Sakura Samurai (group)

Sakura Samurai
Formation2020
FoundersJohn Jackson
PurposeWhite hat hacking and security research
Membership5
Websitesakurasamurai.pro Edit this at Wikidata

Sakura Samurai was a white hat hacking and security research group that was founded in 2020. The group is responsible for multiple vulnerability disclosures involving governmental groups and various corporations.[1]

History

Sakura Samurai was founded in 2020 by John Jackson, also known as "Mr. Hacking".[2] Active members of the group include Jackson, Robert "rej_ex" Willis, Jackson "Kanshi" Henry, Kelly Kaoudis, and Higinio "w0rmer" Ochoa.[2][3] Ali "ShÄde" Diamond, Aubrey "Kirtaner" Cottle, Sick.Codes, and Arctic are all former members of the group.[4]

In October 2022, Sakura Samurai announced on their Twitter page that they are now inactive due to "various other commitments" the members have individually.[5]

Notable work

Governmental groups

United Nations

Sakura Samurai discovered exposed git directories and git credential files on domains belonging to the United Nations Environmental Programme (UNEP) and United Nations International Labour Organization (UNILO). These provided access to WordPress administrator database credentials and the UNEP source code, and exposed more than 100,000 private employee records to the researchers. Employee data included details about U.N. staff travel, human resources data including personally identifiable information, project funding resource records, generalized employee records, and employment evaluation reports.[6][7] Sakura Samurai publicly reported the breach in January 2021, after first disclosing it through the U.N.'s vulnerability disclosure program.[7]

India

In March 2021, Sakura Samurai publicly disclosed vulnerabilities that affected 27 groups within the Indian government. After finding exposed git and configuration directories, Sakura Samurai were able to access credentials for critical applications, more than 13,000 personal records, police reports, and other data. The group also discovered vulnerabilities relating to session hijacking and arbitrary code execution on finance-related governmental systems.[8] After the issues reported to India's National Critical Information Infrastructure Protection Centre went unaddressed for several weeks, Sakura Samurai involved the U.S. Department of Defense Vulnerability Disclosure Program, and the issues were remediated.[9][8]

Corporations

Apache Velocity Tools

Sakura Samurai discovered and reported a cross site scripting (XSS) vulnerability with Apache Velocity Tools in October 2020. Sophisticated variations of the exploit, when combined with social engineering, could allow attackers to collect the logged-in user's session cookies, potentially allowing them to hijack their sessions. The vulnerable Apache Velocity Tools class was included in more than 2,600 unique binaries of various prominent software applications. Apache acknowledged the report and patched the flaw in November 2020, although Apache did not formally disclose the vulnerability.[10]

Keybase

The group discovered that Keybase, a security-focused chat application owned by Zoom, was insecurely storing images, even after users had ostensibly deleted them. They reported the vulnerability in January 2021, and disclosed it publicly in February after the bug had been patched and updates had been widely distributed.[11]

Sakura Samurai found a vulnerability in Pegasystems' Pega Infinity enterprise software suite, which is used for customer engagement and digital process automation. The vulnerability, which was first reported to Pegasystems in February 2021, involved a possible misconfiguration that would enable data exposure.[12]

The vulnerability led to Sakura Samurai breaching systems belonging to both Ford Motor Company and John Deere, incidents which were publicly disclosed in August 2021.[13][14] These breaches were the subject of a 2021 DEF CON presentation by Sick.Codes, which was titled "The Agricultural Data Arms Race: Exploiting a Tractor Load of Vulnerabilities in the Global Food Supply Chain (in good faith)".[15]

Fermilab

In May 2021, Sakura Samurai reported vulnerabilities they had discovered and disclosed to Fermilab, a particle physics and accelerator laboratory. The group was able to gain access to a project ticketing system, server credentials, and employee information.[16]

