Live data from Hacker News

Hackers who broke into Equifax exploited a flaw in open-source server software

qz.com

41–50 of 84 posts

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#42
post #2

To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."

Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.

No, the vulnerability was reported to the Struts project on July 17.

https://lgtm.com/blog/apache_struts_CVE-2017-9805

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#44
post #41

Wrong emphasis. It must be read "flaw in open source Java software. The problem is Java, not Open Source.

I'd leave it out of the title altogether as irrelevant. The fact that Struts is distributed with a particular license is no more important in this case than the fact that the foundation that distributes it is incorporated in Delaware.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#45

Earlier quoted context omitted.

Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.

No, the vulnerability was reported to the Struts project on July 17. https://lgtm.com/blog/apache_struts_CVE-2017-9805

I meant a month before it was reported.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#46
Regarding CVE-2017-9805, I’m genuinely in awe over how remote code execution in Java is even possible. Why should it even be possible to deserialize data on the wire into executable code?

Also, can someone shed light on the technical side of this? E.g., how does the JVM compile Java code it receives on the wire into Java byte code? Does the JVM runtime have a built-in Java compiler that outputs Java byte code that it itself can execute?

https://lgtm.com/blog/apache_struts_CVE-2017-9805

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#47
post #2

To give nuance to the clickbait: "The vulnerability in Struts was just recently discovered by security researchers, who announced it earlier this week on Sept. 4. According to the researchers, the bug has existed since 2008."

Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.

So little to no chance then that those executives who sold stock the other day didn't know about it then.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#50
post #48

> a popular plugin called REST Why cant tech 'journalists' get someone who knows what they're talking about to proofread their articles?

Remember this the next time you read anything in the news about an industry you don't understand.
Post reply on HN