Imobiliare.ro user data allegedly leaked
A Romanian real estate site, Imobiliare.ro, had its user database allegedly stolen and put up for sale on the dark web. Attackers claimed to get in by exploiting a misconfigured debug setting on the site's servers.
- Report priority
- Medium
- Targets
- Fortinet
How it works
- Attackers found a misconfigured debug setting on Imobiliare.ro's servers that showed error details, including a database connection string.
- They used that to break into the site's database.
What to do
Check if you used Imobiliare.ro to buy, sell, or rent property in Romania. If you did, monitor your email and phone for suspicious messages or calls.
Change passwords for any accounts linked to Imobiliare.ro if you suspect they were compromised.
Technical details
Affected software: Fortinet
An attacker visits Imobiliare.ro and sees a detailed error page because the site's debug setting is turned. The error shows the database connection details. The attacker uses those details to log into the database and steals 1.2 million user records, including emails, phone numbers, and property listings. They then list the stolen data for sale on the dark web.
An alleged database leak from Imobiliare.ro, a Romanian real estate platform, was advertised on underground forums. The seller claimed to have accessed 1.2 million user records, including emails, phone numbers, property listings, and transaction history, by exploiting an exposed ASP.NET debug configuration in production. The attacker allegedly triggered a verbose error page by querying a non-existent URL, revealing the SQL Server cluster connection string and enabling backend data access.
If authentic, this exposure could enable phishing, real estate fraud, and targeted scams using stolen property and transaction details. The listing was attributed to NEWS-8c58d2ce4c4509f1e8 and involved a misconfigured debug mode (customErrors=Off, debug=True), a common oversight in web applications. No CVE or CVSS score was assigned, as this appears to be a configuration error rather than a software vulnerability.
References
- bleepingcomputer.com · hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages BleepingComputer
- thehackernews.com · 24-npm-packages-abuse-unpkg-mirrors-to.html TheHackerNews
- infosecurity-magazine.com · gunra-ransomware-fortinet-flaws Infosecurity Magazine
- neuracybintel.com · critical-metabase-zero-day-sql-injection-flaw-actively-exploited-exposing-customer-data-at-framework-and-tally NeuraCybIntel