• hacker_ Profile Picture

    Corben Leo @hacker_

    3 years ago

    Uber was hacked. The hacker social engineered an employee -> logged into the VPN and scanned their intranet. 👇

    86 2K 7K 0 814
  • hacker_ Profile Picture

    Corben Leo @hacker_

    3 years ago

    Apparently there was an internal network share that contained powershell scripts... "One of the powershell scripts contained the username and password for a admin user in Thycotic (PAM) Using this i was able to extract secrets for all services, DA, DUO, Onelogin, AWS, GSuite"

    hacker_ tweet picture

    25 290 2K 0 121
    Download Image
  • totdgbtagb Profile Picture

    totty.eth 🍌 @totdgbtagb

    3 years ago

    @hacker_ imagine grinding for years to be a top tier level engineer and falling to some probably bozo-tier social engineering scam

    1 3 87 0 0
  • BugBountyHQ Profile Picture

    BugBountyHQ @BugBountyHQ

    3 years ago

    @hacker_ Yep, my inbox just blew up

    0 0 25 0 0
  • carnal0wnage Profile Picture

    Chris Gates @carnal0wnage

    3 years ago

    @hacker_ they mad they got one starred

    2 0 12 0 0
  • VillaRoot Profile Picture

    VillaRoot @VillaRoot

    3 years ago

    @hacker_ Ah, the ol' admin credentials inside scripts on a network share mistake. It's been around since the dawn of time.

    1 4 131 0 2
  • TimC_266 Profile Picture

    Tim C @TimC_266

    3 years ago

    @hacker_ @ErrataRob That sounds bad. Fortunately I never use the Internet. Only apps.

    2 0 25 0 0
  • rotembar Profile Picture

    Rotem Bar @rotembar

    3 years ago

    @hacker_ Yep.. Seen this kind of attack in live, A little imagination and some good crafted messaging will let you in into everywhere.. We need a plan to move all companies to fido2.. today!!

    1 0 20 0 0
  • 0Porosh Profile Picture

    0xPorosh 🇧🇩❤️🇵🇸 @0Porosh

    3 years ago

    @hacker_ Sqli

    0Porosh tweet picture

    1 0 18 0 2
    Download Image
  • HaboubiAnis Profile Picture

    Anis Haboubi |₿| @HaboubiAnis

    3 years ago

    @hacker_ It is an employee or it is the account of Christopher Duarte Leading Enterprise Apps @ Uber .. Personally I think we are on the continuation of the supplychain attack on codecov and okta :-)

    HaboubiAnis tweet picture
    HaboubiAnis tweet picture
    keyboard_arrow_left Previous keyboard_arrow_right Next

    0 3 11 0 2
    Download Image
  • KHIZER_JAVED47 Profile Picture

    Khizer Javed @KHIZER_JAVED47

    3 years ago

    @hacker_ Looks more like an Inside job from these messages…

    2 0 13 0 0
  • AlesandroOrtizR Profile Picture

    Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtizR

    3 years ago

    @hacker_

    kateconger Profile Picture

    kate conger @kateconger

    3 years ago

    @hacker_

    23 269 605 0 29

    0 1 9 0 0
  • wismbuhcuk Profile Picture

    c0de @wismbuhcuk

    3 years ago

    @hacker_ What should network admin do to avoid this happen?

    3 1 8 0 1
  • elaef_j Profile Picture

    elaef @elaef_j

    3 years ago

    @hacker_ Curious bout the steps of the social engineering part 🧐

    1 1 6 0 0
  • tradodog Profile Picture

    tradodog @tradodog

    3 years ago

    @hacker_ how did he overcome 2FA?

    4 0 8 0 1
  • CyberAlmogavar Profile Picture

    almogaver_digital @CyberAlmogavar

    3 years ago

    @hacker_ More often than not the most critical points of failure in security infrastructures are precisely the humans that use it.

    1 0 6 0 0
  • kubatyszko Profile Picture

    Kuba Tyszko @kubatyszko

    3 years ago

    @hacker_ @etorreborre Ironically, for years I've been warning people to be careful taking Uber and/or Lyft rides, especially shared rides. It's surprisingly easy for a stranger to fish out valuable pieces of information from a casual conversation (such as dog's name, your first school etc).

    0 1 4 0 0
  • andre_lugt Profile Picture

    Andre7455 @andre_lugt

    3 years ago

    @hacker_ does anyone know what the goals was of this hack? it looks like publicity right now

    1 0 5 0 0
  • KatarzynaRossi Profile Picture

    Brzozova @KatarzynaRossi

    3 years ago

    @hacker_ Why Powershell scripts instead of some kind of Terraform, Ansible, or another tool with secrets stored in Vault or something similar? And this happened to Uber which was widely exposed to bug bounties programs...

    1 0 5 0 1
  • MikeHuntSmel Profile Picture

    StpHnt @MikeHuntSmel

    3 years ago

    @hacker_ These dumbasses always burn their access straight away with some highschool level troll pranks instead of playing the long game.

    1 0 5 0 0
  • 1belisarius Profile Picture

    Fl0kii @1belisarius

    3 years ago

    @hacker_ @JackRhysider

    1 0 5 0 0
  • LedgerOps Profile Picture

    LedgerOps @LedgerOps

    3 years ago

    @hacker_ Wow…Uber actually has a solid security team

    3 0 4 0 0
  • sshbounty Profile Picture

    rahmetu @sshbounty

    3 years ago

    @hacker_ If they exfiltrate data, it will be a catastrophic breach. Just think about how huge and how much data Uber will have.

    1 0 4 0 0
  • c0d3x27 Profile Picture

    c0d3x27 @c0d3x27

    3 years ago

    @hacker_ Things like this just show how stupid many people with talent are... he could easily get a big bounty for this and make a name for himself. Instead he prefers to act like a clown for attention. For what? Now he will get arrested, no bounty and ruin his life.

    2 0 3 0 0
  • AlenSalamun Profile Picture

    Alen Salamun @AlenSalamun

    3 years ago

    @hacker_ The weakest link...and the chain fails....

    0 0 2 0 0
  • goodciso Profile Picture

    Good CISO @goodciso

    3 years ago

    @hacker_ Failure at multiple basic things, chained. A classic. 1. No or improper 2FA for VPN 2. Lack of security awareness of whichever dev wrote that script (as usual) 3. No code scanning for hardcoded creds 4. SMB share with such scripts with the org? Wow.

    0 0 2 0 0
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer