The European Tribune is a forum for thoughtful dialogue of European and international issues. You are invited to post comments and your own articles.
Please REGISTER to post.
Microsoft president calls SolarWinds hack an "act of recklessness"
SolarWinds is the maker of a nearly ubiquitous network management tool called Orion. A surprisingly large percentage of the world's enterprise networks run it. Hackers backed by a nation-state--two US senators who received private briefings say it was Russia--managed to take over SolarWinds' software build system and push a security update infused with a backdoor. SolarWinds said about 18,000 users downloaded the malicious update.
"A software build system" is the code and procedures to turn the code into a functioning program.
How they managed to penetrate and subvert the build system is, AFAIK, unknown. She believed in nothing; only her skepticism kept her from being an atheist. -- Jean-Paul Sartre
We're not saying this is how SolarWinds was backdoored, but its FTP password 'leaked on GitHub in plaintext'
Vinoth Kumar, a security researcher, claimed on Tuesday he had made such a report to SolarWinds last November, warning that it could be used to upload files to the server. The password he said he found, in plaintext for all to see, is a textbook example of a weak password that never should have been allowed. In a message to The Register, Kumar said that on November 19, 2019, he told SolarWinds "their update server was accessible with the password 'solarwinds123' which is leaking in the public Github repo. They fixed the issue and replied to me on [November 22]."
In a message to The Register, Kumar said that on November 19, 2019, he told SolarWinds "their update server was accessible with the password 'solarwinds123' which is leaking in the public Github repo. They fixed the issue and replied to me on [November 22]."
Was reading about a sophisticated attack on FireEye leveraging Solarwinds. Hmmm how that would happened?🤔. Then realized their password was ***123 🤣 #FireEye #SolarWinds pic.twitter.com/foGzEOdytG— Vinoth Kumar (@vinodsparrow) December 14, 2020
Was reading about a sophisticated attack on FireEye leveraging Solarwinds. Hmmm how that would happened?🤔. Then realized their password was ***123 🤣 #FireEye #SolarWinds pic.twitter.com/foGzEOdytG
by Frank Schnittger - Feb 23 7 comments
by Oui - Feb 22 8 comments
by Frank Schnittger - Feb 20 2 comments
by gmoke - Feb 14 2 comments
by Frank Schnittger - Feb 19 13 comments
by Frank Schnittger - Feb 15 23 comments
by Frank Schnittger - Feb 14 13 comments
by Oui - Feb 17 33 comments
by Frank Schnittger - Feb 237 comments
by Oui - Feb 228 comments
by Frank Schnittger - Feb 202 comments
by Oui - Feb 2018 comments
by Frank Schnittger - Feb 1913 comments
by Oui - Feb 195 comments
by Oui - Feb 18
by Oui - Feb 1733 comments
by Oui - Feb 168 comments
by Frank Schnittger - Feb 1523 comments
by gmoke - Feb 142 comments
by Frank Schnittger - Feb 1413 comments
by Oui - Feb 144 comments
by Oui - Feb 1238 comments
by Oui - Feb 774 comments
by Oui - Feb 665 comments
by Frank Schnittger - Feb 518 comments
by Frank Schnittger - Feb 412 comments
by Oui - Feb 136 comments
by Frank Schnittger - Jan 3035 comments