Published Sep 26, 2022

Firefox supports blockers, NATS is great, Uber's MFA fatigue, OAuth2 drawn in cute shapes & an aging programmer

Jerod Santo delves into Mozilla's strategic defense of content blockers amidst Chrome's constraints, exposes the intricacies behind Uber's security breach driven by MFA fatigue, and explores programmer Jorge Manrubia's insights on aging in tech, emphasizing the enduring enthusiasm and capability in coding careers.
Episode Highlights
The Changelog logo

Popular Clips

Episode Highlights

  • MFA Fatigue

    The recent Uber security breach highlights the use of MFA fatigue as a potent attack vector. explains that the attacker spammed the target with repeated multi-factor authentication requests until access was granted 1. This technique, combined with a previously purchased password from the dark web, allowed the attacker to bypass Uber's last line of defense.

    The attacker disguised themselves as Uber IT and spammed the target with repeated multi-factor auth requests until they eventually authorized access.

    ---

    Once inside, the attacker exploited vulnerabilities in Uber's intranet to further their access 1.

       

    Intranet Flaws

    Uber's intranet vulnerabilities played a crucial role in the security breach. After gaining access through MFA fatigue, the attacker scanned the network and discovered a PowerShell script containing admin credentials 1. This oversight allowed the attacker to escalate their privileges and navigate Uber's internal systems with ease.

    Once they had access to Uber's intranet, they scanned the network until they found a PowerShell script with admin credentials, and at that point it was pretty much over easy peasy lemon squeezy.

    ---

    This incident underscores the importance of securing internal networks and regularly auditing for potential vulnerabilities.

Related Episodes