Current Events > Solarwinds Orion hacked

Topic List
Page List: 1
CableZL
12/16/20 2:51:56 PM
#1:


https://www.theguardian.com/technology/2020/dec/15/orion-hack-solar-winds-explained-us-treasury-commerce-department

Solarwinds Orion is a very popular infrastructure management platform, and was one of my favorite monitoring tools. Apparently their update server's password was "solarwinds123," and it looks like Russian agents accessed it and compromised systems from multiple government entities and private companies.

---
... Copied to Clipboard!
treewojima
12/16/20 3:06:52 PM
#2:


CableZL posted...
Apparently their update server's password was "solarwinds123"

It's amazing how people that should know better still don't understand what makes a decent password.
... Copied to Clipboard!
nothanks1
12/16/20 3:07:52 PM
#3:


treewojima posted...


It's amazing how people that should know better still don't understand what makes a decent password.

We used to have it as
WmtJfex6AZ%Wr#?ExuLLzY+q@XggDx*FBBVF7H?+#zh

But Stacy the new PA to the CEO said she found it hard to copy and paste it from a password vault so we had to make it easier
---
for the alcohlics
https://www.aa.org/
... Copied to Clipboard!
Corrupt_Power
12/16/20 3:10:42 PM
#4:


Damn. And we were considering their RMM solutions too. Probably gonna stamp a big old "nope" on that now.
---
Posted with GameRaven 3.6.0_B3
... Copied to Clipboard!
CableZL
12/16/20 3:14:15 PM
#5:


Corrupt_Power posted...
Damn. And we were considering their RMM solutions too. Probably gonna stamp a big old "nope" on that now.
Yeah, it's really a shame. I thought Orion was the best monitoring platform out there, but it's gonna be hard for them to get any new business now. Fortunately, at my job, we didn't use Orion. All we had was their TFTP/FtP/SFTP/etc. server stuff as far as I know, but we've even dumped those things.

---
... Copied to Clipboard!
Hexenherz
12/16/20 3:20:33 PM
#6:


I mean... Not only was the password stupid easy to guess, someone outright told them it was broken. How do you ignore that?

Also wondering how much of my data has been taken between this and the OPM breach.

---
FFXIV: Lucius Hexenseele (Brynhildr) | RS3: UltimaSuende . 99 WC/Fish/Cook/Fletch/Div/Mining/Smithing/Thieving/Crafting/RC
https://letterboxd.com/BMovieBro/
... Copied to Clipboard!
Topic List
Page List: 1