3 ms·
The AFF back to back breaches were interesting because there were faults to found at every level. * The breach included PII from a property they had already so
by tal8d 7y ago
The AFF back to back breaches were interesting because there were faults to found at every level.
* The breach included PII from a property they had already sold, but held onto for some reason.
* SHA1. A good choice if you want to slightly inconvenience somebody with a GPU, while also increasing the odds of your hashes getting uploaded in full to one of many distributed cracking projects.
* No effective user input validation. The exploit was one step in sophistication beyond those ancient IIS ../../hue.txt attacks.
* No attempt at anything resembling principles of least privilege, exec whatever wherever.
So, everyone failed - executives to DBAs. Screw pentests, start by implementing best practices that have been around for 40 years.