Get a Pentest and security assessment of your IT network.

Cyber Security

Online avatar service Gravatar allows mass collection of user info

A user enumeration technique discovered by security researcher Carlo Di Dato demonstrates how Gravatar can be abused for mass data collection of its profiles by web crawlers and bots. A hidden API route in the service enables anyone to obtain the user’s JSON data by simply using the profile “id”” field. The danger of this kind of issue is that a malicious user could download a huge amount of data and perform any kind of social engineering attack against legit users. The data is already public on Gravatar users on their profiles.”

Source: https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security