RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2

Amazon Relational Database Service (Amazon RDS)

Product
Developers: Amazon
Last Release Date: 2022/11/17
Technology: ITSM - IT Service,  DBMS Management Systems

The main articles are:

2022: Data breach

The leak of personal information from hundreds of databases on the Amazon Relational Database Service (Amazon RDS) was reported by researchers from Mitiga. According to them, such a leak is a real gift for attackers - it contains names, email addresses, phone numbers, dates of birth, marital status, car rental information and even company credentials. This became known on November 17, 2022.

The Amazon Relational Database Service (Amazon RDS) is a suite of managed services that makes it easier to set up, use, and scale a database in the cloud. It supports various database systems such as MariaDB, MySQL, Oracle, PostgreSQL, and SQL Server.

As experts figured out, the root cause of data leaks was a function that allows you to create a publicly available snapshot of the entire database environment working in the cloud. In the course of the study, which was conducted from September 21, 2022 to October 20, 2022, experts found 810 images that were in the public domain for several hours to several weeks, which means only one thing - attackers could use them.

It is worth noting that in its documentation, Amazon recommends not including any important information in a publicly available snapshot, since all other AWS users will be able to copy it.

Based on the nature of the information leaked to the network, experts believe that attackers will use it for financial gain or in order to better understand the company's IT environment, which could become their potential victim[1].

Notes