Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Rangarira I akanyora pana Habré uye kumba muTeregiramu chiteshikuti ruzivo rwekubhadhara mukufarira mapurisa emigwagwa uye FSSP yevashandisi vesaiti yave kuwanikwa pachena paygibdd.rf, paygibdd.ru, gos-oplata.ru, fines.net и oplata-fssp.ru?

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Ingo usaseka, uku hakusi kuseka zvachose - iyo imwechete sevha ine data kubva kune imwecheteyo system zvakare yakave yakavhurika kune nyika yese.

Zvakanaka, handei tinoona ...

Дисклеймер: вся информация ниже публикуется исключительно в образовательных целях. Автор не получал доступа к персональным данным третьих лиц и компаний. Информация взята либо из открытых источников, либо была предоставлена автору анонимными доброжелателями.

Kutanga, rega ndikuyeuchidze zvishoma nezve kuverengwa kwenguva kwezviitiko:

  • Musi waApril 12.04.2019, XNUMX (husiku), sevha yeElasticsearch yakawanikwa iyo yaisada humbowo hwekubatanidza.
  • Pana 13.04.2019/XNUMX/XNUMX (mangwanani) chiziviso chakatumirwa kune varidzi veseva.
  • Musi waApril 13.04.2019, XNUMX (masikati), sevha yakabviswa "chinyararire" kubva paruzhinji.

Panguva yekuvharwa kwesevha yekutanga, maElasticsearch indexes aitaridzika seizvi:

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Uye zvino pa 21.05.2019/16/00 panguva dzinenge XNUMX:XNUMX (nguva yeMoscow), iyo yakafanana Elasticsearch server, ine yakafanana (pamwe nenyowani) indexes zvakare inooneka munzvimbo yeruzhinji:

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Handina kukwanisa kutenda maziso angu pandakazviona (pakarepo mushure mekuita pa PHDays pamusoro penyaya yekuona yakavhurika dhatabhesi) mune tsamba yekuzivisa kubva kune yedu DeviceLock Data Breach Intelligence. Kutaura chokwadi, pfungwa yangu yekutanga yaive yekuti iyi yaive imwe mhando yesystem glitch.

Nekudaro, kwete, yanga isiri glitch uye mushure mekutarisa zvese nemawoko, na01:25 muna Chivabvu 22.05.2019, XNUMX, ndakatumira yambiro kumakero akafanana nekekutanga.

Kubva pakuvhara kwekutanga, sevha iyi yakaongororwa naShodan ka11 uye kusvika May 21, Elasticsearch yakavharwa pairi.

Mangwanani chete aMay 24.05.2019, XNUMX, iyi Elasticsearch yakanyangarika kubva paruzhinji kechipiri. Munguva ino, ma indices akawedzera zvakanyanya:

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Uye kana iwe ukatarisa iyo data (chete ruzivo rwakakosha rune ruzivo rwevanhu vevagari) mune indices yenguva kubva Chivabvu 1 kusvika Chivabvu 22, ipapo mufananidzo unotevera:

  • 127,525 zvinyorwa muindex paygibdd
  • 49,627 zvinyorwa muindex shtrafov-net
  • 162,282 zvinyorwa muindex oplata-fssp
  • 220,201 zvinyorwa muindex gosoplata

Muenzaniso data kubva index gosoplata:

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Muenzaniso data kubva index paygibdd:

Zvakare, mazana ezviuru zvekubhadhara kwevagari kumapurisa emigwagwa uye FSSP aive munharaunda yeruzhinji

Zvakanaka, icing pakeke yaive tsamba kubva kune imwe kero kwandakatumira zviziviso:

Tatambira tsamba yenyu nezve ElasticSearch yakavhurika - tinotenda neruzivo, dhatabhesi rakavharwa. System administrator akavhurazve kupinda adzingwa. Bazi rezvemitemo riri kugadzirirawo kutumira kuBazi reMukati meRepublic of Tatarstan Chirevo pamusoro pezviratidzo zvekuvapo muzviito zvemutongi wehurongwa hwezvinhu pasi peChinyorwa 272 ne273 cheCriminal Code yeRussian Federation.

Nhau nezve ruzivo rwunoburitswa uye vemukati vanogona kugara vachiwanikwa pane yangu Telegraph chiteshi "Ruzivo rwunobuda»: https://t.me/dataleak.

Source: www.habr.com

Voeg