3 ms·
You're completely right, this wasn't a complicated attack at all. The two most notable items here are, Solarwinds has horrible security practices and those cust
by technick 6y ago
You're completely right, this wasn't a complicated attack at all. The two most notable items here are, Solarwinds has horrible security practices and those customers who were affected by the attack, also have horrible security practices. In a correctly secured environment it wouldn't have been possible for a infected Solarwinds server to connect out to a C2C server.
- ed_elliott_asc 6y ago100% this no ports should be allowed in or out by default and every port open justified - if you can’t get out a payload is useless.
- jannes 6y agoWhat about port 80 and 443?
- sofixa 6y agoWhy would monitoring servers have access to the internet?
- PeterisP 6y agoYes, a secure server should not be able to make outgoing connections to arbitrary external machines on 80/443. If there's a specific need for a specific connection (e.g. the server needs to pull updates from the vendor) then that particular connection can be whitelisted.