GAO Says Equifax Missed Flaws, Intrusion in Massive Breach

  /     /     /  
Publicated : 23/11/2024   Category : security


GAO Says Equifax Missed Flaws, Intrusion in Massive Breach


A report from the Government Accountability Office details the issues found and opportunities missed in the huge 2017 Equifax data breach.



The 2017 Equifax breach involved at least 9,000 queries to 51 databases over a period of 76 days, according to a report on the attack issued by the Government Accountability Office (GAO). The report details the mechanisms used by the attackers to gain access and exfiltrate personal information of approximately 145 million individuals in the US, Canada, and the UK.
Attackers began scanning Equifaxs systems for a vulnerability in Apache Struts within two days of the vulnerabilitys public disclosure. While they quickly found the flaw, Equifaxs own systems not only failed to find the vulnerability, they failed to spot the intrusion for weeks following its initial success.
The attackers were careful to take data out of the databases in small chunks to avoid detection, using an outdated certificate in a dispute-resolution server to encrypt the exfiltrated data and avoid tripping packet-inspecting security components.
According to the report, there were a number of different issues at Equifax, each contributing to the possibility and severity of the breach. The security issues ranged from bad network architecture to a failure to establish limits on the number of database queries possible from a single address.
The report notes that Equifax has publicly reported that it has remediated all the issues associated with the breach. The company has not detailed those remediation steps, and the GAO has not independently verified or assessed the remediation.
For more, read
here
.
 
Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the
conference
 and
to register.

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
GAO Says Equifax Missed Flaws, Intrusion in Massive Breach