Live data from Hacker News

Hackers who broke into Equifax exploited a flaw in open-source server software

qz.com

11–20 of 84 posts

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#11
post #2

To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."

Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.

A month before this vulnerability was discovered by these specific security researchers.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#12
post #7
post #6

Earlier quoted context omitted.

I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.

Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable.

In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#13
post #7

Earlier quoted context omitted.

Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

> points away from a world where a hundred million people's private information is unavoidably vulnerable

Regardless of this specific situation, we already live in this world. We all just need to get used to it.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#14
post #7

Earlier quoted context omitted.

Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable.

Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and plugging a raspi onto your network. Nobody notices an inconspicuous black box amid a pile of cables.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#16
post #13

Earlier quoted context omitted.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.

[deleted]

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#17
post #7
post #6

Earlier quoted context omitted.

I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.

Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.

I find their behaviour overall rather abhorrent and against people in general. Justice should be served, but I hope it goes very poorly for them. Sorta like one might hope something bad happens to Oracle.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#18

Humm, just got an apache struts security update from Redhat, and confluence doesn't have an update for it. Interesting...

I believe the more recent vulnerability doesn't apply to the atlassian tools (I'd love to know if I was mislead). My understanding was the latest struts vuln requires you to be using a specific REST plugin.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#19
post #6
post #4

Take this with a grain of salt: They claim that the Struts vulnerability in question is specifically CVE-2017-9805, and cite a William Baird & Co. report [1]. However, the report in question says nothing about a specific CVE, only that it was "the Apache Struts flaw". Struts has had multiple vulnerabilities recently, such as one back in February (CVE-2017-5638). It's possible it was one of these that they failed to p…

I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.

The site is swiss cheese sqli and xss everywhere, even now.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#20
post #2

To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."

There is now a correction at the beginning of the article:

> Correction: An earlier version of this article said the vulnerability exploited by the hackers who broke into Equifax was the one disclosed on Sep. 4. It’s possible that the vulnerability that was targeted was one disclosed in March. We will update this post when we’ve confirmed which vulnerability it was.

Post reply on HN