4 ms·
Intel denies it was hacked: https://twitter.com/TheRegister/status/1291461942624677889 https://twitter.com/TheRegister/status/1291461942624677889
by pdevr 6y ago
Intel denies it was hacked: https://twitter.com/TheRegister/status/1291461942624677889 https://twitter.com/TheRegister/status/1291461942624677889
- dleslie 6y ago... They're claiming it came from an NDA'd source of IP that's shared with customers. Given that it _appears_ like there are backdoors in this Firmware code, we can conclude that if there are such backdoors then they were shared with numerous customers. That really doesn't improve the optics of the breach.
- jpxw 6y agoImagine what they aren’t sharing
- moonchild 6y agoAlternately, as others have noted, it could be overloaded nomenclature and doesn't actually indicate a backdoor. Which would be an excellent reason for them to feel comfortable sharing said 'backdoors' with their customers.
- dathinab 6y agoIt it is actually a backdoor but only gets put on prototypes/engineering samples or similar. Or maybe some well documented Intel management features need to backdoor there own security mechanisms to work. Or ... Well the point is it's a starting point for someone dissecting the data but not much more.
- technonerd 6y agohttps://del.dog/sourcestatements.txt https://del.dog/sourcestatements.txt source: They have a server hosted online by Akami CDN that wasn't properly secure. After an internet wide nmap scan I found my target port open and went through a list of 370 possible servers based on details that nmap provided with an NSE script. source: I used a python script I made to probe different aspects of the server including username defaults and unsecure file/folder access. source: The folders were just lying open if you could guess the name of one. Then when you were in the folder you could go back to root and just click into the other folders that you didn't know the name of. deletescape: holy shit that's incredibly funny source: Best of all, due to another misconfiguration, I could masqurade as any of their employees or make my own user. deletescape: LOL source: Another funny thing is that on the zip files you may find password protected. Most of them use the password Intel123 or a lowercase intel123 source: Security at it's finest.
- deleted 6y ago[deleted]
- johnnyfaehell 6y agoIt wasn't hacked... But these files came into the hands of an unauthorised user... That seems a lot think something of theirs got hacked...
- jug 6y agoA guy on reddit claiming to be ex-Intel thinks it looks like material shared with OEM’s and thus a breach of something like a motherboard manufacturer rather than Intel.
- japgolly 6y agoYeah but the data is still a legit leak, even though the means by which is was obtained wasn't hacking.