Technology
Hackers access files of US-based cyber security firm
San Francisco, July 28
Using an email address and password mistakenly exposed on the Internet, a hacker gained access to the internal files of US-based cyber security company Comodo, bringing the credibility of the company under question.
The credentials were found in a public GitHub repository owned by a Comodo software developer, TechCrunch reported on Saturday.
The account was not protected with two-factor authentication and with the email address and password in hand, the hacker could enter the company's Microsoft-hosted Cloud services.
The leaked credentials were discovered by a Netherlands-based security researcher Jelle Ursem who reached out to Comodo Vice-President Rajaswi Das.
According to Ursem, the account allowed him to access internal Comodo files, including sales documents and spreadsheets in the company's OneDrive and the company's organisation graph on SharePoint, allowing him to see the team's biographies, contact information, like phone numbers and email addresses, photos, customer documents and calendar.
Screenshots of folders containing agreements and contracts with several customers -- with names of customers in each filename, such as hospitals and US state governments.
"Seeing as they're a security company and give out Secure Sockets Layer (SSL) certificates, you'd think the security of their own environment would come above all else," the report quoted the Userm as saying.
Earlier this year Ursem found a similarly exposed set of internal Asus passwords on an employee's GitHub public account.
The credentials were found in a public GitHub repository owned by a Comodo software developer, TechCrunch reported on Saturday.
The account was not protected with two-factor authentication and with the email address and password in hand, the hacker could enter the company's Microsoft-hosted Cloud services.
The leaked credentials were discovered by a Netherlands-based security researcher Jelle Ursem who reached out to Comodo Vice-President Rajaswi Das.
According to Ursem, the account allowed him to access internal Comodo files, including sales documents and spreadsheets in the company's OneDrive and the company's organisation graph on SharePoint, allowing him to see the team's biographies, contact information, like phone numbers and email addresses, photos, customer documents and calendar.
Screenshots of folders containing agreements and contracts with several customers -- with names of customers in each filename, such as hospitals and US state governments.
"Seeing as they're a security company and give out Secure Sockets Layer (SSL) certificates, you'd think the security of their own environment would come above all else," the report quoted the Userm as saying.
Earlier this year Ursem found a similarly exposed set of internal Asus passwords on an employee's GitHub public account.
2 hours ago
From security cooperation to bilateral payment linkages: India, Malaysia sign six key pacts
2 hours ago
PM Modi's efforts in peacekeeping are unequivocal: Malaysian PM Anwar Ibrahim
2 hours ago
Our stance on terrorism firm, no double standards, no compromise: PM Modi in Malaysia
2 hours ago
True friend, full of trust and understanding: Malaysian PM Ibrahim on PM Modi
2 hours ago
North Korea to convene key party congress in late February
2 hours ago
Netanyahu to meet Trump in Washington, discuss Iran talks
3 hours ago
Heavy security blanket for Amit Shah’s Puducherry visit on Feb 14; BJP steps up poll preparations
3 hours ago
Group II and II-A main exams postponed in TN after widespread irregularities claims at test centres
3 hours ago
Fire breaks out in moving train in Rajasthan's Jaisalmer; no casualties reported
3 hours ago
Quack's clinic raided in Telangana, drugs seized
3 hours ago
Female foetus found in Rajasthan's Alwar
3 hours ago
CM Himanta Sarma asks Centre to probe ‘Pakistan links’ of Cong MP Gaurav Gogoi
3 hours ago
'Gaurav Gogoi was digitally silent for 10 days in Pakistan': Assam CM raises questions