References

  1. ^ Xavier, John (20 February 2021). "India's cyber defenses breached and reported; govt. yet to fix it". The Hindu. ISSN 0971-751X. Retrieved 12 August 2021.
  2. ^ a b Jackson, John (22 January 2021). "Episode 200: Sakura Samurai Wants To Make Hacking Groups Cool Again. And: Automating Our Way Out of PKI Chaos". The Security Ledger with Paul F. Roberts. Retrieved 26 September 2021.
  3. ^ "Sakura Samurai". Sakura Samurai. Retrieved 26 September 2021.
  4. ^ "Retired Members of Sakura Samurai". Sakura Samurai. Retrieved 26 September 2021.
  5. ^ "Retirement Announcement". Twitter. Retrieved 30 October 2022.
  6. ^ Riley, Duncan (11 January 2021). "United Nations data breach exposes details of more than 100,000 employees". SiliconANGLE. Retrieved 12 August 2021.
  7. ^ a b Spadafora, Anthony (11 January 2021). "United Nations suffers major data breach". TechRadar. Retrieved 26 September 2021.
  8. ^ a b Sharma, Ax (12 March 2021). "Researchers hacked Indian govt sites via exposed git and env files". BleepingComputer. Retrieved 26 September 2021.
  9. ^ Majumder, Shayak (22 February 2021). "Government-Run Web Services Found to Have Major Vulnerabilities: Reports". NDTV-Gadgets 360. Retrieved 16 August 2021.
  10. ^ Sharma, Ax (15 January 2021). "Undisclosed Apache Velocity XSS vulnerability impacts GOV sites". BleepingComputer. Retrieved 16 August 2021.
  11. ^ Osborne, Charlie (23 February 2021). "Keybase patches bug that kept pictures in cleartext storage on Mac, Windows clients". ZDNet. Retrieved 16 August 2021.
  12. ^ "NVD – CVE-2021-27653". nvd.nist.gov. Retrieved 12 August 2021.
  13. ^ Sharma, Ax (15 August 2021). "Ford bug exposed customer and employee records from internal systems". BleepingComputer. Retrieved 26 September 2021.
  14. ^ Bracken, Becky (10 August 2021). "Connected Farms Easy Pickings for Global Food Supply-Chain Hack". ThreatPost. Retrieved 26 September 2021.
  15. ^ Kirk, Jeremy (9 August 2021). "Flaws in John Deere Systems Show Agriculture's Cyber Risk". National Cyber Security News Today. Retrieved 26 September 2021.
  16. ^ Sharma, Ax (6 May 2021). "US physics lab Fermilab exposes proprietary data for all to see". Ars Technica. Retrieved 26 September 2021.

Read other articles:

Vladimir Mikhailovich Bekhterev Vladimir Mikhailovich Bekhterev (lahir 20 Januari 1857 di Sorali, Vyatka [sekarang Kirov], Rusia — meninggal 24 Desember 1927 di Moskow, Rusia, Uni Soviet pada umur 70 tahun) adalah ahli neurofisiologi, psikiater, fisiolog, psikolog, dan refleksolog berkebangsaan Rusia.[1][2] Pada tahun 1881, Bekhterev menerima gelar doktor dari Akademi Bedah Medis St. Petersburg, dan kemudian ia melanjutkan belajarnya ke luar negeri selama empat tahun.[1&...

 

Частина інформації в цій статті застаріла. Ви можете допомогти, оновивши її. Можливо, сторінка обговорення містить зауваження щодо потрібних змін. (травень 2018) У Вікіпедії є статті про інших людей із прізвищем Полянський. Тома ПолянськийНародився 13 березня 1822(1822-03-13)[1...

 

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (أبريل 2019) أل فنسنت معلومات شخصية الميلاد 23 ديسمبر 1906  برمنغهام، ألاباما  تاريخ الوفاة 14 ديسمبر 2000 (93 سنة)   مواطنة الولايات المتحدة  إخوة وأخوات جون فنسنت  ...

Cuban guitarist, composer and poet (1913–1996) Celedonio Romero - An Evening of Guitar MusicCeledonio Romero (2 March 1913 – 8 May 1996) was a guitarist, composer and poet, perhaps best known as the founder of The Romeros guitar quartet. Biography Celedonio Romero was born in Cienfuegos, Cuba,[1] while his parents were on a business trip to the island. He began playing the guitar at the age of 5, and eventually studied music theory, harmony, composition, and counterpoint at th...

