/?pid=critics-fume-after-github-removes-exploit-code-for-exchange-22392

Updated:03:09 AM EDT Apr 19


this is ggmania.com subsite Critics fume after Github removes exploit code for Exchange - TechAmok

Critics fume after Github removes exploit code for Exchange - [security]
06:16 PM EST - Mar,11 2021 - post a comment

Github has ignited a firestorm after the Microsoft-owned code-sharing repository removed a proof-of-concept exploit for critical vulnerabilities in Microsoft Exchange that have led to as many as 100,000 server infections in recent weeks. ProxyLogon is the name that researchers have given both to the four Exchange vulnerabilities under attack in the wild and the code that exploits them. Researchers say that Hafnium, a state-sponsored hacking group based in China, started exploiting ProxyLogon in January, and within a few weeks, five other APTs-short for advanced persistent threat groups-followed suit. To date, no fewer than 10 APTs have used ProxyLogon to target servers around the world.

Microsoft issued emergency patches last week, but as of Tuesday, an estimated 125,000 Exchange servers had yet to install it, security firm Palo Alto Networks said. The FBI and the Cybersecurity and Infrastructure Security Agency have warned that ProxyLogon poses a serious threat to businesses, nonprofits, and government agencies that remain vulnerable. On Wednesday, a researcher published what's believed to be the first largely working proof-of-concept (PoC) exploit for the vulnerabilities. Based in Vietnam, the researcher also published a post on Medium describing how the exploit works. With a few tweaks, hackers would have most of what they needed to launch their own in-the-wild RCEs, security speak for remote code execution exploits. Publishing PoC exploits for patched vulnerabilities is a standard practice among security researchers. It helps them understand how the attacks work so that they can build better defenses. The open source Metasploit hacking framework provides all the tools needed to exploit tens of thousands of patched exploits and is used by black hats and white hats alike. Within hours of the PoC going live, however, Github removed it. By Thursday, some researchers were fuming about the takedown. Critics accused Microsoft of censoring content of vital interest to the security community because it harmed Microsoft interests. Some critics pledged to remove large bodies of their work on Github in response.

Short overview of recent news articles

You Deserve this much OLED - AORUS CO49DQ (Apr,19 2024 )

Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC (Apr,19 2024 )

Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit (Apr,18 2024 )

I Will Build You a PC Right Now! (Apr,18 2024 )

These games carry REAL security risks! BEWARE! (Apr,17 2024 )

Visible First to Offer Annual Payment Plan, with Discount up to 26% (Apr,17 2024 )

Is Coding Still Worth Learning in 2024? (Apr,17 2024 )

All New Atlas - Boston Dynamics (Apr,17 2024 )

The NEW Chip Inside Your Phone! (NPUs) (Apr,16 2024 )

XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel! (Apr,16 2024 )

The Most 2024 Laptop - Razer Blade 14 Review (Apr,15 2024 )

NEVER install these programs on your PC... EVER!!! (Apr,15 2024 )

Use Live Translate on Galaxy S24 series to translate a call's (Apr,14 2024 )

I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam? (Apr,14 2024 )

Samsung Galaxy Ring - This Just Got Interesting (Apr,13 2024 )

Piracy Is Over Party - WAN Show April 12, 2024 (Apr,13 2024 )

Conan O'Brien Needs a Doctor While Eating Spicy Wings (Apr,13 2024 )

Beatbox Jcob recreats every sound (Apr,13 2024 )

Intel is Gunning for NVIDIA (Apr,13 2024 )

Building a Budget DIY Home Surveillance System (Apr,13 2024 )

Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop (Apr,12 2024 )

DARK MATTER Trailer (2024) New Sci-Fi Movies 4K (Apr,11 2024 )

How to Build a PC, the last guide you'll ever need! (2024 Update) (Apr,11 2024 )

Intel 300 CPU Review - The Pentium Replacement is Finally Here... (Apr,10 2024 )

Wubuntu, the Dubious Linux Windows (Apr,10 2024 )

A Lite Version Of Windows 11 To Be Released This Year (Apr,09 2024 )

This $150 Smartphone might be All You Need (Apr,09 2024 )

I Can't Believe These are Real - Reacting to Ridiculous PCs on (Apr,09 2024 )

A new video shows AirPower prototype charging an Apple Watch (Apr,08 2024 )

Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved (Apr,08 2024 )

20 COOL GADGETS YOU SHOULD SEE (Apr,08 2024 )

New HTTP/2 vulnerability leaves servers in danger of devastating DoS (Apr,08 2024 )

3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance? (Apr,07 2024 )

The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024 (Apr,06 2024 )

Top NEW RELEASES on Netflix in APRIL 2024 (Apr,06 2024 )

Magician vs Slow-Mo Camera (Skill Challenge) (Apr,05 2024 )

Re-Ranking All Current GPUs From Worst to Best (2024 Update) (Apr,05 2024 )

Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function (Apr,04 2024 )

HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld (Apr,04 2024 )

Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware (Apr,03 2024 )

OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge (Apr,02 2024 )

Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all (Mar,31 2024 )

This MIGHT be the best NAS on the market (Mar,31 2024 )

What do Zen 5, Arc Battlemage and NVIDIA RTX 50 GPUs Have In Common? (Mar,31 2024 )

They FIXED the Dual Chamber Problem! (Mar,31 2024 )

Paying for Cloud Storage is Stupid (Mar,30 2024 )

Entire Case Company Built on Literal Theft (Mar,30 2024 )

Red Hat warns of backdoor in XZ tools used by most Linux distros (Mar,30 2024 )

AMD Ryzen 7 7800X3D vs. Ryzen 9 7900X3D vs. Ryzen 9 7950X3D, Gaming (Mar,30 2024 )

I Need a Home Theater PC... NOW! - NVIDIA RTX HDR (Mar,30 2024 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs