• toadjones79@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 minutes ago

    Lots of Penetration Testing stories on YouTube. Not exactly cyber security but it was still solved with basic cyber security updates (and a few physical ones) I remember one where they just physically waited for six hours in an elevator they turned off with a key they bought on eBay for $5 after putting up an “out of order” sign on the door. Then, when everyone had gone home for the night, they came out and went to the server room and hacked their way through the entire system. They were pros paid by that company to find security holes, and they earned their pay that day.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 hour ago

    EternalBlue has to be up there. Triggering 3 bugs in SMB to allow an arbitrary code execution on an unmatched system.

    I hope the NSA person responsible for chaining those got a good bonus, but like any government employee I doubt they did.