We got hacked
21–25 of 25 posts
Re: We got hacked
#22Asked my team to review their Jenkins passwords and Jenkins user rights...
Re: We got hacked
#23Second, why even list A, B, or C? Whoever thought running Jenkins as a passwordless sudo user shouldn't be doing sysops. Why was Jenkins even public facing? At worst, put it behind a VPN.
Re: We got hacked
#24Was the original attack via jenkins? all it says some vague privilege escalation was used to upload c file. what?
No the author seems to indicate that it was on their application code and an attacker was able to get OS access, and the attacker subsequently replaced the ssh service with one that instead ignores login attempts and harvests the username/password pairs. It seems to have been a coincidence that their Jenkins service was not secured.
Re: We got hacked
#25no customer data was exposed during the attack How did you confirm that?