 

Salah satu gerbang masuk menuju Pasarean Mataram Pasarean Mataram (Hanacaraka: ꦥꦱꦫꦺꦪꦤ꧀ꦩꦠꦫꦩ꧀) adalah sebuah komplek pemakaman wangsa Mataram yang terletak di Kotagede, Yogyakarta. Di komplek pemakaman terdapat pusara Ki Ageng Pamanahan, Panembahan Senapati, Anyakrawati, Hamengkubuwana II, Paku Alam I, Paku Alam II, Paku Alam III dan Paku Alam IV.[1] Di komplek pemakaman tersebut terdapat juga pusara Sultan Adiwijaya dari Kesultanan Pajang, Ki Juru Martani serta ...

 

Untuk kegunaan lain, lihat Telisik (disambiguasi). TelisikAlbum studio karya DanillaDirilis3 Maret 2014Direkam2013StudioMenyentak Studio, Jakarta Tesla Manaf Studio, Bandung ARU Studio, BandungGenrePop, JazzDurasi48:37LabelOrion Records, DemajorsProduserLafa Pratomo, Danilla RiyadiKronologi Danilla -String Module Error: Match not foundString Module Error: Match not found Telisik (2014) Lintasan Waktu (2017)Lintasan Waktu2017 Singel dalam album Telisik Buaian Ada di Sana Berdistraksi Terpa...

Italian actor and author Mario ScacciaScaccia in La calandria (1972)Born(1919-12-26)26 December 1919Rome, ItalyDied26 January 2011(2011-01-26) (aged 91)Rome, ItalyOccupation(s)Actor, authorHeight1.80 m (5 ft 11 in) Mario Scaccia (26 December 1919 – 26 January 2011) was an Italian actor and author. He was a prominent figure in the Italian theatre of '900. Biography Born in Rome, the son of a painter, during the Second World War Scaccia was conscripted into the army as an ...

 

2022 single by Jax Victoria's SecretSingle by JaxReleasedJune 30, 2022 (2022-06-30)GenreRock[1]Length2:56LabelAtlanticSongwriter(s) Jackie Miskanic Mark Nilan Jr Dan Henig Producer(s) Jesse Siebenberg Mark Nilan Jax singles chronology U Love U (2022) Victoria's Secret (2022) Cinderella Snapped (2023) Lyric videoVictoria's Secret on YouTube Victoria's Secret is a song by American singer-songwriter Jax, and produced by Jesse Siebenberg and Mark Nilan. It was released in J...

 

British TV series or programme Monty Python: Almost the TruthTitle cardGenreDocumentaryDirected by Alan G. Parker Bill Jones Ben Timlett Starring Graham Chapman John Cleese Terry Gilliam Eric Idle Terry Jones Michael Palin Country of originUnited KingdomOriginal languageEnglishNo. of seasons1No. of episodes6ProductionProducers Margarita Doyle Bill Jones Benjamin Timlett Andrew Winter Running time360 minutesProduction companiesBill and Ben ProductionsOriginal releaseNetwork BBC2 IFC Relea...

2018 computer-animated science fiction film directed by Kevin R. Adams and Joe Ksander Next GenFilm poster outside ChinaDirected by Kevin R. Adams Joe Ksander Written by Kevin R. Adams Joe Ksander Story byWang NimaBased on7723by Wang NimaProduced by Jeff Bell Patricia Hicks Charlene Logan Kelly Yangbin Lu John Morch Ken Zorniak Starring John Krasinski Charlyne Yi Jason Sudeikis Michael Peña David Cross Constance Wu Cinematography Paul Kohut Paul Stodolny Edited byMatt AhrensMusic by Samuel J...

 

Keluarga yang berasal dari Jilu pada tahun 1910 Pejuang suku Jilu pada tahun 1918 Jīlū adalah sebuah distrik yang terletak di wilayah Hakkari di Mesopotamia atas di Turki sekarang. Sebelum tahun 1915 Jīlū adalah tempat bagi Bangsa Asyur dan juga minoritas Kurdi. Ada 20 desa Asyur di distrik ini. Daerah itu secara tradisional dibagi menjadi Jīlū Besar dan Kecil, dan Ishtāzin - masing-masing dengan Malik sendiri, dan terdiri dari sejumlah desa bangsa Asyur. Pada musim panas 1915, selama ...

