Forum Moderators: open

Message Too Old, No Replies

Hacker Publishes Details From Pulse Secure VPN Enterprise Servers

         

engine

11:16 am on Aug 5, 2020 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Reports of a hacker publishing admin account details, plaintext usernames and passwords, and IP addresses of over 900 Pulse Secure VPN enterprise servers came out today.
It seems the Pulse Secure VPN servers in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability.

The list includes the following:-

  • IP addresses of Pulse Secure VPN servers
  • Pulse Secure VPN server firmware version
  • SSH keys for each server
  • A list of all local users and their password hashes
  • Admin account details
  • Last VPN logins (including usernames and cleartext passwords)
  • VPN session cookies


  • [zdnet.com...]