Live data from Hacker News

Sega Europe suffers major security breach

vpnoverview.com

1–10 of 108 posts

Re: Sega Europe suffers major security breach

#2
Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums.

All the keys and services are secure and the breach is closed.

Re: Sega Europe suffers major security breach

#3
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

> dig out more keys

I guess that if they leave them lying around that it is likely there are more.

Re: Sega Europe suffers major security breach

#4
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

This would be awesome as a blog post if you ever want to go into detail on how you executed each step.

Re: Sega Europe suffers major security breach

#5
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

This would be awesome as a blog post if you ever want to go into detail on how you executed each step.

[deleted]

Re: Sega Europe suffers major security breach

#6
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time.

Also, the HackerOne page doesn't appear to be claimed by SEGA Sammy, so notices might dead-end there as well.

Re: Sega Europe suffers major security breach

#7
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

Assertive: Show me something else.

Re: Sega Europe suffers major security breach

#8
post #6
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time. Also, the HackerOne page doesn't appear to be claime…

Yes, if PII is involved it's common to run an audit like this. In addition to the access keys on the server image, Sega also accidentally published a database export containing PII. In order to write a comprehensive disclosure I have to investigate thoroughly.

And yeah, there's no branding or information on HackerOne. Even if this had been in scope, I would have thought twice about submitting anything. Our publishing standards match HackerOne ethical disclosure standards.

Re: Sega Europe suffers major security breach

#10
post #2

Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.

Assertive: Show me something else.

stay tuned
Post reply on HN