TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hackers went undetected in Citrix’s internal network for six months

328 pointsby marccabout 6 years ago

11 comments

benmarksabout 6 years ago
&gt; Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication.<p>How did Citrix not have 2FA in place?
评论 #19795319 未加载
评论 #19794250 未加载
评论 #19795502 未加载
todd3834about 6 years ago
I fully assume there are more hacks we don’t hear about that ones we do. Not only because of cover ups but it can’t be that hard to cover your tracks if you know what you are doing.
评论 #19794168 未加载
评论 #19796179 未加载
评论 #19794279 未加载
评论 #19794101 未加载
m3nuabout 6 years ago
Security is hard. On the upside, every breach is a chance to learn for everyone else. I hope they release more details on how it happened.<p>Is there any blog or news that summarizes such post-mortem lessons? Could be a nice project to collect that.
评论 #19794131 未加载
评论 #19797013 未加载
robbiet480about 6 years ago
Has anyone gotten that kind of call from the FBI and can shed light on how the process works? Would be fascinating for a outsider and provide a guide on what next steps look like for those poor souls that receive the call in the future.
评论 #19794794 未加载
rmasonabout 6 years ago
If you&#x27;d like a full perspective of the Citrix hack three security people from Detroit discussed it on a recent episode of their show, How they got hacked:<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=fMgdrq0xMLk" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=fMgdrq0xMLk</a>
评论 #19795487 未加载
axaxsabout 6 years ago
Having worked with Citrix, I&#x27;m shocked. Shocked that they detected it at all...
评论 #19794224 未加载
评论 #19794444 未加载
评论 #19794782 未加载
empath75about 6 years ago
If you have anything of value, I absolutely guarantee you that there are hackers in your network right now.<p>One thing that frustrates me more than anything else is people assuming that their corporate network is safe. Your firewall and your vpc or whatever is a speed bump at best. You have to assume that you have an attacker on the desk right next to you, because you will eventually.
评论 #19794341 未加载
评论 #19794134 未加载
评论 #19794411 未加载
ngcc_hkabout 6 years ago
You need network sniffer and pattern recognition. Otherwise basically you hope some of the unusual activities will affect ids&#x2F;ips (or touch internet). However if it is normal account you need some sort of intelligence to recognise and alert.<p>Not many software can do this.
评论 #19795583 未加载
markholmesabout 6 years ago
This might not be the right place for this, but where should one get started with security research?
评论 #19795430 未加载
qaqabout 6 years ago
average is 206 days
评论 #19794157 未加载
inapisabout 6 years ago
&gt;Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication.<p>Wow. This simply reinforces the fact that humans cannot, and should not, be trusted with actively maintaining security of a system especially if there could be significant economic consequences.<p>Would a password manager help in this? I don&#x27;t know.<p>Probably a hardware token which controls all and any access to a system.<p>*Removed some ambiguous sentences.
评论 #19794113 未加载