Monday, February 28, 2011

Cascade of Failure

(Via Schneier on Security)

The complete takedown of computer security firm HBGary (by Anonymous) has been spelled out by ars technica's Peter Bright

The short version is:
  1. SQL Injection
  2. Rainbow Tables + Weak passwords
  3. Password Reuse
  4. Unpatched Server Exploit
  5. Admin email access
  6. Compromise email accounts
  7. Social Engineering nets root access

But the long version is oh so much more entertaining.

Take a look

No comments: