4 ms·
Does anyone know the technical details of how this happened? Did someone just run a spider on the e3expo.com site and find the publicly accessible URL that way,
by slang800 7y ago
Does anyone know the technical details of how this happened? Did someone just run a spider on the e3expo.com site and find the publicly accessible URL that way, or did they do something more advanced?
- hello_asdf 7y agoThere was a direct link to the excel file on the "Helpful Links" page of the E3 Expo site.
- pbhjpbhj 7y agoThe OP says: >"Unfortunately, a vulnerability was exploited and that list became public." // If it was just a link to a file on the website them claiming a vulnerability was exploited is like saying "my security system was overcome" if I dropped my wallet on the bus.
- eswat 7y agoBased on the ESA statement it’s probably a case of hanlon's razor where they have nobody on-staff to do a proper incident response. They also said they “shut down the site”, which really meant they removed/hidden the page in WordPress but they didn’t remove the culprit file nor did they take down the E3 website.