Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue: default API keys #1217

Open
soxoj opened this issue Jan 4, 2024 · 0 comments
Open

Security issue: default API keys #1217

soxoj opened this issue Jan 4, 2024 · 0 comments

Comments

@soxoj
Copy link

soxoj commented Jan 4, 2024

Describe the bug

CompreFace has default demo services and default hardcoded API keys

So, it's possible to use some private instances of CompreFace if demo services were not removed just using default API keys.

To Reproduce

You can find CompreFace instances in such services like Netlas, Censys, Shodan and so on, just filtering pages with keyword Compeface. Netlas is giving 123 known instances: https://app.netlas.io/responses/?q=http.body%3ACompreface&page=1&indices=

Expected behavior

Demo services have randomly generated API keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant