"According to Capital One, its logs show a number of connections or attempted connections to Capital One’s server from TOR exit nodes" Now there's a fail.
Capital One Says Breach Hit 100M Individuals in U.S
61–70 of 319 posts
Re: Capital One Says Breach Hit 100M Individuals in U.S
#62Dear "Seattle Woman": while you're in there, please dump Capital One's junk mail database, and set their address label printer on fire. Sincerely, another Seattle resident with a mailbox.
[0] https://www.consumer.ftc.gov/articles/0148-prescreened-credi...
Re: Capital One Says Breach Hit 100M Individuals in U.S
#63Re: Capital One Says Breach Hit 100M Individuals in U.S
#64I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...
I'm curious about what the first command could have been
Also this all unfurled after a report to their security line from someone monitoring gists - that public feed as well as text dump sites have always been a good source of new vulnerabilities
Re: Capital One Says Breach Hit 100M Individuals in U.S
#65He worded it carefully. He's not apologizing for the actual and potential harm of the breach so as to not take responsibility for it. Not a real, sincere, apology, but just a legally defensive move.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#66Re: Capital One Says Breach Hit 100M Individuals in U.S
#67I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...
It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?
Re: Capital One Says Breach Hit 100M Individuals in U.S
#68Generally it's not a good idea to sabotage your employer's clients, but I wonder how many engineers across the Big 3 US cloud providers have the know-how to exploit holes in how Forture 500 companies use their platforms.
At a minimum, AWS Support has near complete read access to AWS accounts in connection with support cases.
It would be interesting to hear from an AWS employee how access to customer information is controlled.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#69Earlier quoted context omitted.
Who cares if it has your data in it or not. Just report it to authorities and the guy who runs haveibeenpwned. Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.
I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#70> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
Per the complaint, it doesn't sound like the bucket was exposed to the world. Rather, security credentials were "obtained": > Capital One determined that the first command, when executed, obtained security credentials for an account named XXXX-WAF-Role, that in turn, enabled access to certain of Capital One's folders at the Cloud Computing Company. Unsure how one would obtain credentials for an IAM Role, but the abov…
They used those creds to launch like 1700 gpu machines across the globe for a bitcoin mining network...
The culprit was from germany...
We got it cleared and AWS forgave all the charges.