Уровень 0 · материалов: 5
В кластер входят документы о критических ошибках в конфигурации доступа и безопасности российских веб-сервисов и инфраструктур.
Общие признаки: отсутствие контроля доступа, открытые административные панели, небезопасные API, публичный доступ к внутренним серверам, информационная безопасность в России
Группа выше: Уязвимости российских и государственных систем
Смысл: The text exposes a critical security flaw in Moscow's surveillance infrastructure (ECXD) that allowed unauthorized access to over 20,000 cameras via simple URL manipulation, emphasizing the need for proper API authorization.
A user discovered and published a vulnerability in Moscow's surveillance system allowing anyone to view thousands of cameras by changing a numeric ID in a URL.
Смысл: The text demonstrates how a lack of proper access control on a public proxy server allowed an individual to discover and access hundreds of unsecured CCTV cameras in Moscow through simple URL manipulation and automated scanning.
The author discovered a vulnerability in Moscow's public camera system that allowed the discovery of 608 unsecured CCTV streams via proxy server enumeration.
Смысл: The text highlights a critical security failure on a VTB promotional site developed by Artemy Lebedev's studio, where open directories exposed internal code, customer data, and administrative panels due to a lack of basic server configuration.
A security researcher discovered that a VTB promotional website built by Lebedev's studio had open directories, exposing sensitive files and admin panels.
Смысл: The text highlights a widespread security negligence among Russian website administrators who leave memcached servers open to the public, exposing potentially sensitive data and system structures due to a lack of default authentication.
Approximately 1% of RuNet websites leave their memcached servers publicly accessible, exposing potentially sensitive data due to missing authentication configurations.
Смысл: The main idea is that many top Russian banks neglect basic web security by leaving their CMS admin panels exposed, which is unacceptable for financial institutions that should prioritize rigorous information security.
An analysis of leading Russian banks reveals that many dangerously leave their Bitrix CMS administration panels open to the public.