Information Security News mailing list archives

Online casino group leaks information on 108 million bets, including user details


From: InfoSec News <alerts () infosecnews org>
Date: Tue, 22 Jan 2019 07:54:00 +0000 (UTC)

https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/

By Catalin Cimpanu
Zero Day
ZDNet News
January 21, 2019

An online casino group has leaked information on over 108 million bets, including details about customers' personal information, deposits, and withdrawals, ZDNet has learned.

The data leaked from an ElasticSearch server that was left exposed online without a password, Justin Paine, the security researcher who discovered the server, told ZDNet.

ElasticSearch is a portable, high-grade search engine that companies install to improve their web apps' data indexing and search capabilities. Such servers are usually installed on internal networks and are not meant to be left exposed online, as they usually handle a company's most sensitive information.

Last week, Paine came across one such ElasticSearch instance that had been left unsecured online with no authentication to protect its sensitive content. From a first look, it was clear to Paine that the server contained data from an online betting portal.

[...]



--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_


Current thread: