Today it was revealed that servers at
Apache.org and
Atlassian were successfully attacked, leading to thousands of stolen passwords. The attack on apache.org's servers was via
JIRA, and since the attack on Atlassian came from the same source, it probably was also through JIRA.
I'm sure that JIRA's programmers feel embarrassed enough about all of
(
Read more... )
Comments 15
Reply
- Jon Silvers, Atlassian
Reply
-Max
Reply
Reply
-Max
Reply
Reply
Reply
Reply
You write: "[HttpOnly] is one of the simplest and most effective protections". Baloney. It's simple, sure. But effective it is not. In most cases, anything an attacker can do without the HttpOnly flag, the attacker can do with the HttpOnly flag, at the cost of more work. It's a speedbump, not a robust protection.
Reply
-Max
Reply
Reply
Leave a comment