Earlier quoted context omitted.
I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).
TLDR; in some jobs, you can't have social media accounts. I have some contact with cybersec in Europe and it is very common that cybersec professionals in gov and mil positions do not have any social media accounts under their own name, and certainly not linkedin. Social media makes you too much of a target and reveals too much about your org. When promoted to a public-facing position the person then suddenly "appear…
Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
121–130 of 216 posts
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#122Earlier quoted context omitted.
Wtf is this "zoominfo" site that, upon clicking "Read More", tries to drive-by download an exe onto my computer? What is this, 2002?
Wow, I read the EULA-thing for that executable. > I Agree to the Terms of Service and Privacy Policy I understand that I will receive a subscription to Zoominfo Community Edition at no charge in exchange for downloading and installing the ZoomInfo which, among other features involves sharing my business contacts as well as headers and signature blocks from emails that I receive. It's effectively malware though at lea…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#123The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…
Good catch, that is called a 3 letter agency front.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#124Earlier quoted context omitted.
1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…
What's suspicious about PR Newswire / Business Wire? They're the industry standard wire tools in Public Relations. The Golden Bridge trophies seem to be available to buy if you've won .
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#125Earlier quoted context omitted.
https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?
Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#126Earlier quoted context omitted.
https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?
Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#127I am not very well informed. How serious is this?
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#128Earlier quoted context omitted.
Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)
Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#129Earlier quoted context omitted.
TLDR; in some jobs, you can't have social media accounts. I have some contact with cybersec in Europe and it is very common that cybersec professionals in gov and mil positions do not have any social media accounts under their own name, and certainly not linkedin. Social media makes you too much of a target and reveals too much about your org. When promoted to a public-facing position the person then suddenly "appear…
Does the entire org appear out of nowhere? No. MI5, CIA, Stasi, etc have been quite public about their existence.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#130Earlier quoted context omitted.
[flagged]
Assad is using chemical weapons against his own people. It was determined by OPCW. You can read full reports of the two well publicized attacks here: https://www.opcw.org/fileadmin/OPCW/Fact_Finding_Mission/s-1... https://www.opcw.org/sites/default/files/documents/2019/03/s... But there were many more. So please don't spread unsubstantiated falsehoods and doubt.