What DentiGrid Found — And What It Means
On the night of February 14, DentiGrid's dark web and public index scanning engine flagged a critical exposure.
A server configuration file belonging to Bangladesh Water Development Board (BWDB) — one of the most critical public infrastructure organisations in Bangladesh — was publicly accessible. Open. Indexed. Readable by anyone on the internet who knew where to look.
Inside that file: live SIP (Session Initiation Protocol) account credentials and internal server connection details, stored in plain text.
No encryption. No access control. No warning.
Who Is Bangladesh Water Development Board?
BWDB manages water resource infrastructure across Bangladesh — flood control systems, irrigation networks, and water supply operations that millions of Bangladeshis depend on directly. It is not a small agency. It is national critical infrastructure.
A breach of this organisation's communication systems would not just affect a government department. It would affect every community that relies on the systems BWDB manages.
What the Exposure Made Possible
DentiGrid's scan identified three categories of immediate, exploitable risk:
1. Communication System Hijack
The exposed SIP credentials would allow any attacker to take full control of BWDB's internal telephonic communication system — and to make calls appearing to originate from official government numbers. Call spoofing from a government authority is one of the most effective social engineering vectors in existence.
2. Severe Financial Damage
International fraud groups routinely exploit exposed SIP credentials to generate millions of dollars in international call charges — billed directly to the organisation whose credentials they stole. In this case, that bill would ultimately be paid by Bangladeshi taxpayers.
3. National Security Risk
The exposed file contained internal server maps and connectivity details for critical government infrastructure. In the wrong hands, this information provides the blueprint for a deeper, more targeted attack against systems that serve the entire country.
What DentiSystems Did
We did not exploit the exposure. We did not log in to any system. We did not touch a single file.
This is a non-negotiable part of how we operate. DentiGrid is a tool for finding and disclosing vulnerabilities — never for exploiting them.
February 14 — Same day as detection:
We compiled a full disclosure report in PDF format — including the exact location of the exposed file, the specific credentials at risk, a technical explanation of the vulnerabilities, and a clear remediation guide. We submitted this report to BGD e-GOV CIRT, Bangladesh's national cyber incident response team, the same day.
Following days — Direct contact:
When we received no response from CIRT indicating action had been taken, we contacted BWDB directly — reaching their system administrator and explaining the risk clearly, by both email and phone.
February 20 — Status at time of writing:
The loophole remained open. The credentials remained exposed. We continued to monitor and followed up through all available responsible disclosure channels. But shortly after, we partnered with BGD e-GOV CIRT to get everything sorted out.
Why This Matters Beyond BWDB
This case study is not just about one government agency with an open configuration file.
It is about a category of risk that almost no mid-market or public-sector organisation in Bangladesh is currently watching for: credentials, internal documents, and server details that have leaked onto public indexes, dark web forums, and open repositories — and are sitting there, waiting for an attacker to find them.
Most organisations assume that if they did not publish something, it is not public. That assumption is wrong. Misconfigured servers, accidental commits, exposed APIs, and third-party leaks put sensitive internal data into public view every day — without anyone inside the organisation ever knowing.
DentiGrid monitors for exactly this. It does not wait for an attacker to enter your network. It watches the places attackers look before they decide to target you.
In this case, we found the exposure first. Next time, it might be someone with different intentions.
What We Are Offering
DentiSystems is currently selecting two corporate partners in Bangladesh to deploy DentiGrid at a highly discounted flat fee — in exchange for a documented case study.
What you receive:
→ Full DentiGrid deployment monitoring your internal network and external exposure surface
→ Real-time alerts for credential leaks, exposed files, and dark web mentions of your organisation
→ A complete threat visibility report at the end of the deployment period
→ The same capability that found BWDB's exposure — watching for yours
What we receive:
→ Permission to document and publish the findings as an anonymised case study
If you want to know what is out there about your organisation before an attacker finds it — contact us.

