Samsung leaked SmartThings app source code and secret keys
#1
Quote:A security researcher at a Dubai-based cybersecurity firm SpiderSilk discovered a development lab used by Samsung engineers was leaking highly sensitive source code, credentials and secret keys for several internal projects — including its SmartThings  platform.
 
The researcher, Mossab Hussein, found Samsung engineers had left dozens of internal coding projects on a GitLab instance hosted on a Samsung-owned domain. 
 
The platform was used by staff to share and contribute code to various Samsung apps, services and projects and contained logs and analytics data for Samsung’s SmartThings and Bixby services, but also several employees’ exposed private GitLab tokens stored in plaintext, which allowed the researcher to gain additional access from as many as 135 projects, including many private projects.
 
Hussein reported the issue to Samsung on April 10, 2019, and said Samsung took until April 30 to revoke the GitLab private keys although it did immediately begin revoking the AWS credentials. But it’s not known if the remaining secret keys and certificates were revoked, the researcher told TechCrunch.

SOURCE: https://www.scmagazine.com/home/security...cret-keys/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes 19.1.6
25.4.0 All TODO...Kool — 16:06
YouTube updates Shorts view count metho...
This is a smart and ...Kiran78 — 11:41
Microsoft Edge 135.0.3179.73
Version 135.0.3179...harlan4096 — 06:08
AnyDesk 9.5.1 for Windows
AnyDesk 9.5.1 for ...harlan4096 — 06:07
Messengers 101: safety and privacy advic...
A dozen short and ...harlan4096 — 06:05

[-]
Birthdays
Today's Birthdays
avatar (37)urumahiz
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (45)MeighGoask
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
avatar (42)cdoubapKit
avatar (37)lystraPonia
avatar (30)smith8395john
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (45)Rodneykak
avatar (48)tradeSmode
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>