Live data from Hacker News

Sega Europe suffers major security breach

vpnoverview.com

21–30 of 108 posts

Re: Sega Europe suffers major security breach

#21
post #6

Earlier quoted context omitted.

Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time. Also, the HackerOne page doesn't appear to be claime…

> Is it common, now or historically Historically: yes. Now: no. > possibly criminal Sans some sort of formal agreement (which platforms like HackerOne might facilitate), it's definitely criminal. (IMO at least not unethical, to be clear.) Again, sans some sort of contract either one-off or platform based. If SEGA wanted a prosecution, they would almost certainly be able to convince a prosecutor to press charges. The…

I used to do this white hat hacking back in the day: modify a page on the web server, send a link to the admin with the exploit walkthrough.

It's a dangerous game to play now, though. You're basically betting the company you tested your PoC on would rather avoid the negative PR of filing charges against you, vs. a bunch of non-technical suits who just want to see you do 150 years in Sing Sing.

Re: Sega Europe suffers major security breach

#22
post #15

So the breach referenced was a breach by the researchers, not a malicious third party (that we know of)? I would have called it exposure or a vulnerability since breach has a specific meaning that I am not sure this fits. Maybe I am being pedantic.

"Breach" is a legal term, and although IANAL, it seems semantically correct here. When anyone outside of your organization gains access to sensitive information in your systems, regardless of their intent, that is a breach and these guys accomplished that. PCI and all of those other security protocols and programs don't draw the line at white-hat access vs black-hat access.

Re: Sega Europe suffers major security breach

#23

A good example of how the usability of your product directly affects security. AWS has multiple forms of credentials. IAM Users (static keys tied to a specific user identity) are one form. But you can also authenticate via SAML or OIDC. If you use SAML/OIDC, you can enforce temporary IAM credentials, audit who authenticated, expire credentials, enforce password rules & MFA, etc. Because IAM Users are the easiest thin…

When allowing 3rd parties to access your AWS resources, IAM keys are in most cases the only way to achieve this.

For example, most CI/CD systems don't support OIDC yet, so you have to add IAM keys to them. GitHub Actions is a notable exception here.

Re: Sega Europe suffers major security breach

#24
post #19

By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punis…

> By temporarily defacing the Sega website

I may have missed it but what did they deface?

I see a proof of script execution in what appears to be an uploaded file of a random string of letters and numbers .htm address.

So if don’t correctly there is a near zero chance of any public user stumbling into the site.

Re: Sega Europe suffers major security breach

#25
post #6
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time. Also, the HackerOne page doesn't appear to be claime…

Historically, definitely. Currently? Fairly common. However, what's both historically and currently uncommon is having the sense to not do so while also identifying yourself. For the h4x0r cred, or whatever. Which is of course childishly idiotic, but makes my job a whole lot easier. In my experience, if you're not under any such contract and even if you are going to report such a compromise in complete good faith and have done no damage, you are far better off doing so as anonymously as possible. Nobody likes to be embarrassed, and it's a lot simpler for a corporation with a stock price and public image to think about to pin the whole situation on those damn hackers than own up to even the slightest degree of incompetence. Typing at work in sort of a hurry so, please forgive grammatical issues.

Re: Sega Europe suffers major security breach

#26
post #24
post #19

By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punis…

> By temporarily defacing the Sega website I may have missed it but what did they deface? I see a proof of script execution in what appears to be an uploaded file of a random string of letters and numbers .htm address. So if don’t correctly there is a near zero chance of any public user stumbling into the site.

They clearly said they modified careers.sega.co.uk and posted a screenshot of the careers site displaying vpnoverview's logo (https://vpnoverview.com/wp-content/uploads/screenshot-about-...)

Re: Sega Europe suffers major security breach

#27

Earlier quoted context omitted.

Yup, this was totally criminal in most jurisdictions. I don’t care if the person intended to help; this kind of vigilante hacking deserves to land you in prison. You want a bounty? Talk to me before you break into my systems. Because once you do that without my permission, you have proven yourself completely unworthy of being trusted. Why should I believe that you have not installed a rootkit or other tech that you d…

Not sure why my comment got downvoted, but it very much feels like HN is defending this kind of behavior. This is why we can’t have nice things.

You can't have nice things because you aggressively criminalized the white hats, thus were never warned by them before a black hat took your nice things away.

> Why should I believe that you have not installed a rootkit or other tech that you did not subsequently disclose?

Because doing that and also disclosing your identity would be incredibly stupid?

Re: Sega Europe suffers major security breach

#28
post #24

Earlier quoted context omitted.

> By temporarily defacing the Sega website I may have missed it but what did they deface? I see a proof of script execution in what appears to be an uploaded file of a random string of letters and numbers .htm address. So if don’t correctly there is a near zero chance of any public user stumbling into the site.

They clearly said they modified careers.sega.co.uk and posted a screenshot of the careers site displaying vpnoverview's logo ( https://vpnoverview.com/wp-content/uploads/screenshot-about-... )

They say it "briefly" showed that logo. Who knows how long that is.

Re: Sega Europe suffers major security breach

#29
post #19

By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punis…

it seems like there's a couple of hundred consumer-facing VPN service providers, all with slick looking marketing websites to sell you a $5/mo service.

lots of them are nothing more than 1 or 2 people and some rented 1U servers or dedicated servers somewhere on whatever ISP that can find with cheap IP transit / DIA rates. maybe a part time website design/graphic arts person they found via fiverr to make things look cool.

from the perspective of a colocation-specialist ISP or medium sized generalist ISP that offers colo, they get lots of weird requests for colo and dedicated server services from VPN companies they've never heard of before. often with something like a corporate entity that exists in cyprus, panama or even weirder places.

looking at this in terms of the risk that a VPN provider presents to an ISP's reputation, IP space, attracting unusual volumes and numbers of DDoS, etc... there is a certain amount of "KYC" (exact same idea as finance industry KYC) that needs to go into a potential vpn service provider as a colocation client before quoting them a price or accepting them as a customer. fail to do that at your own risk.

it's very much in the weird/shady/grey market end of the ISP market.

the level of technical acumen and professionalism varies greatly between VPN providers.

Re: Sega Europe suffers major security breach

#30
post #14

Earlier quoted context omitted.

Yup, this was totally criminal in most jurisdictions. I don’t care if the person intended to help; this kind of vigilante hacking deserves to land you in prison. You want a bounty? Talk to me before you break into my systems. Because once you do that without my permission, you have proven yourself completely unworthy of being trusted. Why should I believe that you have not installed a rootkit or other tech that you d…

How do you know there’s a breach without seeing it?

How would Sega know there are AWS API keys in a public S3 bucket without vpnoverview defacing their careers site? Sega could probably, y'know, look in the S3 bucket at the identified file which contained the keys.

All of the things found could have been investigated by Sega and replicated if vpnoverview just documented how they got access to the info.

You don't have to joyride in a car to show the owner that they dropped their keys.

Post reply on HN