TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

FBI: Hackers stole Source Code of US Agencies due to SonarQube misconfiguration [pdf]

23 pointsby aschattenover 4 years ago

2 comments

aschattenover 4 years ago
<i>During the initial attack phase, cyber actors scan the internet for SonarQube instances exposed to the open Internet using the default port (9000) and a publicly accessible IP address. Cyber actors then use default administrator credentials (username: admin, password: admin) to attempt to access SonarQube instances.</i><p>Given how often this happens, not having a default password and forcing users to set it should be a standard practice these days. Relying on administrators of the instance doing the right thing obviously keeps failing, thus an option to do the wrong thing should be removed completely.
txutxuover 4 years ago
I did discover a SonarQube instance at $work open to the internet, default credentials too...<p>Developers are good at copy&#x2F;pasting commands.<p><pre><code> docker </code></pre> We&#x27;re not an US Agency, but it seems those things happen eventually.
评论 #25022930 未加载