 

English artist (1966–2008) Angus FairhurstAngus FairhurstBorn(1966-10-04)4 October 1966Pembury, Kent, EnglandDied29 March 2008(2008-03-29) (aged 41)Bridge of Orchy, ScotlandNationalityBritishEducationCanterbury Art College, Goldsmiths, University of LondonKnown forConceptual art, sculptureMovementYoung British Artists Angus Fairhurst (4 October 1966 – 29 March 2008) was an English artist working in installation, photography and video. He was one of the Young British Artists (YBA...

Canadian media/broadcasting company For other uses, see Corus. Corus Entertainment Inc.Corus Entertainment's logo since April 1, 2016Corus's headquarters, Corus Quay in Toronto, as seen from the CN TowerFormerlyShaw Radio Ltd. (1987–1999)TypePublicTraded asTSX: CJR.B (non-voting)IndustryMass media, broadcastingPredecessorsAlliance Atlantis (Broadcasting assets)CanwestShaw MediaWestern International CommunicationsFoundedAugust 27, 1987; 36 years ago (August 27, 1987) (Shaw ...

 

For other people named Alexander Arbuthnot, see Alexander Arbuthnot (disambiguation). Sir Alexander ArbuthnottBorn1789 (1789)Forton, Hampshire, EnglandDied8 May 1871 (1871-05-09)LeicesterAllegiance United KingdomService/branch Royal NavyYears of service1803–1846RankRoyal Navy Rear admiralBattles/wars Battle of Trafalgar, 1805 Battle of Copenhagen, 1807 Awards Naval General Service Medal, clasp Trafalgar[1] Gentleman of the Privy Chamber to George IV and to Queen Victo...

 

Не следует путать с Правительство (телесериал). Страны по формам государственного правления. По данным на 2021.      Президентские республики, полная власть президента      Парламентские республики, исполнительная власть президента зависит от парл...

Pesawat Dakota RI-001 Seulawah (Livery Lama) di Anjungan Aceh pada bulan Januari 2010Pesawat Dakota RI-001 Seulawah (Livery Baru) di Anjungan Aceh pada bulan Agustus 2010Anjungan Provinsi Aceh (NAD) adalah salah satu Anjungan Daerah di Taman Mini Indonesia Indah. Anjungan ini menampilkan dua rumah adat sebagai bangunan induk, lumbung padi (krueng pade), penumbuk padi (jeungki), tempat kumpul (bale), langgar (meunasah), panggung pergelaran, pesawat Dakota RI-001 Seulawah, toko cenderamata, dan...

 

American action comedy television series American Born ChineseGenreFantasyAction comedyCreated byKelvin YuBased onAmerican Born Chineseby Gene Luen YangStarring Ben Wang Yeo Yann Yann Chin Han Ke Huy Quan Jimmy Liu Sydney Taylor Daniel Wu Michelle Yeoh Music byWendy WangCountry of originUnited StatesOriginal languages English Mandarin No. of seasons1No. of episodes8ProductionExecutive producers Kelvin Yu Destin Daniel Cretton Asher Goldstein Jake Kasdan Melvin Mar Erin O'Malley Gene Luen Yang...

 

HepatoportoenterostomyIntraoperative view of complete biliary atresia.Other namesKasai portoenterostomyICD-10-PCS0F194ZBICD-9-CM51.37[edit on Wikidata] A hepatoportoenterostomy or Kasai portoenterostomy is a surgical treatment performed on infants with Type IVb choledochal cyst and biliary atresia to allow for bile drainage. In these infants, the bile is not able to drain normally from the small bile ducts within the liver into the larger bile ducts that connect to the gall bladder and sm...

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Voetbal Inside – news · newspapers · books · scholar · JSTOR (March 2022) (Learn how and when to remove this template message) Dutch TV series or program Voetbal InsideVoetbal InsideCreated byRTL NederlandPresented byWilfred GeneeCountry of originNetherlan...

 

This article does not cite any sources. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: The Last Live Video – news · newspapers · books · scholar · JSTOR (December 2009) (Learn how and when to remove this template message) 2002 video by X JapanThe Last Live VideoVideo by X JapanReleasedMarch 29, 2002RecordedTokyo Dome, December 31, 1997GenreHeavy metal, spe...

 

Strategi Solo vs Squad di Free Fire: Cara Menang Mudah!