Earlier quoted context omitted.
Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.
Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
111–120 of 209 posts
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#112We‘re doing something way less critical at my job. But we have two pentests per year by external companies. How on earth is this level of incompetence even legal.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#113https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#114> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…
[flagged]
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#115Earlier quoted context omitted.
Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.
From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#116Earlier quoted context omitted.
Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.
And SBF of FTX fame was ex-Jane St so obviously was a serious finance professional. This is why using past employers as a shorthand for capability is unwise.
[1] https://www.bloomberg.com/news/articles/2024-05-15/ftx-bankr...
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#117Earlier quoted context omitted.
Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.
From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#118Earlier quoted context omitted.
One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.
That sounds more like a stupid person than smart lol
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#119However bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...
Anedote: in Wall Street, Global Relay and TeleMessage are the major players when it comes to achieving communication for compliance.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#120Earlier quoted context omitted.
This just reads like a terrible LinkedIn-speak to me.
Sufficiently advanced human written linkedin-speak is indistinguishable from a barely coherent chatgpt 3.5 that's been instructed to speak in business buzzwords.