To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."
Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.
Hackers who broke into Equifax exploited a flaw in open-source server software
11–20 of 84 posts
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#12Earlier quoted context omitted.
I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#13Earlier quoted context omitted.
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
Regardless of this specific situation, we already live in this world. We all just need to get used to it.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#14Earlier quoted context omitted.
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and plugging a raspi onto your network. Nobody notices an inconspicuous black box amid a pile of cables.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#15Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#16Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#17Earlier quoted context omitted.
I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#18Humm, just got an apache struts security update from Redhat, and confluence doesn't have an update for it. Interesting...
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#19Take this with a grain of salt: They claim that the Struts vulnerability in question is specifically CVE-2017-9805, and cite a William Baird & Co. report [1]. However, the report in question says nothing about a specific CVE, only that it was "the Apache Struts flaw". Struts has had multiple vulnerabilities recently, such as one back in February (CVE-2017-5638). It's possible it was one of these that they failed to p…
I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#20To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."
> Correction: An earlier version of this article said the vulnerability exploited by the hackers who broke into Equifax was the one disclosed on Sep. 4. It’s possible that the vulnerability that was targeted was one disclosed in March. We will update this post when we’ve confirmed which vulnerability it was.