Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

Mondee security lapse exposed flight itineraries and unencrypted credit card numbers

  • August 2, 2023
Total
0
Shares
0
0
0

Travel giant Mondee has secured an exposed database that was spilling sensitive customer information, including detailed flight and hotel itineraries and unencrypted credit card numbers.

Anurag Sen, a good-faith security researcher known for discovering inadvertently exposed data on the internet, found the database and shared details with TechCrunch to alert the company.

According to Sen, the database was exposed to the internet without a password, allowing anyone to access the sensitive data inside using a web browser, just with its IP address. TechCrunch found that the database was also accessible from an easily-guessable subdomain of a Mondee subsidiary’s website.

Much of the data appears to relate to Mondee subsidiary TripPro, a travel agent platform used by tens of thousands of booking agents and travel startups allowing self-service flight ticketing and hotel booking.

The database, hosted on Oracle’s cloud, contained customer’s personal information, including names, gender, dates of birth, home addresses, flight information, and passport numbers. Some of the data seen by TechCrunch includes full customer passenger name records, or PNR, including ticket and booking details. TechCrunch has also seen customers’ full credit card numbers and expiry dates in the database, but none of the data was encrypted.

TechCrunch verified that the exposed data matches real people’s information. One person we spoke to confirmed their flight information was accurate and said they booked their flights through a popular booking site.

The database also contained non-customer testing data generated by Mondee developers.

The database was first spotted as exposed in late-July, according to a listing on Shodan, a search engine that crawls the web for exposed servers and databases. The circumstances of how the database became publicly accessible are not known, though database exposures are often misconfigurations caused by human error.

When reached by email, Mondee spokesperson Karen Gillo did not acknowledge the incident or provide comment. The database became inaccessible a short time after TechCrunch contacted Mondee.

It is not yet known if anyone other than Sen found the exposed database during the window it was accessible from the internet. TechCrunch asked Mondee if the company has the technical ability, such as logs, to determine what, if any, data was accessed or exfiltrated from the database.

Mondee did not say if it plans to notify affected customers of this data exposure.

Read more on TechCrunch:


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

AMD’s RX 7900 XTX is finally in Steam hardware survey but hardly any gamers use it

  • August 2, 2023
View Post
Next Article
  • Technology

X, formerly Twitter, streamlines its crowdsourced fact-checking system Community Notes

  • August 2, 2023
View Post
You May Also Like
View Post
  • Technology

Inside Kinhub’s plan to democratize employee wellness

  • September 21, 2023
View Post
  • Technology

eStreamly blends physical, digital shopping with the video as the star

  • September 21, 2023
View Post
  • Technology

Salesforce to acquire Airkit.ai, a low-code platform for building AI customer service agents

  • September 21, 2023
View Post
  • Technology

AvantGuard wants to turn chlorine into the best antiseptic you’ve ever seen

  • September 21, 2023
View Post
  • Technology

Meredith Whittaker reaffirms that Signal would leave U.K. if forced by privacy bill

  • September 21, 2023
View Post
  • Technology

OnePlus confirms its first foldable is officially ‘coming soon’

  • September 21, 2023
View Post
  • Technology

Don’t want that commuter stipend? Bundl enables employees to choose their own company benefits

  • September 21, 2023
View Post
  • Technology

GGV splits off China business following congressional panel probe

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.