Security News > 2021 > January > Stack Overflow Shares Technical Details on 2019 Hack

Stack Overflow Shares Technical Details on 2019 Hack
2021-01-28 12:44

Stack Overflow, the popular Q&A platform for programmers, this week shared technical information on how its systems were breached back in 2019, and it turns out that the hacker often viewed questions posted on Stack Overflow to learn how to conduct various activities on the compromised systems.

The security breach was disclosed by Stack Overflow in mid-May 2019, and a few days later it admitted that the incident resulted in the details of some users being exposed.

The attacker apparently started from a low-privileged account and gradually worked their way up to the point where they could steal Stack Overflow source code.

"Thankfully, none of the databases-neither public nor private-were exfiltrated. Additionally, there has been no evidence of any direct access to our internal network infrastructure, and at no time did the attacker ever have access to data in Teams, Talent, or Enterprise products," Stack Overflow said in its blog post.

The attacker regularly viewed questions posted on Stack Overflow to obtain information, which allowed the company to "Anticipate and understand the attacker's methodology." during its investigation.

Stack Overflow says it cannot share any information about the attacker due to ongoing investigations, but the company's description of the attack suggests that the hacker was skilled and determined.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/Do7Ho4bUh7E/stack-overflow-shares-technical-details-2019-hack