DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 18th December 2020
frcc frcc is online now
Don't Worry Be Happy!
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 335
Default Security breach at Solar Winds

I find this article interesting.

https://www.moneytimes.com/articles/...ity-expert.htm

It mentions a security expert (Vinoth Kumar), warned public/state agencies of
a potential login security breach at Solar Winds involving "ftp" ?????
Supposedely this led to a backdoor path to major Gov't/Commercial entities.

Administrator: didn't know if this post belongs in this section or "other"
since I don't know if it is BSD related.

Last edited by frcc; 18th December 2020 at 12:34 PM. Reason: note on forum positioning
Reply With Quote
  #2   (View Single Post)  
Old 18th December 2020
victorvas victorvas is offline
Real Name: Victor
Linux
 
Join Date: May 2019
Posts: 148
Default

They have been warned about weak update server password, and did not change it for a year. It looks suspicious.
https://en.wikipedia.org/wiki/SolarWinds
Russian hackers were involved.
Reply With Quote
  #3   (View Single Post)  
Old 18th December 2020
blackhole's Avatar
blackhole blackhole is offline
Spam Deminer
 
Join Date: Mar 2014
Posts: 320
Default

https://thwack.solarwinds.com/t5/Gee...ls/ba-p/478665

Oh the irony....

Quote:
However, the risk is far less when it comes to proprietary software. Due to the nature of open-source software allowing anyone to update the code, the risk of downloading malicious code is much higher.
Or on the other hand someone could develop proprietary code and be this feckless:
Quote:
Security researcher Vinoth Kumar told Reuters that, last year, he alerted the company that anyone could access SolarWinds’ update server by using the password “solarwinds123”

“This could have been done by any attacker, easily,” Kumar said.
https://www.reuters.com/article/glob...-idUSKBN28Q07P
Reply With Quote
  #4   (View Single Post)  
Old 18th December 2020
frcc frcc is online now
Don't Worry Be Happy!
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 335
Default

If any form of detail/truth from this incident (Ya Right!) reaches our level, I will be surprised! Still, the amount of informationl that is already available "appearing" to be news gives new meaning to the term IT security professional........
Scheeeeeeeez!
Reply With Quote
  #5   (View Single Post)  
Old 23rd December 2020
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,131
Default

The Guardian has an article from Bruce Schneier about this security breach: The US has suffered a massive cyberbreach. It's hard to overstate how bad it is
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote
  #6   (View Single Post)  
Old 24th December 2020
IdOp's Avatar
IdOp IdOp is offline
Too dumb for a smartphone
 
Join Date: May 2008
Location: twisting on the daemon's fork(2)
Posts: 1,027
Default

Thank you for the Schneier article, though the link didn't work for me. This link did.
Reply With Quote
  #7   (View Single Post)  
Old 25th December 2020
frcc frcc is online now
Don't Worry Be Happy!
 
Join Date: Jul 2011
Location: hot,dry,dusty,rainy,windy,straight winds, tornado,puts the fear of God in you-Texas
Posts: 335
Default

https://www.reuters.com/article/us-g...-idUSKBN28Y1BF
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Dutch PKI provider's web site security breach under investigation J65nko News 0 8th December 2011 08:24 PM
Other Another Linux Security Breach (this time at Linux Foundation) vermaden News 0 12th September 2011 07:00 AM
Security breach at kernel.org graudeejs News 4 8th September 2011 06:51 AM
PHP.net breach: Concern over safety of source code J65nko News 2 24th March 2011 09:57 AM
Tor Project infrastructure updates in response to security breach J65nko News 1 22nd January 2010 06:57 PM


All times are GMT. The time now is 10:41 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick