Live data from Hacker News

Viewing profile — daviddede

daviddede

HN member
Joined
Wed, Jan 23, 2013, 4:55 PM UTC
HN karma
172
Public activity
44 items

About daviddede

dd@sucuri.net

Recent public activity

  1. comment
    Comment #8543439

    We have a few samples of the SQL injection attempts here: http://blog.sucuri.net/2014/10/drupal-sql-injection-attempts... In there you can see the type of backdoors being added (ge…

  2. comment
    Comment #8543436

    And that was at the same time that everyone was worried about POODLE and the media was going crazy over it. Somehow this vulnerability went over the radar. What is interesting is t…

  3. comment
    Comment #8530624

    Virtual patching is the main benefit on WAFs for cases like this. We were able to issue a virtual patching signature for our clients in less than 2 hrs after the disclosure. Plus, …

  4. comment
    Comment #8529763

    That's exactly the issue. Most enterprises didn't even have time to be notified and properly test/push a patch live before the attacks were already in the wild.

  5. comment
    Comment #8529753

    You have a good point, but I was looking at these two points: 1- Extent of the damage 2- Number of points vulnerable Heartbleed had (has) a lot more servers vulnerable, but the imp…

  6. comment
    Comment #8529428

    It depends on the complexity of the attack. This Drupal one took our team less than an hour to have a working proof of concept (just based on the diffs). The exploit is very simple…

  7. comment
    Comment #8528949

    That's as big as it can be. We started seeing attacks hours after the initial disclosure and shared some of them here: http://blog.sucuri.net/2014/10/drupal-sql-injection-attempts.…

  8. story
  9. story
  10. comment
    Comment #8369387

    That's very similar to what we are seeing as well: http://blog.sucuri.net/2014/09/bash-shellshocker-attacks-inc... Also, if anyone need a WAF to protect it in the mean while, we of…

  11. comment
    Comment #8368014

    That's just the start. Once people start hitting cpanel servers: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...

  12. comment
    Comment #8368008

    It absolutely is. Specially now with thousands of cPanel servers known to be vulnerable: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...

  13. comment
    Comment #8368005

    cPanel servers vulnerable as well: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...

  14. story
  15. comment
    Comment #8362933

    Do you have a screenshot by chance?

  16. story
  17. comment
    Comment #8120491

    We have quite a few openings (all remote): -Senior PHP developer: http://sucuri.net/company/senior-php-developer-ops-022514 -Frontend designer/developer: http://sucuri.net/company/…

  18. comment
    Comment #8050219

    Not new: http://dcid.me/texts/attacking-log-analysis-tools.html It had a similar vuln many years ago.

  19. comment
    Comment #8021079

    Yep, same here. I hate when products (companies) I use get acquired. It always come with not-welcoming product changes. Hope it doesn't happen to them.

  20. story
  21. story
  22. story
  23. comment
    Comment #7802536

    Top of my list: Linode, Digital Ocean, Sucuri, CloudProxy, Balsamiq and Amazon Ec2.

  24. comment
    Comment #7324475

    Sucuri, Inc - Remote Our company is fully remote and we have people working from all sort of places: USA, Canada, Brazil, Spain, Romania, etc. Right now we have 3 positions open: -…

  25. story