Exposed Python Script with Hardcoded SFTP Credentials, Internal IPs, and Sensitive Data Access

Disclosed by
unknown_soldier
Summary by unknown_soldier

I found a Python script that is publicly available on the internet. The script contains hardcoded login details (username and password), IP addresses of internal devices, and access to sensitive data. This could allow hackers to get unauthorized access to the system, download important data, or interfere with research files.

Activity