nginx 1.25.3
tcp/443
MySQL is currently open without authentication.
Additionally a ransom note has been found in the dataset which indicates it has been compromised
This results in all the database data made available publicly.
Severity: critical
Fingerprint: cf350410ecceb5fdf06a1e48b152b767d796b88ad5476388b099dc21774d8d92
Databases: 82, row count: 4886, size: 3.7 MB Found table mysql.columns_priv with 0 records Found table mysql.component with 0 records Found table mysql.db with 2 records Found table mysql.default_roles with 0 records Found table mysql.engine_cost with 2 records Found table mysql.func with 0 records Found table mysql.general_log with 2 records Found table mysql.global_grants with 57 records Found table mysql.gtid_executed with 0 records Found table mysql.help_category with 53 records Found table mysql.help_keyword with 1092 records Found table mysql.help_relation with 1502 records Found table mysql.help_topic with 891 records Found table mysql.innodb_index_stats with 141 records Found table mysql.innodb_table_stats with 46 records Found table mysql.ndb_binlog_index with 0 records Found table mysql.password_history with 0 records Found table mysql.plugin with 0 records Found table mysql.procs_priv with 0 records Found table mysql.proxies_priv with 1 records Found table mysql.replication_asynchronous_connection_failover with 0 records Found table mysql.replication_asynchronous_connection_failover_managed with 0 records Found table mysql.replication_group_configuration_version with 1 records Found table mysql.replication_group_member_actions with 2 records Found table mysql.role_edges with 0 records Found table mysql.server_cost with 6 records Found table mysql.servers with 0 records Found table mysql.slave_master_info with 0 records Found table mysql.slave_relay_log_info with 0 records Found table mysql.slave_worker_info with 0 records Found table mysql.slow_log with 2 records Found table mysql.tables_priv with 2 records Found table mysql.time_zone with 0 records Found table mysql.time_zone_leap_second with 0 records Found table mysql.time_zone_name with 0 records Found table mysql.time_zone_transition with 0 records Found table mysql.time_zone_transition_type with 0 records Found table mysql.user with 4 records Found table readme_to_recover_a.recover_your_data with 2 records Found table ruoyi-portal.ad_management with 2 records Found table ruoyi-portal.company_contact with 0 records Found table ruoyi-portal.company_info with 2 records Found table ruoyi-portal.company_news with 2 records Found table ruoyi-portal.company_profile with 0 records Found table ruoyi-portal.company_recruit with 8 records Found table ruoyi-portal.company_vcard with 2 records Found table ruoyi-portal.development_history with 2 records Found table ruoyi-portal.gen_table with 12 records Found table ruoyi-portal.gen_table_column with 120 records Found table ruoyi-portal.pro_equipment with 2 records Found table ruoyi-portal.product_category with 6 records Found table ruoyi-portal.product_info with 68 records Found table ruoyi-portal.qrtz_blob_triggers with 0 records Found table ruoyi-portal.qrtz_calendars with 0 records Found table ruoyi-portal.qrtz_cron_triggers with 0 records Found table ruoyi-portal.qrtz_fired_triggers with 0 records Found table ruoyi-portal.qrtz_job_details with 0 records Found table ruoyi-portal.qrtz_locks with 0 records Found table ruoyi-portal.qrtz_paused_trigger_grps with 0 records Found table ruoyi-portal.qrtz_scheduler_state with 0 records Found table ruoyi-portal.qrtz_simple_triggers with 0 records Found table ruoyi-portal.qrtz_simprop_triggers with 0 records Found table ruoyi-portal.qrtz_triggers with 0 records Found table ruoyi-portal.qua_certificate with 0 records Found table ruoyi-portal.sys_config with 11 records Found table ruoyi-portal.sys_dept with 6 records Found table ruoyi-portal.sys_dict_data with 31 records Found table ruoyi-portal.sys_dict_type with 11 records Found table ruoyi-portal.sys_job with 3 records Found table ruoyi-portal.sys_job_log with 0 records Found table ruoyi-portal.sys_logininfor with 242 records Found table ruoyi-portal.sys_menu with 99 records Found table ruoyi-portal.sys_notice with 2 records Found table ruoyi-portal.sys_oper_log with 314 records Found table ruoyi-portal.sys_post with 4 records Found table ruoyi-portal.sys_role with 3 records Found table ruoyi-portal.sys_role_dept with 3 records Found table ruoyi-portal.sys_role_menu with 117 records Found table ruoyi-portal.sys_user with 2 records Found table ruoyi-portal.sys_user_online with 0 records Found table ruoyi-portal.sys_user_post with 2 records Found table ruoyi-portal.sys_user_role with 2 records
Open service 101.200.197.254:3306
2024-06-20 07:01
MySQL detected
Open service 101.200.197.254:443
2024-06-20 06:36
HTTP/1.1 302 Server: nginx/1.25.3 Date: Thu, 20 Jun 2024 06:36:34 GMT Content-Length: 0 Connection: close Set-Cookie: JSESSIONID=7f14fdd4-6476-42e4-90c0-a8d37c54722b; Path=/; HttpOnly; SameSite=lax Location: http://101.200.197.254/login
Open service 101.200.197.254:3306
2024-06-19 20:21
MySQL detected
Open service 101.200.197.254:3306
2024-06-17 21:26
MySQL detected
Open service 101.200.197.254:3306
2024-06-15 21:15
MySQL detected
Open service 101.200.197.254:3306
2024-06-11 21:21
MySQL detected
Open service 101.200.197.254:3306
2024-06-09 21:59
MySQL detected
Open service 101.200.197.254:3306
2024-06-07 21:11
MySQL detected
Open service 101.200.197.254:3306
2024-06-05 21:00
MySQL detected
Open service 101.200.197.254:3306
2024-06-03 20:15
MySQL detected