4 ms·
Pure conjecture. But let’s say solar winds is using a known popular build server, and this build server was only ever going to be accessed by internal resources
by Trisell 6y ago
Pure conjecture. But let’s say solar winds is using a known popular build server, and this build server was only ever going to be accessed by internal resources and employees.
Then let’s say this build server had an unusually high usage of build plugins. And the upgrading of that product was difficult and sometimes troublesome because of these custom plugins and their interdependencies. And so they at some point they missed an upgrade or two on accident, or because upgrading is hard.
Now they are running an build server with several know vulnerabilities. But because that build server isn’t public. It’s really no big deal that it’s a bit out of date. Until it is.
- __turbobrew__ 6y agoLet me guess, was there a certain butler involved?
- still_grokking 6y agoThat sounds very interesting and frightening at the same time. Could it be that there are more companies out there in a kind of similar situation? It would be quite bad of course if such information would become widely know I could imagine.
- jcims 6y agoAnd said build server application has 150 CVEs, and if people get lazy will provide shells to unauthenticated web users: https://www.cvedetails.com/vulnerability-list/vendor_id-15865/product_id-34004/Jenkins-Jenkins.html https://www.cvedetails.com/vulnerability-list/vendor_id-1586...
- jsty 6y agoAh, it was the butler - in the server room - with the ethernet cable. (Come to think of it, security Cluedo would be quite fun ...)