Home

Mar 19, 2020

Blisk Browser Vendors Leaked Data Via Unsecured Database Server


Vendors behind the Blisk browser – a dedicated browser for web developers – inadvertently left a database unsecured that leaked data containing millions of records. Blisk is a web browser tailored for web developers keeping in view their needs. Launched in 2014, the browser’s userbase includes some prominent names as well, such as Apple, Microsoft, NASA, eBay, UNICEF, and others.

Blisk Vendor Data Leaked Security researchers from vpnMentor, Noam Rotem and Ran Locar, discovered another unsecured server exposing users’ data. This time, the open server belonged to the Blisk browser vendors, which leaked data related to web developers.

Detailing their findings in a post, the researchers revealed that they found an unprotected Elasticsearch database leaking data. It precisely contained 3.4GB of data that included more than 2.9 million records.

Blisk obtained this data from users without the need to bypass any security measures. The exposed information included sensitive details about users, including their email addresses, user agent details, and IP addresses. While leaving databases open is already negligent, the additional issue with Blisk was the way they collected the data. According to the researchers,

Since the browser “sees” what the user sees, it can potentially bypass encryption, 2-factor authentication, and any other measure they have in place. If the user is using software that is not heavily secured, this can lead to very serious security breaches. It appears that no matter what security measures you put in place while using Blisk, your data would still potentially be leaked.

Database Now Closed Upon finding the unprotected server, the researchers traced back the vendors and informed them of the matter. Following their report, the vendors addressed the matter in a few days pulling the database offline.

Though the researchers fear that the kind of information left online could lead to serious security threats, Blisk confirmed to ZDNet that the incident did not affect any sensitive data. Nonetheless, any Blisk user eager to know about the potential impact on oneself of the incident may contact the vendors for details.

 

Category: General
Posted by: Admin
authorarticle: Master3395
blisk.png
video: 
youtube: 
sources: 
keywords: data exposed, Data Leak, data leaked, database, database security, Elastic database, ElasticSearch, ElasticSearch Server, Leaky database, No password on database, unprotected database, unsecured database, Unsecured server, user data compromised, user deta

Comments:

comments powered by Disqus

Return
Discord

Page 1 of 506  >  >>

Microsoft with Skype crisis response: removes login requirements, copies Zoom

skype.webp

Apr 4, 2020 | Category: Microsoft | Comments

Do as Zoom with link sharing and no Microsoft account requirements.

During the corona crisis, Microsoft has finally found that it must be easy to start meetings and stay in touch.

read more…

OnePlus 8 gets top marks

oneplus8.webp

Apr 3, 2020 | Category: General | Comments

And that's before it's launched.

On April 14 at 17:00, OnePlus 8 will be unveiled.

read more…

Tekya Malware Targets 1 Million Android Users Through Malicious Apps On Play Store

android.jpg

Apr 2, 2020 | Category: Google | Comments

While Google employs some tough policies for app developers to keep the Play Store safe, yet it never remains so. Once again, criminal hackers managed to ditch Google’s policies and flood the Play Store with malicious Android apps.

This time, they target users with Tekya malware distributed via numerous apps with almost 1 million downloads.

read more…

Page 1 of 506  >  >>