Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ Misconfigurations in Google Firebase lead to over 19.8 million leaked secrets

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Misconfigurations in Google Firebase lead to over 19.8 million leaked secrets


๐Ÿ’ก Newskategorie: Programmierung
๐Ÿ”— Quelle: dev.to

On March 19th, news broke that researchers uncovered more than 19.8 million plaintext credentials publicly exposed through instances ofย Google's Firebase. Firebase is a popular app development platform used by over 3 million developers worldwide and nearly 4,000 enterprises.

In mid March, three security researchers,ย mrbruh,ย xyzevaย andย logykk, discovered the secrets while checking more than 5 million websites for security flaws. This was a follow-up to previous research, in which they were able to gain "superadmin" permissions due to misconfigurations.

This new round of research unveiled 916 websites that had either no security rules implemented or where security was misconfigured. Not only were plaintext secrets discovered, but more than 125 million sensitive user records containing emails, names, phone numbers, and billing information with bank details were also discovered. According to theย original reporting summaryย "These numbers should be taken with a grain of salt. They are likely larger than shown here."

Improperly stored credentials

This incident is consistent with the conclusions we have drawn from our research released in theย State of Secrets Sprawl Report 2024: developers are increasingly improperly storing plaintext credentials, and secret sprawl is only getting worse.

The passwords uncovered were stored as plaintext inside the application databases. This is especially alarming because Google providesย Firebase Authentication. This end-to-end identity platform can make it unnecessary to store user passwords in the first place through the use of OpenID Connect or integration with any custom authentication service.

If a developer does need to store passwords in a database for some reason, there are very well-established patterns of using salted hashes or other encryption methods to ensure that if the database is exposed, the password entries will be useless. For these sites in question, it seems this was not a consideration. The researchers reported that, to them, "companies must have gone out of their way to store [the password] in plain text."

Researchers report showing the counts of records with unhashed credentials
Researchers report showing the counts of records with unhashed credentials Source: env.fail

IaC means misconfiguration at scale

These findings also show that misconfigurations continue to provide an attack vector for malicious actors, as we have seen with other reports, such as a researcherย finding GitHub admin credentialsย at a major car company andย Microsoft leaking 38 TB of records. The issue is only compounded when deploying at scale, as a misconfiguration in one instance can easily mean misconfigurations in hundreds of incidents, all by changing one variable.

This is why GitGuardian developedย Infra as Code Security. The GitGuardian platform can scan for over 100 of the most common IaC misconfigurations. We can help developers detect issues likeย using HTTP instead of HTTPSย orย Unrestricted ingress traffic, which can lead to attackers from unknown IP addresses accessing your internal DBs. Security and development teams can shift left with GitGuardians IaC scanning thanks toย ggshield, our CLI, which can detect and prevent IaC misconfigurations before a commit is made.ย ย 

Multifactor authentication is vital for applications

Unfortunately, if security researchers could easily uncover this many passwords, it is likely that malicious actors also discovered them. As we saw inย other recent attacks, such as the one at Cloudflare, it is likely only a matter of time before these passwords will be used in a future attack. It is more vital than ever for developers to keep plaintext passwords out of their code, databases, and environments.

One way developers can protect users is by implementing multifactor authentication, MFA. As Microsoft is fond of reporting, "MFA can prevent 99.9 percent of attacks on your accounts." If properly implemented, even if a malicious actor does get your password, they will still not be able to gain access unless they also have access to your other authentication method. While it is not a completely foolproof system for advanced persistent threat actors, as we saw with incidents like the one atย MGM, it will deter the most common attacks.

Leverage available security tools early in development

It is easy from the outside to say, "If they had just done X, this would not have happened." Hindsight is 20/20. The truth is security is challenging to get right at every step, especially if you are under pressure and up against tight deadlines. Developers don't need additional steps or forced "best practices" mandated on top of their workload. What they need are better tools that integrate as seamlessly as possible into their flow.

At GitGuardian, we believe in meeting the security challenge at every step of the software development lifecycle. With ggshield, developers can set pre-commit hooks to double-check for common IaC misconfigurations and for anyย secrets they might have added in plaintext. We can also scan at the pull request step or asย late as the CI/CD pipeline, meeting you where you are on your security journey.

