paint-brush
Uber & Thycotic:密码库是一个巨大的安全漏洞吗?经过@jamesbores
41,515 讀數
41,515 讀數

Uber & Thycotic:密码库是一个巨大的安全漏洞吗?

经过 James Bore4m2022/10/03
Read on Terminal Reader
Read this story w/o Javascript

太長; 讀書

安全性很复杂,管理凭证很困难。一名 17 岁的黑客 TeaPot 获得了 Uber 承包商的凭据,并开始反复向他们发送多因素身份验证请求。一旦承包商生气并点击接受,他们的帐户就被用来访问带有管理员凭据的脚本,进入优步的密码库 Thycotic,从而使他们可以访问几乎所有其他内容。

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - Uber & Thycotic:密码库是一个巨大的安全漏洞吗?
James Bore HackerNoon profile picture
James Bore

James Bore

@jamesbores

Security professional, homebrewer, amateur butcher, techie, board gamer, and beekeeper.

关于 @jamesbores
LEARN MORE ABOUT @JAMESBORES'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

James Bore HackerNoon profile picture
James Bore@jamesbores
Security professional, homebrewer, amateur butcher, techie, board gamer, and beekeeper.

標籤

Languages

这篇文章刊登在...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite