Technology
Hackers access files of US-based cyber security firm
San Francisco, July 28
Using an email address and password mistakenly exposed on the Internet, a hacker gained access to the internal files of US-based cyber security company Comodo, bringing the credibility of the company under question.
The credentials were found in a public GitHub repository owned by a Comodo software developer, TechCrunch reported on Saturday.
The account was not protected with two-factor authentication and with the email address and password in hand, the hacker could enter the company's Microsoft-hosted Cloud services.
The leaked credentials were discovered by a Netherlands-based security researcher Jelle Ursem who reached out to Comodo Vice-President Rajaswi Das.
According to Ursem, the account allowed him to access internal Comodo files, including sales documents and spreadsheets in the company's OneDrive and the company's organisation graph on SharePoint, allowing him to see the team's biographies, contact information, like phone numbers and email addresses, photos, customer documents and calendar.
Screenshots of folders containing agreements and contracts with several customers -- with names of customers in each filename, such as hospitals and US state governments.
"Seeing as they're a security company and give out Secure Sockets Layer (SSL) certificates, you'd think the security of their own environment would come above all else," the report quoted the Userm as saying.
Earlier this year Ursem found a similarly exposed set of internal Asus passwords on an employee's GitHub public account.
The credentials were found in a public GitHub repository owned by a Comodo software developer, TechCrunch reported on Saturday.
The account was not protected with two-factor authentication and with the email address and password in hand, the hacker could enter the company's Microsoft-hosted Cloud services.
The leaked credentials were discovered by a Netherlands-based security researcher Jelle Ursem who reached out to Comodo Vice-President Rajaswi Das.
According to Ursem, the account allowed him to access internal Comodo files, including sales documents and spreadsheets in the company's OneDrive and the company's organisation graph on SharePoint, allowing him to see the team's biographies, contact information, like phone numbers and email addresses, photos, customer documents and calendar.
Screenshots of folders containing agreements and contracts with several customers -- with names of customers in each filename, such as hospitals and US state governments.
"Seeing as they're a security company and give out Secure Sockets Layer (SSL) certificates, you'd think the security of their own environment would come above all else," the report quoted the Userm as saying.
Earlier this year Ursem found a similarly exposed set of internal Asus passwords on an employee's GitHub public account.

8 hours ago
On UK trip, US President Trump highlights his ‘very good relationship’ with PM Modi

8 hours ago
Indian envoy to US meets senior Pentagon official, holds 'valuable discussion'

9 hours ago
Newark Airport ranks last once again; even the new Terminal A couldn’t save it.

11 hours ago
Trade deal with US to bolster India’s regional role: Report

13 hours ago
Trump administration unveils 'patriotic education' initiative as new priority for federal education grants

15 hours ago
Tucson City Council in Arizona to open with ancient Hindu prayers

15 hours ago
Did Deepika Padukone exit 'Kalki 2898 AD' due to commitment issues?

15 hours ago
Tannishtha Chatterjee wishes ‘incredible woman’ Shabana Azmi on 75th b’day

15 hours ago
Ananya Panday flaunts bronzed glow post her Maldivian holiday

15 hours ago
Divya Dutta to Shabana Azmi: You are supremely precious in my life

15 hours ago
Kerala a bridge between India and Europe: CM Vijayan on blue economy conclave

15 hours ago
Bengal student murder: Protest erupts at Birbhum school, headmaster thrashed

15 hours ago
India-US tariff stalemate likely to be resolved in 8-10 weeks: Chief Economic Advisor