this post was submitted on 30 Jan 2025
15 points (100.0% liked)

Technology

1060 readers
46 users here now

A tech news sub for communists

founded 2 years ago
MODERATORS
 

[...] a publicly accessible ClickHouse database linked to DeepSeek, completely open and unauthenticated, exposing sensitive data. It was hosted at oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000.

This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details.

More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.

It seems that the Empire has decided to strike.

you are viewing a single comment's thread
view the rest of the comments
[–] itsraining@lemmygrad.ml 4 points 1 month ago

thank you for the analysis