Avatar feed
Responses: 2
PFC David Foster
3
3
0
They are getting good. Real good. They call me from the number listed to financial crimes unit from DC trying to scam me.
(3)
Comment
(0)
Maj Cyberspace Operations
Maj (Join to see)
3 y
I always like getting called from my own number.
(2)
Reply
(0)
PFC David Foster
PFC David Foster
3 y
Maj (Join to see) - I haven't had that happen yet.
(2)
Reply
(0)
Maj Cyberspace Operations
Maj (Join to see)
3 y
PFC David Foster - Give it time.
(1)
Reply
(0)
Avatar small
Maj Cyberspace Operations
2
2
0
This one is just too funny from a security perspective. This was probably a forgotten piece of functionality as the government focuses more on unauthorized access to confidential information than it does little annoyances like this. This annoyance was a gut punch to their reputation, however.

The Krebs article states that everything about these emails was generated client-side. Everything about the attack was setup locally and then sent back to the server, which willingly complied because that's the way it was programmed. "Here, server, just send this email on my behalf and don't ask any questions." The first rule in application security is that you never trust anything from the client. It's like asking a kid if they brushed their teeth or washed behind their ears.
(2)
Comment
(0)
Avatar small

Join nearly 2 million former and current members of the US military, just like you.

close