...



๐Ÿ“Œ Misconfigurations in Google Firebase lead to over 19.8 million leaked secrets


๐Ÿ“ˆ 77.43 Punkte

๐Ÿ“Œ Google Firebase May Have Exposed 125M Records From Misconfigurations


๐Ÿ“ˆ 34.94 Punkte

๐Ÿ“Œ Thousands of Android Apps Leak Data Due to Firebase Misconfigurations


๐Ÿ“ˆ 32.94 Punkte

๐Ÿ“Œ Over 12 million auth secrets and keys leaked on GitHub in 2023


๐Ÿ“ˆ 31.26 Punkte

๐Ÿ“Œ Creating a Google Sign-In with Firebase (Firebase Authentication)


๐Ÿ“ˆ 30.63 Punkte

๐Ÿ“Œ Creating a Google Sign-In with Firebase (Firebase Authentication)


๐Ÿ“ˆ 30.63 Punkte

๐Ÿ“Œ CipherCloud helps prevent unintended cloud misconfigurations that lead to data loss


๐Ÿ“ˆ 29.85 Punkte

๐Ÿ“Œ Top Firewall Misconfigurations that Lead to Easy Exploitations by Attackers


๐Ÿ“ˆ 29.85 Punkte

๐Ÿ“Œ Top Firewall Misconfigurations that Lead to Easy Exploitations by Attackers


๐Ÿ“ˆ 29.85 Punkte

๐Ÿ“Œ ServiceNow Misconfigurations Lead to Leak of Sensitive Data


๐Ÿ“ˆ 29.85 Punkte

๐Ÿ“Œ Firebase Summit product updates, Firebase Crashlytics SDK upgrade, Cloud Shell Editor, and more!


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ Firebase Authentication: Build a Smooth Authentication Flow System with Firebase


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ Fixed No Firebase App '[DEFAULT]' has been created - call firebase.initializeApp() In React Native


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ Firebase-Extractor - A Tool Written In Python For Scraping Firebase Data


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ Internet scans find 1.6 million secrets leaked by websites


๐Ÿ“ˆ 25.71 Punkte

๐Ÿ“Œ AppOmni Raises $10 Million to Help Companies Prevent Cloud Misconfigurations


๐Ÿ“ˆ 24.23 Punkte

๐Ÿ“Œ 100 Million Users Exposed Due to Small Misconfigurations


๐Ÿ“ˆ 24.23 Punkte

๐Ÿ“Œ Secrets Hub fรผr AWS Secrets Manager


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Secrets Hub fรผr AWS Secrets Manager - com! professional


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Tell Me Your Secrets Without Telling Me Your Secrets


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ The Secrets of Python โ€œSecretsโ€


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Amazon Addresses Best Practice Secrets Management with AWS Secrets Manager


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Git-Secrets Prevents You From Committing Secrets And Credentials Into Git Repositories


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ 1Password Secrets Automation helps businesses secure and manage secrets


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Secure, orchestrate, and manage your companyโ€™s infrastructure secrets with 1Password Secrets Automation


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Secrets Sensei: Conquering Secrets Management Challenges


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Hard-coded secrets up 67% as secrets sprawl threatens software supply chain


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Bitwarden Secrets Manager secures, controls, and manages infrastructure secrets


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Effective Secrets Management: Retrieving Secrets From Azure Key Vault With Powershell Script


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Two ways to manage secrets for AWS Redshift Serverless with AWS Secrets Manager !!


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Managing Secrets Security at any Scale: introducing the GitGuardian Secrets Management Needs Quiz


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Two flaws that could lead to Potential lead to RCE fixed by OpenSSL project team


๐Ÿ“ˆ 22.44 Punkte

๐Ÿ“Œ Google I/O 2021: Firebase tops 3 million app mark, rolls out bevy of updates


๐Ÿ“ˆ 21.92 Punkte

๐Ÿ“Œ GKE Auditor โ€“ Detect Google Kubernetes Engine Misconfigurations


๐Ÿ“ˆ 20.63 Punkte

๐Ÿ“Œ Cloudbleed: Big web brands leaked crypto keys, personal secrets thanks to Cloudflare bug


๐Ÿ“ˆ 20.1 Punkte











matomo