4 ms·
You don't get this kind of attack because you had an exposed FTP server. The attack implanted malicious code into their code, learning the tooling, process and
by CyberRage 5y ago
You don't get this kind of attack because you had an exposed FTP server.
The attack implanted malicious code into their code, learning the tooling, process and responsibilities of the personal.
They then reversed engineered the protocol and used it in their backdoor to look basically the same as regular communications.
The issue is that we blindly trust 3rd party software that is used by hundreds of companies. this makes SolarWinds a prime target, one that is worth the efforts taken in this case.
- boomboomsubban 5y ago>You don't get this kind of attack because you had an exposed FTP server This kind of attack needs an entry point, and an exposed FTP server provides the potential for one. Whether it actually was the entry point is a separate matter, willfully ignoring one unlocked door means there's likely to be others.
- CyberRage 5y agoInitial access is part of the day-to-day these days. you can't cover all entry points, it's a matter of time for someone to make a mistake. the fact that the adversary showed these extreme levels of proficiency and dedication tells me that the vast majority of companies would have fallen for that. In fact, the backdoor was running for months on targets like Microsoft, gov agencies, security companies like Malwarebytes. These companies know a thing or two about security. Today we work with "assume breach" mentality that assumes you are already compromised.
- freeflight 5y ago> You don't get this kind of attack because you had an exposed FTP server. Leaking the extremely weak login credentials to your updateserver, trough a public Github repo, is not exactly a glowing endorsement of how serious security seems to have been taken at Solwarwinds. With stuff like that being a thing, who knows where else they cut corners/got lazy. > this makes SolarWinds a prime target, one that is worth the efforts taken in this case. A prime target, yet apparently could still not be bothered to put in some minimum effort to protect themselves.
- galaxyLogic 5y ago> could still not be bothered to put in some minimum effort to protect themselves. What would have been the minimum effort that would have protected them?
- freeflight 5y agoThe minimum effort starts at selecting more secure passwords than "company123".
- dogman144 5y agoYeah I mean I’ve read the technical FEYE writeups, and yeah once they had a foothold it got fairly f’ing complex (hope those guys don’t end up in my CI/CD ever, yikes). That said, foothold for this stuff more often than note comes from keys on public GitHub repos (or things like that: simple misses that are enough to throw the door open). I hear things like “intern” and “totally unrelated” and it’s the dog whistles of policy/policy enforcement failures of these sorts of initial ways in. So many sexy hacks start from admin123 passwords unfortunately