3 ms·
But if they have a vulnerability that SolarWinds has not yet disclosed, they could very well be distributing compromised software.
by colonelpopcorn 6y ago
But if they have a vulnerability that SolarWinds has not yet disclosed, they could very well be distributing compromised software.
- sudhirj 6y agoYes, but that’s a big if. It’s also simply possible that Solarwinds has their TeamCity admin account password set to ‘password’ and accessible on a public network.
- vorpalhex 6y agoRight, and we don't know, which means we should audit aggressively and assume these things may still be open attack vectors. You don't hang out with the backdoor open waiting for your friend to let you know.
- marcosdumay 6y agoI guess that's why they said that they are auditing aggressively their CI tool.
- sudhirj 6y agoWe should, but we should have assumed CI software was an attack vector since before the solar winds hack. It’s always been a vector. This hack doesn’t change anything.
- zinekeller 6y ago... actually, SolarWinds used "solarwinds123" on their FTP site. Which is stored on a publicly-accessible GitHub repository. (Source: https://www.theregister.com/2020/12/16/solarwinds_github_password/ https://www.theregister.com/2020/12/16/solarwinds_github_pas...)
- foolmeonce 6y agoEverything has a vulnerability that Solarwinds hasn't disclosed. What is the logic in focusing on this extremely unique choice? A plan by a government wants to spearfish developers at every enterprise software company to find 1+ ways in to their clients and should have chosen something universal. Without any apparent data, it seems more likely the suspicion is just speculation because it is less common than email clients, legacy browsers, dev-servers, common libraries, etc. I.e. because no one else found this intruder the crap software that everyone uses must be safe?