Attacker Cites Exposed Akamai Server and “intel123” Password

FavoriteLoadingInsert to favorites

Intel: “We believe that an specific with obtain downloaded and shared this data”

A misconfigured Akamai CDN (written content supply network) server and data files with the password “intel123” have been pinpointed as the evident result in of a important leak from Intel which has found 20GB of supply code, schematics and other sensitive facts released on the web.

The leak, posted very last evening by Tillie Kottman, an IT advisor primarily based in Switzerland, includes data files furnished to partners and prospects by chip maker Intel less than non-disclosure arrangement (NDA), and incorporates supply code, development and debugging instruments and schematics, instruments and firmware for the company’s unreleased Tiger Lake system.

Go through extra: Intel’s 7nm ‘Defect’ Leaves Investors Fretting

In a now-deleted article, the alleged supply of the leak said: “They have a service hosted on the web by Akami CDN that was not effectively secure. Soon after an world-wide-web-vast nmap scan I discovered my goal port open and went through a list of 370 attainable servers primarily based on aspects that nmap furnished with an NSE script.

“The folders were just lying open and I could just guess the title of 1. Then you were in the folder you could go back to the root and just click on into the other folders that you really don’t know the title of.

The Intel leak discussed in a (now deleted) article by the meant perpetrator

“Best of all, owing to yet another misconfiguration, I could masquerade as any of their workers or make my possess user.”

The supply extra that although many of the zip data files on the folder were password-secured, “most of them [have] the password Intel123 or a lowercase intel123.”

Kottman expects the facts dump will be the initially in a series of leaks from Intel.

“Unless I am misunderstanding my supply, I can already tell you that the upcoming sections of this leak will have even juicier and extra categorised stuff,” he said on Twitter.

A spokesman for Intel said the chipmaker is investigating the leak, but declined to comment on the claims about the misconfigured server and weak passwords.

She said:“The data seems to arrive from the Intel Useful resource and Style and design Heart, which hosts data for use by our prospects, partners and other exterior get-togethers who have registered for obtain.

“We believe that an specific with obtain downloaded and shared this facts.”

The incident is a stark reminder — if any were needed — that proactively mimicking these forms of techniques by hackers is important to company stability, irrespective of whether that is by way of common Purple Teaming, or other techniques.

The latest stability steering from the NSA (focussed on OT environments, but relevant across many IT environments much too), famous that ideal practices include:

  • Thoroughly patching all Online-available techniques.
  • Segmenting networks to safeguard workstations from immediate exposure to the world-wide-web. Carry out secure network architectures utilizing demilitarized zones (DMZs), firewalls, soar servers, and/or 1-way conversation diodes.
  • Guarantee all communications to distant equipment use a digital personal network (VPN) with strong encryption further more secured with multifactor authentication.
  • Test and validate the genuine business require for these types of obtain.
  • Filter network traffic to only enable IP addresses that are acknowledged to require obtain, and use geo-blocking where correct.
  • Connect workstations to network intrusion detection techniques where feasible.
  • Capture and evaluation obtain logs from these techniques.
  • Encrypt network traffic to protect against sniffing and man-in-the-middle techniques.

See also: National Security Agency: Believe Your OT Handle System Will Get Turned Against You