Samsung exposed sensitive data, credentials and source codes of several major projects

Samsung logo

According to a security researcher, Mossab Hussein, Samsung was leaking sensitive data, such as credentials, source codes and secret keys, for various important projects.

Unknowingly, the company had given "public" access to critical files in your development lab on GitLab, which were not protected with a password.

The exposed data contained credentials for the Amazon web services account that was used for the development of Samsung services. These additionally reveal 100 S3 storage compartments attached to the same AWS account containing log and analytics data.

Samsung

Employee GitLab access tokens are also part of the sensitive data that was discovered. The security researcher gained access to various public and private projects with the access tokens, increasing the number of exposed projects from 43 to 135. “I had the private token of a user who had full access to all 135 projects on that GitLab "Says Mossab Hussein.

Most of the publicly viewable files contained data related to Samsung's SmartThings and Bixby services. It could have been "disastrous" if some bad actor manipulated the code.

Samsung hosts multiple projects at Vandev Lab, a company's GitLab repository for development purposes. The same repository contains projects like Samsung's SmartThings platform and Bixby services.

However, Samsung has now revoked access to all keys and credentials on the test platform. The company is investigating to find evidence of any external access after this event.

After all this was discovered, the firm will apply stronger security measures in all its laboratories, clearly, as well as in other sectors open to different audiences, with the intention that something similar does not happen again in the future.

(Source)


samsung models
You are interested in:
This is the catalog of Samsung models: smartphones and tablets
Follow us on Google News

Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Actualidad Blog
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.