4 ms·
See this blog post (linked in original article) from a security firm that was one of Okta's customers, and alerted them to the breech, when they detected suspic
by stygiansonic 3y ago
See this blog post (linked in original article) from a security firm that was one of Okta's customers, and alerted them to the breech, when they detected suspicious activity on their network shortly after sharing the HAR file with Okta:
https://www.beyondtrust.com/blog/entry/okta-support-unit-breach https://www.beyondtrust.com/blog/entry/okta-support-unit-bre...
- hrpnk 3y agoThis post has at least some reasonable detail that one can follow to understand the issue. Okta's post requires a lots of context for understanding.
- totetsu 3y agoAmazon service just asked me to share a HAR file and I though for sure it was a security risk. Doesn’t that mean that agent has an authentication cookie to my account? Why can this be common with practice
- pesfandiar 3y agoWas the session still valid?
- tflinton 3y agoYes, don’t share har files
- acdha 3y agoYes, modulo your session durations and, for services which implement it, IP fixation. You should treat HAR files as secrets for anything involving a login.
- rawicki 3y agoWhen I was talking to Amazon support they provided instructions on how to strip tokens together with the ask for a HAR file.
- totetsu 3y agohttps://repost.aws/knowledge-center/support-case-browser-har-file https://repost.aws/knowledge-center/support-case-browser-har... Oh you7re right. I didn't read till the end.
- jbotdev 3y agoThe post glossed over how exactly they detected session hijacking. They mentioned “This detection looks for suspicious sessions appearing without an authentication event that are consistent with session hijacking.”, but authentication obviously happened at some point, otherwise the session wouldn’t exist. I’m guessing this is a complicated way of saying the IP changed since login. Of course the easiest solution is you shouldn’t voluntarily share HAR files for an active session.
- Huppie 3y agoHow they detected it can be found at the bottom of the blogpost: > *Indicators of Compromise* > ... > Okta activity for a user without any clear indication that the user authenticated (e.g. a user.session.start event for that user from a similar geographic area)