3 ms·
This also came out today: https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ https://mattermost.com/blog/coordinated-disclosure-go-xml-
by trashcan 6y ago
This also came out today:
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ https://mattermost.com/blog/coordinated-disclosure-go-xml-vu...
It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.
- richardwhiuk 6y agoDoubt it - that bug has been known by Go/Mattermost since August.
- trashcan 6y agoHow would SolarWinds know about it if it wasn't publicly disclosed until today? Also, I realize the SAML -> SolarWinds connection is a bit of speculation on my part, but SAML is mentioned in Microsoft's advisory: https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ https://msrc-blog.microsoft.com/2020/12/13/customer-guidance... It sounds like a privilege escalation using the Go/SAML issue.
- trashcan 6y agoAlso, this hack happened in March, so your timeline is irrelevant.