Sega Europe suffers major security breach
vpnoverview.com
Sega Europe suffers major security breach
1–10 of 108 posts
Re: Sega Europe suffers major security breach
#2All the keys and services are secure and the breach is closed.
Re: Sega Europe suffers major security breach
#3Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
I guess that if they leave them lying around that it is likely there are more.
Re: Sega Europe suffers major security breach
#4Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
Re: Sega Europe suffers major security breach
#5Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
This would be awesome as a blog post if you ever want to go into detail on how you executed each step.
Re: Sega Europe suffers major security breach
#6Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
Also, the HackerOne page doesn't appear to be claimed by SEGA Sammy, so notices might dead-end there as well.
Re: Sega Europe suffers major security breach
#7Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
Re: Sega Europe suffers major security breach
#8Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time. Also, the HackerOne page doesn't appear to be claime…
And yeah, there's no branding or information on HackerOne. Even if this had been in scope, I would have thought twice about submitting anything. Our publishing standards match HackerOne ethical disclosure standards.
Re: Sega Europe suffers major security breach
#9Re: Sega Europe suffers major security breach
#10Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums. All the keys and services are secure and the breach is closed.
Assertive: Show me something else.