5 ms·
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds pos
by Merman_Mike 6y ago
Am I understanding the last one correctly?
1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted
2. The checksum doesn't match because malware has been inserted into the package during build/delivery
3. SolarWinds tells customers to ignore this and install it manually
Did no one think to check why the checksum didn't match?
- jessaustin 6y agoOne suspects they've given this advice for a long time... because their shit has been hacked for a long time.
- gitweb 6y agoI don't understand why anyone would pay for SW in the first place. It has been garbage software for a long time. If government clients are paying for this and installing in on their servers, we have bigger worries.
- deleted 6y ago[deleted]
- RobRivera 6y agoSolarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.
- dabockster 6y agoAnd you posted this US military vulnerability on a publicly searchable internet site? head desk
- rootsudo 6y agoTO be fair, it isn't really secret, if you look at any job posting for lackland, you'll see it mentioned over and over.. https://careers-salientcrgt.icims.com/jobs/11200/network-systems-engineer-2/job+&cd=4&hl=en&ct=clnk&gl=us https://careers-salientcrgt.icims.com/jobs/11200/network-sys...' https://i.imgur.com/d8KbSZp.png https://i.imgur.com/d8KbSZp.png But, wow, imagine that's a job, just walk in, look at two programs and swap out parts as needed.
- RobRivera 6y agoFacebook query Find people who work for US Air Force. Vulnerabilities publicly available are numerous, and I gave no such details to anyone that would give them an easier time finding said compromises. Its like saying windows 10 bug found --> HEY THE MILITARY USES WINDOWS 10.
- willis936 6y agoMy employer has a knowledgebase on the public internet that is littered with lists of softwares and practices. There are thousands of employees. Name dropping software should be a risky thing to do, but that isn’t the world we live in.
- quickthrowman 6y agoGood OPSEC, soldier! You must be a former marine...
- RobRivera 6y agoGive the OPSEC snide comment to the job postings publicly advertised. Don't hate on marines, they do hard work. Using a throwaway account to be trite seems par for the course tho for opinions that can be disregarded.
- eli 6y ago#2 is speculation. Seems possible that there's an unrelated bug causing checksum errors. In any event, it's not a good look right now.
- wyldfire 6y agoRegardless of the motivation, cause, mechanism of #2 - #3 is not the appropriate way to handle the problem. Attack is indistinguishable from unintentional corruption. And #3 trains customers to do the wrong thing when they encounter an attack.
- eli 6y agoThe malicious file was signed with the right certificate. So yeah you should ideally be more careful with checksums but there already was a much more robust and secure authentication mechanism and it was defeated.
- heleninboodler 6y agoYes, these are two orthogonal egregious security problems.
- rayvd 6y agoThis seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.
- deleted 6y ago[deleted]
- tstrimple 6y agoIs the proper response to tell a customer to install the package anyway because it's just a partial download or something similar? Regardless, it seems irresponsible.
- deleted 6y ago[deleted]