Accidentally altering data on senate.gov
blog.12security.com
blog.12security.com
appears to be the default public key for a juniper firewall. I could be wrong but I don’t see anything nefarious.
Obviously you should change your default key and you probably shouldn’t whitelist huge IP ranges.
Apparently they left open their main production database a few months ago. The issue here though seems to be that even now they require all these agencies to whitelist on all ports their two /24 "remote support" subnets.
He pulled an SSH key from one of the remote support servers and found it also on dozens of Chinese servers...
The presentation made me doubt if the research is legit or if this is just someone drawing the wrong conclusions and throwing it together in yet another Wordpress blog...
>This specific kind of fingerprint is relatively new and known as the "hassh". It is as follows:
>8e:c3:91:a4:f6:c0:b3:66:01:e9:85:a9:da:a6:24:f9
That’s a regular SSH key fingerprint, not a “hassh”.
GovDelivery, I think the same as Granicus, has always been plagued by mass spamming accusations. This comes up on reddit occasionally.
Either way, the video streaming servers, they are just what Elemental Technologies offered before they were (super allegedly) hacked by the PLA to get at Apple and Amazon in the Bloomberg article last year...