https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/
By Catalin Cimpanu
Zero Day
ZDNet News
January 21, 2019
An online casino group has leaked information on over 108 million bets,
including details about customers' personal information, deposits, and
withdrawals, ZDNet has learned.
The data leaked from an ElasticSearch server that was left exposed online
without a password, Justin Paine, the security researcher who discovered the
server, told ZDNet.
ElasticSearch is a portable, high-grade search engine that companies install to
improve their web apps' data indexing and search capabilities. Such servers are
usually installed on internal networks and are not meant to be left exposed
online, as they usually handle a company's most sensitive information.
Last week, Paine came across one such ElasticSearch instance that had been left
unsecured online with no authentication to protect its sensitive content. From
a first look, it was clear to Paine that the server contained data from an
online betting portal.
[...]
--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_