In response to these allegations KPN issued a statement saying that the suggestions that there is a connection between the hack and creation of certificates is true. “The hack of the site has no connection with the issuance and management of Government PKI certificates.”
Despite the statement issued by KPN, a second website belonging to a subsidiary of the telecommunications company that also issues digital certificates to the Dutch government was also taken down.
According to the original Webwereld article by Brenno de Winter, the attack was launched through a PHP MyAdmin account that didn’t have a password. The attacker then used the database to create files including executable scripts.
0 reactions:
Post a Comment