TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

FBI: Hackers stole Source Code of US Agencies due to SonarQube misconfiguration [pdf]

23 点作者 aschatten超过 4 年前

2 条评论

aschatten超过 4 年前
<i>During the initial attack phase, cyber actors scan the internet for SonarQube instances exposed to the open Internet using the default port (9000) and a publicly accessible IP address. Cyber actors then use default administrator credentials (username: admin, password: admin) to attempt to access SonarQube instances.</i><p>Given how often this happens, not having a default password and forcing users to set it should be a standard practice these days. Relying on administrators of the instance doing the right thing obviously keeps failing, thus an option to do the wrong thing should be removed completely.
txutxu超过 4 年前
I did discover a SonarQube instance at $work open to the internet, default credentials too...<p>Developers are good at copy&#x2F;pasting commands.<p><pre><code> docker </code></pre> We&#x27;re not an US Agency, but it seems those things happen eventually.
评论 #25022930 未加载