this post was submitted on 30 Jan 2025
1 points (100.0% liked)

Technology

1020 readers
9 users here now

A tech news sub for communists

founded 2 years ago
MODERATORS
 

[...] a publicly accessible ClickHouse database linked to DeepSeek, completely open and unauthenticated, exposing sensitive data. It was hosted at oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000.

This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details.

More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.

It seems that the Empire has decided to strike.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here