| ▲ | 1dom a day ago | ||||||||||||||||||||||||||||||||||
From what I can understand from reading a few different, slightly conflicting, versions of these events: they weren't given write access. They found a zero day exploit that allowed them to create folders, and the folder names were initially used for agents to communicate. I'm not sure artifactory was connected to the net. Some agent sandboxes had internet access and were able to communicate with ones without access via artifactory. | |||||||||||||||||||||||||||||||||||
| ▲ | choeger a day ago | parent [-] | ||||||||||||||||||||||||||||||||||
I read the agents used SSRF via artifactory to gain uncontrolled access to the net. Apparently their intended net access went through a tightly controlled proxy. Even that appears to be very risky, tbh. If I was to setup a sandbox for such a complex and autonomous system, I'd probably point them to an archive-like cache for net access and cut their comms at the package level. | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||