All vulnerabilities
HIGHOpSec

OPSEC-INTERNET-ARCHIVE-2024

SaaS · Internet Archive

Summary

Beginning around October 9, 2024, the Internet Archive suffered overlapping attacks rooted in unrotated, exposed authentication tokens. A plaintext GitLab token left in a publicly accessible config file on a dev server (exposed since at least December 2022 and never rotated) let an attacker download source code containing further embedded database credentials, enabling exfiltration of a user database of around 31 million users with emails and bcrypt-hashed passwords. A JavaScript defacement and DDoS attacks accompanied it. On October 20, 2024, an unrotated Zendesk API token, also exposed via the same token mismanagement, was used to access more than 800,000 support tickets, some containing personal ID documents.

References

Related vulnerabilities

All OpSec →