home.social

#mobileirony — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobileirony, aggregated by home.social.

fetched live
  1. Patch numbers globally for #MobileIrony vuln are actually pretty good for a change.

  2. Patch numbers globally for #MobileIrony vuln are actually pretty good for a change.

  3. CISA advisory says the zero day exploitation of #MobileIron was happening from "at least" April 2023 (which backs up from I wrote in my blog - i.e. I can see exploitation in logs going back to early this year).

    Threat actors were uploading webshells and such. #threatintel #mobileirony

    cisa.gov/news-events/cybersecu

  4. CISA advisory says the zero day exploitation of #MobileIron was happening from "at least" April 2023 (which backs up from I wrote in my blog - i.e. I can see exploitation in logs going back to early this year).

    Threat actors were uploading webshells and such. #threatintel #mobileirony

    cisa.gov/news-events/cybersecu

  5. The #MobileIrony API endpoint is now public knowledge - it’s /mifs/aad/

    Yes, you just added to add ‘aad’ to access the admin API without auth and it’s been like that for years.

    github.com/projectdiscovery/nu

  6. The #MobileIrony API endpoint is now public knowledge - it’s /mifs/aad/

    Yes, you just added to add ‘aad’ to access the admin API without auth and it’s been like that for years.

    github.com/projectdiscovery/nu

  7. Was in a meeting with our third party risk management team talking about #mobileirony

    Audibly laughed when I saw @GossiTheDog ’s logo on the screen 😂

  8. Seems that they mitigated this without upgrading somehow. Going to the vulnerable URI just gives an unauthorized error.

    #mobileiron #mobileirony

  9. The number of people online who think the vulnerable API path for the #mobileirony 0-day is literally /vulnerable/path/api/v2/ is too damn high!

  10. The MobileIron vuln is definitely do the rounds in security circles as my honeypot is getting probed, admin lists dumped and disclosures from researchers. #MobileIrony #threatintel

  11. The MobileIron vuln is definitely do the rounds in security circles as my honeypot is getting probed, admin lists dumped and disclosures from researchers. #MobileIrony #threatintel

  12. Anyone know what the vulnerable MobileIron api path is? I've got two clients with unpatched IronMobile endpoints and I want to show them impact. I know the regular path is /api/v2 and the vulnerable path has something prepended to that but haven't figured it out yet.

    #redteam #pentesting #MobileIrony #MobileIron #threatintel

  13. Anyone know what the vulnerable MobileIron api path is? I've got two clients with unpatched IronMobile endpoints and I want to show them impact. I know the regular path is /api/v2 and the vulnerable path has something prepended to that but haven't figured it out yet.

    #redteam #pentesting #MobileIrony #MobileIron #threatintel