this post was submitted on 23 Jul 2025
92 points (100.0% liked)

Cybersecurity

7940 readers
36 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
all 13 comments
sorted by: hot top controversial new old
[–] expatriado@lemmy.world 24 points 1 week ago (4 children)

jee.. is that easy? what's your password OP?

[–] floofloof@lemmy.ca 45 points 1 week ago* (last edited 1 week ago) (1 children)

hunter2, but don't tell anyone because it's a secret.

[–] milkisklim@lemmy.world 39 points 1 week ago (2 children)
[–] Apollo98@sh.itjust.works 28 points 1 week ago (1 children)
[–] treadful@lemmy.zip 8 points 1 week ago* (last edited 1 week ago)

RIP bash.org

EDIT: Nice, there's a bunch of mirrors.

[–] Zier@fedia.io 12 points 1 week ago

Weird, because all I see is hunter*

[–] onslaught545@lemmy.zip 20 points 1 week ago (1 children)

Yup, it is. Social engineering is by far the most effective means of gaining unlawful access to any system.

Humans are always the weakest link.

Exactly. Many breaches follow this pattern:

  1. Learn the name and some basic details about the secretary or something
  2. Call corporate tech support asking for a password reset claiming to be the secretary
  3. Access important stuff since secretaries have a surprising amount of access

Replace "secretary" with some other relevant individual who has a surprising amount of access and wouldn't attract attention.

[–] limer@lemmy.ml 9 points 1 week ago

correcthorsebatterystaple

[–] BigTrout75@lemmy.world 9 points 1 week ago

Hi, I'm Steve from corp. I need your password to verify some settings....

[–] svc@lemmy.frozeninferno.xyz 7 points 1 week ago (1 children)

At least it wasn't due to a user input sanitization issue

[–] example@reddthat.com 1 points 6 days ago

instead it was a user sanitization issue