r/Information_Security
Found out someone in ops built a customer facing app on Replit and no one told IT
- upvotes
- 227
- comments
- 24
Post
Highlighted: the lines this signal was extracted from
I work at a mid-size manufacturing company that rhymes with Schmondelez. Stumbled into this one. Someone in ops has had an intake form running on Replit for about two months, customers fill it out, it writes straight to a database. Only noticed because a vendor called asking why a subdomain I didn't recognize was throwing a cert warning. Asked ops who owns it. Answer was "it just works, why does it matter." Asked if the admin view has auth on it. Silence, then "I dunno think so, I never set one up." Asked where the database lives. He had to go check. It's been live and indexed since October. I dunno what's in it at this point, and I'm not sure he does either. Not filing an incident yet since nothing's confirmed leaked. Just sitting here wondering how many more of these exist that I haven't stumbled into by accident.
Also quoted as evidence
[comment u/skynetcoder] maybe you can find more here. https://crt.sh/?q=mondelezinternational.com