I'm back to discussing data leaks, but this time I'll share a bit about the afterlife of IT projects through two recent findings.

During database security audits, it's not uncommon to discover servers (, as I mentioned in my blog) belonging to projects that have long (or not so long) left our world. Such projects even continue to simulate life (activity), reminiscent of zombies (collecting users' personal data after their demise).
Disclaimer: All information below is published solely for educational purposes. The author has not accessed any personal data of third parties or companies. The information is taken either from open sources or was provided to the author by anonymous well-wishers.Let's begin with a project with the loud name 'Putin Team' (putinteam.ru).
An open MongoDB server was discovered on April 19, 2019.

As you can see, the first to reach this database was a 'ransomware':

The database doesn't contain particularly valuable personal data, but it does have email addresses (less than 1000), first and last names, hashed passwords, GPS coordinates (presumably from smartphone registrations), city of residence, and photos of users who created accounts on the site.
{
"_id" : ObjectId("5c99c5d08000ec500c21d7e1"),
"role" : "USER",
"avatar" : "https://fs.putinteam.ru/******sLnzZokZK75V45-1553581654386.jpeg",
"firstName" : "Vadim",
"lastName" : "",
"city" : "Saint Petersburg",
"about" : "",
"mapMessage" : "",
"isMapMessageVerify" : "0",
"pushIds" : [
],
"username" : "5c99c5d08000ec500c21d7e1",
"__v" : NumberInt(0),
"coordinates" : {
"lng" : 30.315868,
"lat" : 59.939095
}
}
{
"_id" : ObjectId("5cb64b361f82ec4fdc7b7e9f"),
"type" : "BASE",
"email" : "***@yandex.ru",
"password" : "c62e11464d1f5fbd54485f120ef1bd2206c2e426",
"user" : ObjectId("5cb64b361f82ec4fdc7b7e9e"),
"__v" : NumberInt(0)
}There are many junk information and empty records. For example, the subscription code for the newsletter doesn't check if an email address is entered, so anything can be written instead.

According to the copyright on the site, the project was abandoned in 2018. All attempts to contact the project representatives have been unsuccessful. However, a few rare registrations on the site continue, indicating a simulation of life.
The second zombie project in my today's analysis is the Latvian startup 'Roamer' (roamerapp.com/ru).
On April 21, 2019, an open MongoDB database of the mobile application 'Roamer' was discovered on a server in Germany.

The database, sized at 207 MB, has been publicly accessible since November 24, 2018 (according to Shodan)!
By all external signs (non-working technical support email, broken links to the Google Play store, copyright on the site from 2016, etc.) – the application has long been abandoned.

At one time, almost all niche media wrote about this startup:
- VC: “The Latvian startup Roamer — a roaming killer»
- the-village: “Roamer: An app that reduces the cost of calls from abroad»
- lifehacker: “How to reduce roaming communication costs by 10 times: Roamer»
The ‘killer’ seems to have killed itself, but even dead, it continues to leak users' personal data…
Judging by the analysis of the information in the database, many users continue to use this mobile application. During a few hours of observation, 94 new entries appeared. And from March 27, 2019, to April 10, 2019, 66 new users registered in the application.
In the public domain, there are logs (over 100,000 entries) of the application containing information such as:
- user's phone
- access tokens to call history (available via links like: api3.roamerapp.com/call/history/1553XXXXXX)
- call history (numbers, incoming or outgoing call, call cost, duration, call time)
- user's mobile operator
- user's IP addresses
- user's phone model and mobile OS version on it (for example, iPhone 7 12.1.4)
- user's email address
- user's account balance and currency
- user's country
- user's current location (country)
- promo codes
- and much more.
{
"_id" : ObjectId("5c9a49b2a1f7da01398b4569"),
"url" : "api3.roamerapp.com/call/history/*******5049",
"ip" : "67.80.1.6",
"method" : NumberLong(1),
"response" : {
"calls" : [
{
"start_time" : NumberLong(1553615276),
"number" : "7495*******",
"accepted" : false,
"incoming" : false,
"internet" : true,
"duration" : NumberLong(0),
"cost" : 0.0,
"call_id" : NumberLong(18869601)
},
{
"start_time" : NumberLong(1553615172),
"number" : "7499*******",
"accepted" : true,
"incoming" : false,
"internet" : true,
"duration" : NumberLong(63),
"cost" : 0.03,
"call_id" : NumberLong(18869600)
},
{
"start_time" : NumberLong(1553615050),
"number" : "7985*******",
"accepted" : false,
"incoming" : false,
"internet" : true,
"duration" : NumberLong(0),
"cost" : 0.0,
"call_id" : NumberLong(18869599)
}
]
},
"response_code" : NumberLong(200),
"post" : [
],
"headers" : {
"Host" : "api3.roamerapp.com",
"X-App-Id" : "a9ee0beb8a2f6e6ef3ab77501e54fb7e",
"Accept" : "application/json",
"X-Sim-Operator" : "311480",
"X-Wsse" : "UsernameToken Username="/******S19a2RzV9cqY7b/RXPA=", PasswordDigest="******NTA4MDhkYzQ5YTVlZWI5NWJkODc5NjQyMzU2MjRjZmIzOWNjYzY3MzViMTY1ODY4NDBjMWRkYjdiZTQxOGI4ZDcwNWJmOThlMTA1N2ExZjI=", Nonce="******c1MzE1NTM2MTUyODIuNDk2NDEz", Created="Tue, 26 Mar 2019 15:48:01 GMT"",
"Accept-Encoding" : "gzip, deflate",
"Accept-Language" : "en-us",
"Content-Type" : "application/json",
"X-Request-Id" : "FB103646-1B56-4030-BF3A-82A40E0828CC",
"User-Agent" : "Roamer;iOS;511;en;iPhone 7;12.1.4",
"Connection" : "keep-alive",
"X-App-Build" : "511",
"X-Lang" : "EN",
"X-Connection" : "WiFi"
},
"created_at" : ISODate("2019-03-26T15:48:02.583+0000"),
"user_id" : "888689"
}Contacting the database owners was, of course, unsuccessful. The contacts on the website do not work, and no one responds to messages on social media.
The application is still available on the Apple App Store (itunes.apple.com/app/roamer-roaming-killer/id646368973).
News about data leaks and insiders can always be found on my Telegram channel "»: .
Source: habr.com
