Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
Hackers who broke into Equifax exploited a flaw in open-source server software
21–30 of 84 posts
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#22Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database"
other than new credit card #'s it'd be basically pointless right?
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#23Earlier quoted context omitted.
Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.
A month before this vulnerability was discovered by these specific security researchers .
Given the magnitude of this hack, it is entirely possible they embargoed it for a while.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#24Earlier quoted context omitted.
> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
So if someone takes this data and just keeps the whole dataset exposed publicly on a tor site, is that pretty much the end of data breaches? Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database" other than new credit card #'s it'd be basically pointless right?
Everybody on that list will change their CC and life carries on until the next breach.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#25This is based on a report from Baird Equity Research. Some key items from that report: * "Our understanding is data retained by EFX primarily generated through consumer interactions was breached via the Apache Struts flaw (i.e., core databases not believed to have been breached)." * "Key EFX databases are not known to have been breached as part of the incident, including the consumer credit file, TWN, NCTUE, IXI, or…
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#26Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#27Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…
Sure, if you don't have physical security, you have no security. Goes without saying.
If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but beyond that you never actually talk to anyone so nobody is suspicious. People generally don't care when someone is walking around the halls dressed up in a suit.
One of my coworkers was involved in dozens of red teams and he got caught a grand total of one time. Every other time he was able to acquire an IP address, take a picture of himself sitting in the exec's chair, swipe a file out of the server room, or whatever the customer wanted.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#28Earlier quoted context omitted.
I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#29Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#30Humm, just got an apache struts security update from Redhat, and confluence doesn't have an update for it. Interesting...