Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

from the twitter link ..."The Optus hacker says they accessed an unauthenticated API endpoint. This means they didn't have to login. The person says: "No authenticate needed. That is bad access control. All open to internet for any one to use. The API endpoint was api[dot]http://optus.com.au. Yes, that looks weird, but the hacker says it worked otherwise a DNS error occurred. That API is now offline, so there is no more risk for Optus. It was used in part to let Optus customers access their own data."


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: