|
|
|
|
|
by tejaswiy
3182 days ago
|
|
> Second, Smith blamed a scanning system used to spot this sort of oversight that did not identify the customer-dispute portal as vulnerable. Smith said forensic investigators are still looking into why the scanner failed. Do these scanners ever work? Without naming names, the only reason we used this at a previous company was to kind of handwave around hey we have this tool doing regular security checks. > The first excuse Smith gave was "human error." He says there was a particular (unnamed) individual who knew that the portal needed to be patched but failed to notify the appropriate IT team. How is this one individual responsible for tracking all IT security vulnerabilities in all the technologies that equifax uses across its stack? How do they not have an admin team whose job it is to do these things? |
|
The scanners do work, we used them at my company and they found this specific vulnerability. It surprised some development teams because there are libraries that use struts without really advertising it, so even applications that don't "use struts" had a transitive dependency on it, it was running in their container and showed up on the lists that were circulating.