ShoBeVODSDT: Shodan and Binary Edge based vulnerable open data sources detection tool or what Internet of Things Search Engines know about you
Artjoms Daskevics, Anastasija Nikiforova · 2021
The paper proposes a tool for non-intrusive testing of open data sources for detecting their vulnerabilities, called ShoBeVODSDT (Shodan-and Binary Edge-based vulnerable open data sources detection tool). The use of Open Source Intelligence (OSINT) tools, more precisely the Internet of Things Search Engines (IoTSE), allows the tool to inspect a list of predefined data sources, such as MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch, CouchDB, Cassandra and Memcached, on their vulnerabilities and their extent, i.e. is the data source visible outside the organization? what data can be gathered from open data sources (if any) and what is their “value” for attacker and fraudsters? Whether these data can pose the risks to organization using them to deploy an attack? This allows both a comprehensive analysis of unprotected data sources, falling into a list of predefined data sources, or a specific IP or IP range to examine what can be seen from the outside of the organization about the data source in use. While the tool covers 8 data sources representing both rational databases, NoSQL databases and data stores, it is designed to be easily scalable, so, the list of data sources can be extended by third-parties by adapting the code made available. While some data sources can be described as complying with the security-by-design principle, some of them face serious challenges in this respect, including some databases already being compromised.