GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I wrote up the Delinea Secret Server Cloud security incident situation: https://doublepulsar.com/delinea-has-cloud-security-incident-in-thycotic-secret-server-gaff-581a33990882

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

As far as I can see Delinea have no responsible disclosure programme or vulnerability reporting contact.

They did, however, do a podcast about how to run one 😬 https://delinea.com/events/podcasts/responsible-disclosure-programs-katie-moussouris-casey-ellis

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Delinea have removed the paywall on the IoCs and remediation information.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

In fairness to Delinea I think they have got on top of this really well now. The remediation guide is top tier.

They probably want to have a look at their CMS setup for their online portals, eg the podcast and marketing content is really well search engine optimised, but the security content (including responsible disclosure policy) is on a platform which is really search engine unfriendly - most of it is so buried I can’t even find it via Google, I think they might be blocking it by mistake.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

All of Delinea’s product and cloud security info is on trust.delinea.com - but only the front page is indexed by search engines, there’s only two results. They block pages off using robots.txt - including how to report vulnerabilities.

Other orgs probably want to learn from that.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
maswan,
@maswan@mastodon.acc.sunet.se avatar

@GossiTheDog If only the Chief Security Scientist and Advisory CISO at Delinea had had an opportunity to listen to that episode, maybe they would have been better off!

faebudo,

@GossiTheDog It's in their responsible disclosure policy pdf: securityandvulnerabilities@delinea.com
here: https://trust.delinea.com/?itemUid=56583ca0-6561-4cf3-a150-8c0c45d214cf

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • dmaonR,

    @GossiTheDog @faebudo If it's not on the contacts webpage it might was well not exist.

    faebudo,

    @dmaonR @GossiTheDog I agree. it's also not indexed and you can't google for it. Also I have to assume it's only there for ISO 27001 compliance and not because they use it, when even their support staff doesn't know about their policies and processes concerning security.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • InstantRegret
  • Durango
  • JUstTest
  • everett
  • tacticalgear
  • modclub
  • anitta
  • cisconetworking
  • tester
  • ngwrru68w68
  • GTA5RPClips
  • normalnudes
  • megavids
  • Leos
  • provamag3
  • lostlight
  • All magazines