ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Apache Struts - Critical Security Flaw

    Scheduled Pinned Locked Moved News
    apachestrutsvulnerabilityhttpdequifaxbreachmillions
    21 Posts 9 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @coliver
      last edited by

      @coliver said in Apache Struts - Critical Security Flaw:

      @dustinb3403 So where does it go from incompetence to malevolent incompetence?

      It's already at the point of being intentional. Everyone in the chain of command from the CEO to the head of the IT department to the System Administrator who didn't patch the system should be brought up on charges and burned at the stake.

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @coliver
        last edited by

        @coliver said in Apache Struts - Critical Security Flaw:

        @dustinb3403 said in Apache Struts - Critical Security Flaw:

        Oh wonderful. . .

        Strut flaw was the root cause of the Equifax breach.

        The fact that they didn't patch it makes it more concerning. It's not necessarily the architecture at that point. If they had updated their infrastructure and implemented a patch this would have been a non-issue.

        Is that true? The exploit has been there in Struts for a while but only recently announced. The breach was a while ago. I'm not sure that Struts had been patched at that point.

        coliverC 1 Reply Last reply Reply Quote 2
        • scottalanmillerS
          scottalanmiller @coliver
          last edited by

          @coliver said in Apache Struts - Critical Security Flaw:

          @dustinb3403 So where does it go from incompetence to malevolent incompetence?

          When you accept the job knowing you are incompetent.

          1 Reply Last reply Reply Quote 0
          • coliverC
            coliver @scottalanmiller
            last edited by

            @scottalanmiller said in Apache Struts - Critical Security Flaw:

            @coliver said in Apache Struts - Critical Security Flaw:

            @dustinb3403 said in Apache Struts - Critical Security Flaw:

            Oh wonderful. . .

            Strut flaw was the root cause of the Equifax breach.

            The fact that they didn't patch it makes it more concerning. It's not necessarily the architecture at that point. If they had updated their infrastructure and implemented a patch this would have been a non-issue.

            Is that true? The exploit has been there in Struts for a while but only recently announced. The breach was a while ago. I'm not sure that Struts had been patched at that point.

            It was patched two months prior to when the web application was exploited.

            DustinB3403D 1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @coliver
              last edited by

              @coliver said in Apache Struts - Critical Security Flaw:

              @scottalanmiller said in Apache Struts - Critical Security Flaw:

              @coliver said in Apache Struts - Critical Security Flaw:

              @dustinb3403 said in Apache Struts - Critical Security Flaw:

              Oh wonderful. . .

              Strut flaw was the root cause of the Equifax breach.

              The fact that they didn't patch it makes it more concerning. It's not necessarily the architecture at that point. If they had updated their infrastructure and implemented a patch this would have been a non-issue.

              Is that true? The exploit has been there in Struts for a while but only recently announced. The breach was a while ago. I'm not sure that Struts had been patched at that point.

              It was patched two months prior to when the web application was exploited.

              No Equifax failed to patch until 2 months after they were breached.

              1 Reply Last reply Reply Quote 0
              • momurdaM
                momurda
                last edited by

                Equifax was breached in May. Patch for Struts was in March. They announced the breach last week.

                scottalanmillerS 1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller @momurda
                  last edited by

                  @momurda said in Apache Struts - Critical Security Flaw:

                  Equifax was breached in May. Patch for Struts was in March. They announced the breach last week.

                  Oh, well zero excuses then.

                  1 Reply Last reply Reply Quote 0
                  • matteo nunziatiM
                    matteo nunziati
                    last edited by

                    here is the Apache explanation

                    1 Reply Last reply Reply Quote 1
                    • JaredBuschJ
                      JaredBusch
                      last edited by

                      Was the Eqifax breech because of the march strus flaw or a more recent one?

                      Just making sure the actual facts are known.

                      coliverC 1 Reply Last reply Reply Quote 1
                      • coliverC
                        coliver @JaredBusch
                        last edited by

                        @jaredbusch said in Apache Struts - Critical Security Flaw:

                        Was the Eqifax breech because of the march strus flaw or a more recent one?

                        Just making sure the actual facts are known.

                        The one from March.

                        1 Reply Last reply Reply Quote 0
                        • 1
                        • 2
                        • 2 / 2
                        • First post
                          Last post