Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

171–180 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#171
post #56
post #24

Earlier quoted context omitted.

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

Interesting, I have little idea how the field really works. I guess there must still be some kind of internet presence, maybe not through a typical social network ?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#172

Earlier quoted context omitted.

Nope. https://haveibeenpwned.com/PwnedWebsites

OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now? Also please note the '?' marks for unverified sources.

There is a difference between not liking the OC's idea of an extension, and saying that HIBP does not have the data required to make such an extension.

First you said the latter, now you're saying the former.

Own up to your mistakes.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#173
post #65

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

FYI, PRNewswire is one of the oldest, respected, and expensive newswire services around. Businesswire is also very well established. Not sure how those seem “suspicious”.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#174
post #152

Earlier quoted context omitted.

This argument is not much different than what the grandparent is referring to. weev was convicted of conspiracy to access a computer without authorization because he advised a guy who discovered a publicly available HTTP API hosted by AT&T that returned email addresses based on guessable ids. The conviction was overturned, but on procedural grounds, not legal ones.

Directory listing wasn't on on the AT&T server.

He accessed “public” URLs that he inferred the existence of but wasn’t supposed to access. So I guess if you can start at the homepage of this site and find a link to a directory, you’re OK.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#175

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

The text on the site alone is a red flag. It might as well be Latin gibberish. And the "awards" aren't linked to anything. Some of them are just silly, like this one: https://resecurity.com/wp-content/uploads/2019/02/award-4.pn...

which was apparently uploaded last month...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#176
post #90
post #75

Earlier quoted context omitted.

[flagged]

Assad is using chemical weapons against his own people. It was determined by OPCW. You can read full reports of the two well publicized attacks here: https://www.opcw.org/fileadmin/OPCW/Fact_Finding_Mission/s-1... https://www.opcw.org/sites/default/files/documents/2019/03/s... But there were many more. So please don't spread unsubstantiated falsehoods and doubt.

What you're saying is impossible; until June, the OPCW didn't have the mandate to assign blame[1], and while they now do, the Duoma expedition still did not[2].

[1] https://www.bbc.com/news/world-europe-44634434

[2] https://www.bbc.com/news/world-middle-east-47424266

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#177
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

This url is now showing a 404.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#178
post #47

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

There is almost no information about this company. I did a passive recon and this is what I've got: https://recon.secapps.com/f/EMh9

That's a really cool service. Thanks for sharing.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#179

I would be interested in knowing how cyber warfare and cyber espionage are viewed from a perspective of diplomacy or power play between nations (or corporations). Does anyone know of interesting articles?

It has been a while since I read it but the first thing that came to mind is this talk by Dan Geer (who is closely connected to US intelligence agencies):

http://geer.tinho.net/geer.blackhat.6viii14.txt

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#180
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

FYI, PRNewswire is one of the oldest, respected, and expensive newswire services around. Businesswire is also very well established. Not sure how those seem “suspicious”.

Not sure if that was meant to be sarcastic. They have a pretty clear history of accepting garbage for money. https://www.seroundtable.com/google-panda-pr-newswire-change...
Post reply on HN