Toyota subcontractor puts customer database key on Github - South Africans likely unaffected

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,887
Reaction score
13,571
Location
The Rabbit Hole
Toyota warns database with 300,000 customers exposed after access key was accidentally put online

Toyota has warned the personal information of almost 300,000 customers using its T-Connect car app may have been exposed after access to its database was accidentally leaked online.

BleepingComputer reports the Japanese automotive giant published a notice informing customers that a part of the T-Connect site's source code posted to Github also contained an access key to the data server storing customer email addresses and management numbers.
 
  • Wow
Reactions: Yuu
Committing sensitive information to a Git repo aside, is there a valid reason a DB server would be accessible on the public internet. Nothing in the article says it could be, but it does give the impression it was.

Even if someone got the access key, normally the DB server is in a private subnet and public access is done via an API. Further to that, the DB itself should be configured to allow connections for specific hosts for specific username/password combinations. Then in order for those credentials to be useful, the hacker would first need to compromise the server the credentials are belong to.

If Toyota have a DB server sitting on the public internet using a single set of credentials, leaking of those credentials is only the start of their problems.
 
Top
Sign up to the MyBroadband newsletter
X