RE: Security Breach 01-01-2015, 06:45 PM
#31
(01-01-2015, 06:04 PM)Oni Wrote: His statement is too broad. He's insinuating that all of the recent security breaches are due to a CSRF and lack of discretion when it comes to login details. That, of course, isn't the case for us. The vulnerability that allowed the attacker to spawn a shell, was in the admin panel (but wasn't a CSRF). Credentials weren't gained through me or clicking of an unsafe link, either.
It might have been broad - but your response was just as broad and suggests that there is no low-risk CSRF vulnerability as he stated.
Also, we are just supposed to take your word that you didn't do a dumbass thing like click on a malicious link? Past experience shows you aren't exactly the brightest bulb in the pack.
(01-01-2015, 06:04 PM)Oni Wrote: But hey, you have no experience at all - so I wouldn't take much from your statement either.
You have no idea what my experience is. But I can tell you that I have enough experience to know that leaving the administration panel at /admin is dumb as fuck. So is not keeping regular offsite backups.
You clearly don't even have that basic administration knowledge.


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)












![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)




![[Image: 5qK1iJK.png]](http://i.imgur.com/5qK1iJK.png)


![[Image: master645.png]](http://pile.randimg.net/1/62/78105/master645.png)














