back to article That sound you hear is Splunk leaking data

Splunk has patched a slip in its JavaScript implementation that leaks user information. The advisory at Full Disclosure explains that the leak happens if an attacker tricks an authenticated user into visiting a malicious Web page. It only leaks the username, and whether or not that user has enabled remote access; but this …

  1. John Smith 19 Gold badge
    Windows

    remind me again what systems come with remote access enabled as standard..

    Oh let me guess....

    1. Anonymous Coward
      Anonymous Coward

      Re: remind me again what systems come with remote access enabled as standard..

      Um, Linux distros?

  2. monty75

    Splunk? Isn't that the game we used to play as kids with marbles and straws in a plastic tube?

    1. VinceH

      No, that was Kerplunk.

      Splunk, according to the urban dictionary, is "A mixture of spunk and splooge. This is formed by the combined semen during a bukkake session."

      1. Anonymous Coward
        Anonymous Coward

        Urban Dictionary FTW

        Having noted the dire quality of most of the definitions therein (scatological, improbable, misspelled: pick any three) I thought I might spend a wet weekend writing a crawler to add bogus versions of "dirty sanchez" to every existing word.

        But on closer inspection it seemed this had already been done, more than once. So I went back to adding cocks through Google Map's user contributions :-)

      2. Anonymous Coward
        Anonymous Coward

        For those of you without a dictionary

        it's probably intended to make the association with spelunking (cave exploration). Yes, it's a daft name, but the tool is very useful for allowing you to cross-reference activity. For example, if you have a VPN login, you can look at which systems were accessed from that IP address. In addition it provides an extra audit trail with the log entries being forwarded to a limited access system. I've recently introduced it where I work, but I still need to get a couple of custom log files integrated.

  3. tiggity Silver badge

    Splunk

    I looked at the website and it seemed designed to be played with (the data mining set) buzzword bingo cards

    1. Robert Carnegie Silver badge

      Re: Splunk

      Yeah, seriously, what is it?

      "We make machine data accessible, usable and valuable to everyone"

      Accessible to everyone - doesn't sound good. "chmod 777" does that.

      1. gr00001000

        Re: Splunk

        Send all your syslogs to one place and correlate for SIEM.

        Send all your user transactions to one place and compute correlations in the big cloud.

        Seems their Schtick, they're quite successful don't you know.

    2. Adam 1

      Re: Splunk

      It's actually not bad if you ignore the marketing. Simple configuration on your servers to monitor your log4Xyz logs, Windows event logs, etc from disparate machines out there and you can do big data-esq mining on it all, find out which software/OS versions are being impacted by some specific exception (in pretty close to real time).

      If I'm reading the JavaScript right, the attacker needs to know the hostname of the splunk server. In public facing servers that might be an issue, but it looks like it needs to be a targeted attack or mitm to be practical.

  4. Joe 59

    remote access is for mainframes and minis

    Name a web service that doesn't allow remote access. One that's powered off?

    That said, can't tell if you're being deliberately obtuse or simply don't know what it is. Splunk is a log aggregation tool. Think the red-haired bastard step-child of syslog-ng, grep, sed, awk and rrdtool.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like