NEILREN.COM Source Code Leaked and Downloaded — Fire in the Backyard

Because I was busy looking for a job recently and just arrived in Beijing, the pace of life is fast and I rarely tend to the site and servers. Today, while doing log analysis, I found a very serious human-caused vulnerability that led to the site source code leaking.

When updating the site version, I have the habit of keeping a backup version: compress the old site with RAR, then replace it with the new files. But I never expected that great social engineering and scanning tools would actually guess the file name, causing the source code to leak. Someone scanned www.neilren.com/neilren.com.rar — this file is my entire site’s program, which also contains the database connection string, database address, database name, username, and password.

After discovering it had been downloaded, I immediately checked the database. Fortunately, thanks to the security mechanism of Alibaba Cloud’s RDS, I use the intranet database connection address. Of course there were also downloads from Alibaba Cloud’s intranet, but RDS has another mechanism — a whitelist. To connect to the database, the server’s IP must be added to the whitelist. So luckily the backyard didn’t catch fire, the data wasn’t tampered with, and I immediately changed the database password.

Here is my statistics:


neilren.com.rar was requested 55 times in total: 30 HEAD requests (10 returned 200, 20 returned 404), 25 GET requests (7 returned 200, 17 returned 206, 1 returned 404).

neilren.com.rar was successfully downloaded 7 times. The following are those who downloaded it successfully: 2016-04-05 04:51:45 163.177.69.38 (Shenzhen, Guangdong — Unicom) 2016-04-05 04:51:48 101.226.93.234 (Shanghai, Shanghai — Telecom) 2016-04-05 04:55:39 182.140.168.114 (Chengdu, Sichuan — Telecom) 2016-04-05 05:03:45 101.227.131.246 (Shanghai, Shanghai — Telecom) 2016-04-05 08:10:53 211.157.175.99 (Changping, Beijing — 263 Network) 2016-04-09 03:26:31 42.51.157.111 (Zhengzhou, Henan — BGP multi-line) 2016-06-25 02:11:32 110.203.95.71 (Changsha, Hunan — China TieTong)


Some key points in time: 121.127.225.213 (Hong Kong SAR) — the first person to guess the file name, at 2015-08-08 01:57:45 the server returned 404. 120.26.231.155 (Hangzhou, Zhejiang — Alibaba) — the first person to discover the file existed, a HEAD request, at 2016-02-27 02:16:08 the server returned 200. 163.177.69.38 (Shenzhen, Guangdong — Unicom) — the first person to successfully download the file, a GET request, at 2016-04-05 04:51:45 the server returned 200. 110.203.95.71 (Changsha, Hunan — China TieTong) — started at 2016-06-25 02:11:32, ended at 2016-06-25 02:12:22, multiple resumed downloads.


All IPs involved with this file: 121.127.225.213 (Hong Kong SAR) 183.93.224.219 (Yichang, Hubei — Unicom) 115.231.235.142 (Jiaxing, Zhejiang — Telecom) 112.74.207.193 (Shenzhen, Guangdong — Alibaba) 120.24.171.125 (Shenzhen, Guangdong — Alibaba) 139.196.54.118 (Shanghai, Shanghai — Alibaba) 183.61.236.95 (Dongguan, Guangdong — Telecom) 120.26.231.155 (Hangzhou, Zhejiang — Alibaba) 211.157.175.99 (Changping, Beijing — 263 Network) 163.177.69.38 (Shenzhen, Guangdong — Unicom) 101.226.93.234 (Shanghai, Shanghai — Telecom) 182.140.168.114 (Chengdu, Sichuan — Telecom) 101.227.131.246 (Shanghai, Shanghai — Telecom) 42.51.157.111 (Zhengzhou, Henan — BGP multi-line) 110.203.62.98 (Yuelu, Changsha, Hunan — China TieTong) 110.203.95.71 (Changsha, Hunan — China TieTong) [multiple resumed downloads] 120.55.88.144 (Hangzhou, Zhejiang — Alibaba) 116.255.177.114 (Zhengzhou, Henan — Unicom)


Summary

This source-code leak accident, as it stands, has caused no impact — they probably haven’t yet found a vulnerability to tamper with the database. After getting the source code in the future they might analyze and find a way to tamper with the database, or they might not be interested in hacking me. But I still reserve the right to report to the police or sue, and I will keep the relevant logs and evidence. Finally, a reminder to everyone: backup files must be moved out of the website directory, and no IIS permissions should be granted outside the website directory. Learn from this mistake — delete this file promptly.

Finally, screenshots of my statistics: