Skip to main content

Porn site BangBros apparently leaked millions of records, including user data

A man is looking at a porn internet site on a screen

Porn site BangBros has allegedly exposed user and model information, cyber security site Cybernews reported.

In June, the research team at Cybernews discovered more than eight gigabytes of sensitive information about BangBros users. This information included IP addresses, usernames, messages, countries and geolocations, and model names, ages, and descriptions.

"Although the credentials were not leaked directly, hackers can associate the IP addresses with the identity from other leaks," explained Cybernews information security researcher Mantas Kasiliauskis in its reporting.

The sensitive information had been stored on an unprotected instance of Elasticsearch, a searchable distributed document storage system typically used for high-volume data. The largest file of the leak contained nearly 11 million records. Cybernews researchers claim this data was likely left unprotected because of an "inadvertent configuration error."

Cybernews contacted BangBros, and the error was fixed. According to Cybernews, however, there's still a risk to users if adversaries accessed the data.

"If bad actors managed to get their hands on this data, they might trace and link adult content viewers' habits to specific individuals," Kasiliauskis said. "Combined with other private information, this could lead to significant privacy issues, cause personal embarrassment, and result in social stigma in places with conservative attitudes."

Mashable has reached out to BangBros for comment and will update if we hear back.



from Mashable https://ift.tt/ltmGZ20
via IFTTT

Comments

Popular posts from this blog

Instagram accidentally reinstated Pornhub’s banned account

After years of on-and-off temporary suspensions, Instagram permanently banned Pornhub’s account in September. Then, for a short period of time this weekend, the account was reinstated. By Tuesday, it was permanently banned again. “This was done in error,” an Instagram spokesperson told TechCrunch. “As we’ve said previously, we permanently disabled this Instagram account for repeatedly violating our policies.” Instagram’s content guidelines prohibit  nudity and sexual solicitation . A Pornhub spokesperson told TechCrunch, though, that they believe the adult streaming platform’s account did not violate any guidelines. Instagram has not commented on the exact reasoning for the ban, or which policies the account violated. It’s worrying from a moderation perspective if a permanently banned Instagram account can accidentally get switched back on. Pornhub told TechCrunch that its account even received a notice from Instagram, stating that its ban had been a mistake (that message itse...

Colorado police identified the serial killer who murdered 4 women 40 years ago after exhuming his body to analyze a DNA sample

A scientist examines computer images of DNA models. Getty Images Police in Colorado have cracked the cold cases of four women killed 40 years ago. Denver PD said genetic genealogy and DNA analysis helped them identify the serial killer. He had died by suicide in jail in 1981. DNA from his exhumed body matched evidence from the murders. Police in Colorado have cracked the code on four murder cases that went unsolved for 40 years, using DNA from the killer's exhumed body. The cases pertain to four women killed in the Denver metro area between 1978 and 1981. They were 33-year-old Madeleine Furey-Livaudais, 53-year-old Dolores Barajas, 27-year-old Gwendolyn Harris, and 17-year-old Antoinette Parks. The four women were stabbed to death. Denver Police Commander Matt Clark said in a press conference Friday that there was an "underlying sexual component" to the murders but didn't elaborate further. In 2009, a detective reviewed Parks' case and picked several p...