Earlier quoted context omitted.
How did we come to this imbalance?
State secrecy being used as an excuse for violence. A truly free people keep no secrets.
Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
141–150 of 216 posts
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#142Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#143We use ShareFile as a client portal for secure document delivery.
Shady.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#144Earlier quoted context omitted.
Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.
this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#145It says they had to find out from the FBI. At least theoretically, how does the FBI find out? (unless someone knows the actuality and is willing to share? Didn't see anything in the article)
I use ShareFile for secure document delivery and they forced a password reset with stricter requirements in January, the month after the first breach, and two months before the FBI notification.
No notice of breached documents to its customers yet.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#146Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…
We aren't getting the whole story from Citrix.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#147Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#148Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…
Same tactic as what's used on Twitter accounts. And same as I said previously: If the bad actors can brute force weak passwords, the company itself should be able to do it too and force those with weak passwords to update them.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#149Earlier quoted context omitted.
I suspect some places still only use passwords for server logins because they can simply use active directory for user management and then have servers use ad/ldap for credential checking. I think businesses with critical infrastructure should use hardware keys (e.g. yubikeys) to provide at least one of the factors needed to log in to a server. Using a yubikey as an authentication key for ssh is not that difficult an…
> This requires the enterprise to run up to date browser however. Why is this so hard?!? I agree with you, but this sentence rang so true it was sad. I've been forced to work with/around unbelievably out-of-date browsers in order to install current firmware updates on systems at almost every place I've worked. /rant
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#150>> Earlier today, Citrix chief information security officer Stan Black gave his company's side of the story. He said that, as of right now, Citrix does not know exactly which documents the hackers obtained nor how they got in... Ouch. The winner of "The worst position to be in today".
No notice from Citrix ShareFile to its customers about a breach yet, though. Thanks.