 2019 (night), an Elasticsearch server was discovered that did not require authentication for connection.
  • On April 13, 2019 (morning), a notification was sent to the server owners.
  • On April 13, 2019 (afternoon), the server was 'quietly' removed from public access.

At the time of the first server closure, the Elasticsearch indices looked like this:

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

And on May 21, 2019 at around 16:00 (MSK), the same Elasticsearch server, with the same (plus new) indices appeared back in public access:

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

I couldn't believe my eyes when I saw (immediately after my presentation at PHDays on the topic of discovering open databases) a notification from our DeviceLock Data Breach Intelligence. To be honest, my first thought was that it was some kind of system glitch.

However, no, it wasn't a glitch, and after manually rechecking everything, at 01:25 on May 22, 2019, I sent a notification again to the same addresses as the first time.

Since the first closure, this server was scanned by Shodan 11 times, and until May 21, Elasticsearch on it was secured.

Only on the morning of May 24, 2019 did this Elasticsearch disappear from public access for the second time. During this time, the indices had grown significantly:

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

And if we look at the data (only significant information containing personal data of citizens) in the indices from May 1 to May 22, the picture is as follows:

  • 127,525 records in the index paygibdd
  • 49,627 records in the index shtrafov-net
  • 162,282 records in the index payment-fssp
  • 220,201 records in the index gosoplata

Sample data from the index gosoplata:

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

Sample data from the index paygibdd:

Once again, hundreds of thousands of payments from citizens to the traffic police and bailiffs were publicly accessible

And the cherry on top was a letter from one of the addresses to which I sent notifications:

We received your letter about the open ElasticSearch — thank you for the information, the database has been closed. The system administrator who reopened access has been dismissed. The legal service is preparing to submit an application to the Ministry of Internal Affairs of the Republic of Tatarstan regarding signs of the administrator's actions corresponding to articles 272 and 273 of the Criminal Code of the Russian Federation.

News about data leaks and insiders can always be found on my Telegram channel "Data Leaks»: https://t.me/dataleak.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster