/?pid=critics-fume-after-github-removes-exploit-code-for-exchange-22392

Updated:09:27 AM EDT Jul 17


this is ggmania.com subsite Critics fume after Github removes exploit code for Exchange - TechAmok

Critics fume after Github removes exploit code for Exchange - [security]
06:16 PM EST - Mar,11 2021 - post a comment

Github has ignited a firestorm after the Microsoft-owned code-sharing repository removed a proof-of-concept exploit for critical vulnerabilities in Microsoft Exchange that have led to as many as 100,000 server infections in recent weeks. ProxyLogon is the name that researchers have given both to the four Exchange vulnerabilities under attack in the wild and the code that exploits them. Researchers say that Hafnium, a state-sponsored hacking group based in China, started exploiting ProxyLogon in January, and within a few weeks, five other APTs-short for advanced persistent threat groups-followed suit. To date, no fewer than 10 APTs have used ProxyLogon to target servers around the world.

Microsoft issued emergency patches last week, but as of Tuesday, an estimated 125,000 Exchange servers had yet to install it, security firm Palo Alto Networks said. The FBI and the Cybersecurity and Infrastructure Security Agency have warned that ProxyLogon poses a serious threat to businesses, nonprofits, and government agencies that remain vulnerable. On Wednesday, a researcher published what's believed to be the first largely working proof-of-concept (PoC) exploit for the vulnerabilities. Based in Vietnam, the researcher also published a post on Medium describing how the exploit works. With a few tweaks, hackers would have most of what they needed to launch their own in-the-wild RCEs, security speak for remote code execution exploits. Publishing PoC exploits for patched vulnerabilities is a standard practice among security researchers. It helps them understand how the attacks work so that they can build better defenses. The open source Metasploit hacking framework provides all the tools needed to exploit tens of thousands of patched exploits and is used by black hats and white hats alike. Within hours of the PoC going live, however, Github removed it. By Thursday, some researchers were fuming about the takedown. Critics accused Microsoft of censoring content of vital interest to the security community because it harmed Microsoft interests. Some critics pledged to remove large bodies of their work on Github in response.

Short overview of recent news articles

Stranger Things 5 - Official Teaser (Jul,17 2025 )

Google Is Selling Fake Products - WAN Show July 11, 2025 (Jul,14 2025 )

Hacked by playing Call of Duty WW2 on Gamepass? (Jul,12 2025 )

2025 VW Golf GTE // TOP SPEED REVIEW on AUTOBAHN (Jul,12 2025 )

NEW Audi RS3 v cheapest used RS3: DRAG RACE (Jul,11 2025 )

A critical security vulnerability in Microsoft Remote Desktop Client (Jul,10 2025 )

Samsung Z Fold/Flip 7 Impressions: Major Upgrades! (Jul,10 2025 )

Gmail's latest feature helps you get rid of those pesky emails from (Jul,08 2025 )

I'm an idiot and still made top 5... here's how (Jul,06 2025 )

The Fantastic Four: First Steps - Official 'Lift Off' Teaser (Jul,05 2025 )

Samsung Galaxy Z Fold 7 - Hands on Look (Jul,04 2025 )

RTX 5070 Ti vs RTX 5080 - Is 5080 Gaming Laptop Worth More $$$? (Jul,04 2025 )

FIRST DRIVE: Praga Bohema - Crazy Hypercar Driven! (Jul,04 2025 )

Ballerina - Exclusive John Wick Deleted Scene (2025) Keanu Reeves, (Jul,03 2025 )

Call of Duty: WWII - Remote Code Execution Warning (PC Game Pass) (Jul,03 2025 )

1014HP Lamborghini REVUELTO 369KMH TOP SPEED POV on AUTOBAHN (Jul,02 2025 )

Nvidia Drivers (V 576.80 vs V 576.88) - Test In 12 Games - RTX 4060 (Jul,01 2025 )

AMD Adrenalin 25.6.3 Driver Is Available (Jun,30 2025 )

NVIDIA GeForce RTX 5080 SUPER Could Feature 24 GB Memory, Increased (Jun,30 2025 )

Guess What Nvidia Did THIS Time (Jun,29 2025 )

The 10 Best Dinosaur Movies of All Time (Jun,28 2025 )

Microsoft officially confirms that Windows 11 version 25H2 is coming (Jun,28 2025 )

Eddington - Official Trailer 2 (2025) Joaquin Phoenix, Pedro Pascal (Jun,26 2025 )

Microsoft Say System Restore Points Now Expire After 60 Days (Jun,25 2025 )

Facebook, Netflix, and Microsoft Websites Hijacked to Insert Fake (Jun,25 2025 )

I put a $3000 GPU in my Average PC... It Was a Mistake (Jun,24 2025 )

Best External SSD for Mac 2025: After Weeks of Testing, Here's What (Jun,24 2025 )

Mostly boob jokes this week (RTX 5090 DD) - Tech News June 22 (Jun,23 2025 )

Superman - Official 30 Second Spot (2025) (Jun,21 2025 )

'The fastest road car I've ever been in!' - Ferrari F80 track day (Jun,21 2025 )

CPU SCAM: AMD Ryzen 9800X3D Counterfeits & Fraud (Jun,20 2025 )

28 Years Later Review (Jun,19 2025 )

HW News - NVIDIA "N1x" CPU Leak, ASUS Xbox ROG Ally, More Intel (Jun,18 2025 )

NVIDIA GeForce 576.80 WHQL Driver (Jun,17 2025 )

The Fantastic Four: First Steps - Official 'H.E.R.B.I.E.' Teaser (Jun,16 2025 )

Huawei Maextro S800 First Look - A True BMW & Mercedes Killer? (Jun,15 2025 )

Upgrade Windows 10 to Windows 10 LTSC Without Losing Data (Jun,14 2025 )

Squid Game: Season 3 - Final Games Trailer (Jun,14 2025 )

WWDC 2025: Everything Revealed in 9 Minutes (Jun,11 2025 )

Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws (Jun,10 2025 )

This Malware BREAKS WINDOWS! (Jun,10 2025 )

Reset Forgotten Password without Any Software, without USB drive in (Jun,10 2025 )

Microsoft Will Block Unsupported Hardware For Windows 11 (Jun,08 2025 )

Memory Wars! Apple vs Ryzen - Is Unified Memory Faster than Shared (Jun,08 2025 )

Predator: Killer of Killers - Exclusive Clip (2025) (Jun,06 2025 )

Enable Deep Effect on Samsung One Ui 7 (Jun,06 2025 )

Google Kills Off PayPal in Google Wallet (Jun,05 2025 )

Samsung's Next Flagship Foldable Will be Ultra (Jun,05 2025 )

Over 40 Malicious Chrome Extensions Mimic Popular Brands to Steal (Jun,05 2025 )

The Witcher IV - Unreal Engine 5 tech demo (Jun,03 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs