3 ms·
Myself, I would agree with your earlier definition of this being a leak[1] simply using the definition. There wasn't a program created or exploit discovered tha
by ZeroSolstice 4y ago
Myself, I would agree with your earlier definition of this being a leak[1] simply using the definition. There wasn't a program created or exploit discovered that exposed previously private information, an authorized user posted to the incorrect privilege level location.
[1] https://www.dictionary.com/browse/leak https://www.dictionary.com/browse/leak
- cowl 4y agoA leak by definition is something from inside. This was not. This was an exploit from outside actors that made this data available to the public. Note the difference: > accidentally posting credentials for Atlassian's Envoy setup in a public repository this was a leak. Using those credentials to then obtain other data and post them publicly-> this is the hack. A hack does not need to be complicated, just to accomplish something that was not intended.
- ZeroSolstice 4y agoI disagree that finding mistakingly posted credentials, logging in and performing an export task is a hack, hacking, or exploitation. All the functionality was already available as it would be for any authorized user. This is the equivalent of reading the user guide.
- shevis 4y agoUsing leaked credentials to access a system that would not otherwise be accessible is absolutely an exploit. Similarly, convincing a security guard to let you in to an area of a building that you aren’t allowed into is also an exploit.
- ZeroSolstice 4y ago> Using leaked credentials to access a system that would not otherwise be accessible is >absolutely an exploit. Can you go into this a bit more as I'm not seeing anything being exploited? Were the credentials not valid? Was exporting data not available to that authentication user? Did they elevate their permissions beyond what the original credentials provided? If I find $20 on the street and buy a lotto ticket and win, what was exploited? I used the money to buy an item that can be purchased with money. In this example would you be saying that finding the money was the exploit or using the discovered money to buy something? > Similarly, convincing a security guard to let you in to an area of a building that you >aren’t allowed into is also an exploit. I agree this is an exploit, aptly named social engineering. However in this example you started with nothing and "convinced" the guard to do something. This is different than already having the credentials. The equivalent for this example, to me, would be finding a persons office/building card and walking past the guard but I wouldn't see that as an exploit. Both the access control and guard are reacting accordingly to the expected inputs. I would view an exploit as going beyond the intent of the built-in/existing controls.
- cowl 4y agoThere is an active searching for these credential leaks in the various repositoriues to then be used so this is an exploit. It shows intent, an organised way of searching for vulenrabilities and accomplishment of the task. It's the equivalent of stalking the security guard and evasdroping on his public communications in the hope that he slips us and when drunken enough will reveal the passcode to the entrance door. Public repositories make it more easy to "stalk" in that sense, but yet it's a active search for a vulnerability, that of not not following security recomandations. If someone intends to rob a bank doens't matter how they have obtained the vault key, when the bank was robbed.