Jan. 4, 2023, 1:41 p.m. | /u/pseudo_su3

cybersecurity www.reddit.com

I’m chasing something down at my org. We had a user who is a sales person (so not inside our org) and their account was compromised.

These sales employees logon to a vpn into a sales platform that sits in the dmz.

Reviewing the logs, I see a favicon.ico. I download it. It’s got a script in it, that appears to take the session/cookie from the referrer and pass it to the sales site. This “cookie” is set to expire …

account compromised cookie cybersecurity dmz down download employees favicon ico logon logs org platform question referrer results sales script session urlscan urlscan.io vpn

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC