Earlier quoted context omitted.
Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)
Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.
Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
131–140 of 216 posts
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#132Earlier quoted context omitted.
What's suspicious about PR Newswire / Business Wire? They're the industry standard wire tools in Public Relations. The Golden Bridge trophies seem to be available to buy if you've won .
I don’t know specifically about Golden Bridge but I have been on the receiving end of other trophy clearinghouses: we were notified we had won a whatever of the year award without even applying for it and that we could purchase the actual trophy for a very reasonable price. Basically these companies’ business is selling overpriced crystal trinkets.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#133Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#134Citrix... mention that to any Hungarian programmer roughly my age and you will likely receive a long string of swearing because the incredibly buggy central system necessary to sign up for courses and exams was only accessible via the Citrix ICA client and back in the second half of the 90s that, in itself, was a huge source of problems beyond the server app not being particularly high quality especially on Linux whi…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#135Earlier quoted context omitted.
Nope. https://haveibeenpwned.com/PwnedWebsites
OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now? Also please note the '?' marks for unverified sources.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#136The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…
Also their fan club looks to be mainly from Thailand (not english speakers from the profile names). Definitely a few red flags.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#137Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…
We need to make companies criminally liable for this information if it gets stolen. If they can’t secure it, don’t collect it.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#138Earlier quoted context omitted.
Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.
this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#139Earlier quoted context omitted.
To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.
This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.
In saying that, if a candidate do have too many public posts showing poor judgment (e.g. hard partying, drunk photos) it will make it definitely make them less in demand.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#140Earlier quoted context omitted.
1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…
https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?