4 ms·
a play, in two parts: https://imgur.com/a/krXIz https://imgur.com/a/krXIz additionally, the twitter account claiming responsibility (@real_1x0123, on friday,
by packetized 9y ago
a play, in two parts:
https://imgur.com/a/krXIz https://imgur.com/a/krXIz
additionally, the twitter account claiming responsibility (@real_1x0123, on friday, sep 08) for the webshell/compromise just protected their tweets. this will turn out to be much more interesting than it has been thus far.
- Kluny 9y agoSome of those are down already. Here's their salesforce login though: https://help.equifax.com/login https://help.equifax.com/login Here's the login for their finance blog: https://blog.equifax.com/wp-login.php https://blog.equifax.com/wp-login.php admin/password and admin/admin doesn't work on that one. It lets you keep trying passwords for a pretty long time, maybe possible to brute force. I haven't been able to get through any of the others with admin/admin as well. Maybe someone is on the job. I can't help thinking of how on-the-ball companies like yahoo, github and dreamhost are about security breaches for much lower-stakes information. This whole story is so pathetic. Makes me think the company is being run by people like my dad, who is barely capable of using a computer for Youtube and the news, and is constantly fearful and paranoid of "cyber" threats, but won't take the most basic steps to educate himself or take precautions.
- packetized 9y agoSure was up last Thursday. Cached results are being scrubbed from Google. The point I'm attempting to illustrate here is that someone appears to have had a PHP web shell on a force.com endpoint.
- Kluny 9y agoYeah, I was just poking through the others to see if I could score any more easy wins :)