Earlier quoted context omitted.
They should not be letting egress traffic through to a Tor node.
Commenting on you because I can't comment below: Tor node IPs are published, so you can just block that list.
Capital One Says Breach Hit 100M Individuals in U.S
81–90 of 319 posts
Re: Capital One Says Breach Hit 100M Individuals in U.S
#82After reading through some of the complaint, it seems quite fitting.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#83Re: Capital One Says Breach Hit 100M Individuals in U.S
#84Earlier quoted context omitted.
Well, the main cloud Capital One uses is Amazon as far as I know. If you think about the attack vectors here, it was most definitely the virtual server that got attacked. If it was the cloud provider (Amazon), there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this…
"there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this sort of scenario shouldn't ever happen." ROTFLMAO....you have clearly never worked for a bank, no offense mate. Capital left this shit in plain text on an S3 bucket, I guarantee you
Re: Capital One Says Breach Hit 100M Individuals in U.S
#85Re: Capital One Says Breach Hit 100M Individuals in U.S
#86I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...
It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?
Re: Capital One Says Breach Hit 100M Individuals in U.S
#87How is this person's information wiped off the Internet? I literally cannot find anything related to her. Is it just me?
Re: Capital One Says Breach Hit 100M Individuals in U.S
#88Earlier quoted context omitted.
They should not be letting egress traffic through to a Tor node.
What sort of rule or policy would you put into play to detect that a connection was a TOR node?
Re: Capital One Says Breach Hit 100M Individuals in U.S
#89> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png
Re: Capital One Says Breach Hit 100M Individuals in U.S
#90I was there when C1 negotiated that deal with Amazon and they swore it couldn't happen but of course, we all know that's false.
Yeah AWS can’t protect you against a misconfigured environment