Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Step 4 is right in the article:

"they were able to sign into a Snowflake employee’s ServiceNow account using stolen credentials, thus bypassing OKTA which is located on lift.snowflake.com.

Following the infiltration, the threat actor claims that they were able to generate session tokens, which enabled them to exfiltrate massive amounts of data from the company"



Yes, but how should ServiceNow create session tokens if it is not part of the SSO system? I don't know enough about ServiceNow, but I think every large company has some products that are not part of their-SSO system. So that makes sense, but I am not sure about the next step.


I think they mean regenerating servicenow's own tokens/cookies, without hitting okta. so SN's session would still be valid.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: