Brazilian Volvo dealer Dimas Volvo leaked database credentials for a year

Organization
Dimas Volvo
Exploit
Misconfiguration
Industry
Automotive Retail

Cybernews researchers reported in April 2023 that Dimas Volvo, an independent Volvo dealer serving the Santa Catarina region of Brazil, had been exposing sensitive configuration files through its public website. The files were found on February 17, 2023 and, according to the research, had been reachable for close to a year.

The exposure did not involve customer records directly. It revealed the credentials needed to reach them. The files contained authentication details for the site's MySQL and Redis databases, including hosts, open ports and passwords, along with credentials for a "hola" email address that researchers said was most likely used for welcome emails.

Also exposed was the Laravel application key for the website. Because Laravel uses that key to encrypt session cookies, an attacker holding it could decrypt cookie contents and potentially take over user sessions or accounts. A .DS_Store file left behind by a developer's machine revealed the file and folder names in the directory holding the site's project files, and the address of an attached Git code repository was visible.

Researchers said the combination would have let an attacker reach the databases, study the site's structure for further weaknesses, hijack the company's official email channel or send phishing messages that appeared to come from a trusted sender. Cybernews said it contacted Dimas Volvo and data protection officers at Volvo headquarters, after which the problem causing the leak was resolved. No evidence was reported that anyone other than the researchers found the files.

Sources