12 ms·
https://twitter.com/Jeremy_Kirk/status/1573652986437726208 https://twitter.com/Jeremy_Kirk/status/1573652986437726208
by bwilli123 4y ago
https://twitter.com/Jeremy_Kirk/status/1573652986437726208 https://twitter.com/Jeremy_Kirk/status/1573652986437726208
- bwilli123 4y agofrom the twitter link ..."The Optus hacker says they accessed an unauthenticated API endpoint. This means they didn't have to login. The person says: "No authenticate needed. That is bad access control. All open to internet for any one to use. The API endpoint was api[dot]http://optus.com.au http://optus.com.au. Yes, that looks weird, but the hacker says it worked otherwise a DNS error occurred. That API is now offline, so there is no more risk for Optus. It was used in part to let Optus customers access their own data."