They could be fake, of course, but this thread[1] of screenshots is pretty bad... internal tools, Slack Admin, Google Workspace admin, an AWS account showing admin permissions. [1] https://twitter.com/Savitar0x01/status/1570580235716014081
Uber investigating breach of its computer systems
11–20 of 327 posts
Re: Uber investigating breach of its computer systems
#12Unconfirmed method of breach: https://twitter.com/hacker_/status/1570582547415068672 - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa) - Once on VPN, scan their intranet and find a network share - Network share has powershell scripts with admin credentials for their PAM vendor, Thycotic - From there can get full access to all systems
Thycotic and Centrify have been rolled up into Delinea fwiw. https://delinea.com/
Re: Uber investigating breach of its computer systems
#13I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…
I would be shocked if they didn’t issue all employees YubiKeys.
And even if they do, they likely have a “backup” for people who never seem to be able to use the Yubikey right.
Re: Uber investigating breach of its computer systems
#14They could be fake, of course, but this thread[1] of screenshots is pretty bad... internal tools, Slack Admin, Google Workspace admin, an AWS account showing admin permissions. [1] https://twitter.com/Savitar0x01/status/1570580235716014081
Re: Uber investigating breach of its computer systems
#15I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…
I would be shocked if they didn’t issue all employees YubiKeys.
Re: Uber investigating breach of its computer systems
#16Pour one out for our fellow sys admins & security teams that are going to be working late into the night. They took down their Slack so I wonder what out-of-band comma they’re using. EDIT: Comms not comma. I'll leave the typo because I LOVE bombcar's comment about the semicolon. Confused at first, but I smiled
Re: Uber investigating breach of its computer systems
#17Pour one out for our fellow sys admins & security teams that are going to be working late into the night. They took down their Slack so I wonder what out-of-band comma they’re using. EDIT: Comms not comma. I'll leave the typo because I LOVE bombcar's comment about the semicolon. Confused at first, but I smiled
Probably a semicolon! (I’d assume going to text messaging to set something up, which is why you should know enough about your immediate coworkers to verify their identity via non-public information.)
Re: Uber investigating breach of its computer systems
#18Earlier quoted context omitted.
I would be shocked if they didn’t issue all employees YubiKeys.
Quoted post unavailable.
Re: Uber investigating breach of its computer systems
#19I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…
I would be shocked if they didn’t issue all employees YubiKeys.