logoalt Hacker News

tardedmemeyesterday at 7:01 PM2 repliesview on HN

I wonder if this is how Handala group recently stole the list of service members.

How do people find these vulnerabilities within the immense scope of the whole internet? Are they going around with some kind of generic API scanner that discovers APIs?


Replies

yellowappleyesterday at 10:33 PM

Probably based on insider info to some degree; if you already do any sort of work for the DoD, then that tends to help narrow the scope of the search for vulnerable things to exploit.