Reply to post: @GingerOne

Solarwinds sends customers each others' complete client lists

Anonymous Coward
Anonymous Coward

@GingerOne

Hopefully your just having a laugh.. but if not....

Although while not a direct attack, knowing the naming conventions of systems within a targets environment is generally a great step forward in gaining unauthorised access to a system. Being able to call in to said target and being able to reel off a list of machine names etc will more than likely assist with a social engineering attack by often proving enough familiarity with the network to gain trust.

I would be very angry if any customer I looked after had had their details leaked knowing what could be on the way after such a breach of information. And before anyone says it wasn't sent to external customers. Do you want your systems security safe guarded by a competitor? Or do you trust them not to accidently let your details "slip" to the wider world?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon