Page 1
Page 1
Started By
Message

The FBI's terrorist watchlist found in an exposed web database without a password

Posted on 8/27/21 at 6:51 am
Posted by NC_Tigah
Carolinas
Member since Sep 2003
123887 posts
Posted on 8/27/21 at 6:51 am
But by damn, at least the FBI is woke!
quote:

FBI watchlist exposed by misconfigured Elasticsearch cluster
A terrorist watchlist was found in an exposed database, and security researcher Bob Diachenko says there is no way of knowing just how long it was open to the public.

By Shaun Nichols
16 Aug 2021


An apparent U.S. government terrorism watchlist was found exposed to the open internet.

Security researcher Bob Diachenko discovered the data in an exposed Elasticsearch cluster and reported the list to the FBI.

...Diachenko says that server was discovered and reported on July 19, with the takedown completed on Aug. 9.

Comprising around 1.9 million records, the database was stored inside an Elasticsearch server that had not been configured to have any sort of password protection. The records included basic info such as names, dates of birth and countries of citizenship, as well as more sensitive information including passport numbers and whether that individual was also on the Transportation Security Administration's no-fly list.

The database was originally created by the FBI-led Terrorist Screening Center, an operation that also involves the Department of Homeland Security (DHS). The DHS referred request for comment to the FBI, whose spokespersons could not be reached to comment on the matter.

LINK
quote:

On July 19, 2021, The exposed server was indexed by search engines Censys and ZoomEye. I discovered the exposed data on the same day and reported it to the DHS.

The exposed server was taken down about three weeks later, on August 9, 2021. It's not clear why it took so long, and I don't know for sure whether any unauthorized parties accessed it.

LINK
You can't spell UnEffingBelievable without FBI
Posted by blueboy
Member since Apr 2006
56312 posts
Posted on 8/27/21 at 6:53 am to
Treason
Posted by cajunangelle
Member since Oct 2012
146688 posts
Posted on 8/27/21 at 6:54 am to
so was it a fake honeypot? LINK

or real names?
Posted by Gulffisherman
Bogalusa
Member since Oct 2009
3531 posts
Posted on 8/27/21 at 6:55 am to
quote:

FBI watchlist exposed by misconfigured Elasticsearch cluster


You can’t make this shite up
Posted by NC_Tigah
Carolinas
Member since Sep 2003
123887 posts
Posted on 8/27/21 at 7:23 am to
quote:

so was it a fake honeypot? LINK

or real names?
Real.

Diachenko ran his "honeypot" test in May to see how quickly unauthorized searches would occur in the event an internet database was exposed without a password.
quote:

The database was set up on 11 May and was removed on 22 May. In that time, Diachenko reported, 175 unauthorised requests were made, averaging 18 a day. The first came on 12 May, just eight hours and 35 minutes after deployment.
The terrorist database exposure was ID'd in July. Based on Diachenko's test work, and the fact the FBI left the database exposed 3wks after being notified of the problem, we can rest assured our terrorist watchlist database is no longer secret.
Posted by Jack Carter
Member since Sep 2018
10351 posts
Posted on 8/27/21 at 7:44 am to
Posted by Tantal
Member since Sep 2012
13958 posts
Posted on 8/27/21 at 7:51 am to
Too bad it's down. I'd be curious to know how many of us are on it.
Posted by teke184
Zachary, LA
Member since Jan 2007
95303 posts
Posted on 8/27/21 at 7:52 am to
I hope they spelled my name right.
Posted by themunch
Earth. maybe
Member since Jan 2007
64654 posts
Posted on 8/27/21 at 7:52 am to
quote:

our terrorist watchlist database is no longer secret.


I want a copy.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram