SolarWinds blames intern for weak password that may have sparked hack
The password ‘solarwinds123’ was publicly accessible on GitHub for more than a year and brought to the firm's attention in 2019
SolarWinds executives have blamed a former intern for leaking a weak company password that was publicly accessible on the internet for more than a year.
The password ‘solarwinds123’ - a critical lapse in password security - was publicly accessible through a private GitHub repository from June 2018, before this was addressed in November 2019.
SolarWinds CEO Sudhakar Ramakrishna claimed this password was the fault of an intern who’d set it on one of their servers in 2017, speaking at a hearing before the US House Committees on Oversight and Homeland Security.
The password was first discovered in 2019 by security researcher Vinoth Kumar, who told Reuters that it had been set to grant access to the company's update server.
To read the full article, click here.