9

A few days ago our server was compromised due to an outdated Jenkins version. The malicious user installed a crypto miner on the server... The same day that it was found I told management that I'm interested in helping out with the server. Since then, nothing happened... No updates, no security measures, no nothing (except for the removed crypto miner and updated Jenkins software)

Oh well only a matter of time before another hack...

Question to some (who work way way way longer than me) med - seniors, should I make a big deal out of this? And keep pressure on it. Or should I just leave it be and wait for the next comprised server? I know devrant is not a Q&A service, but some dev to dev advice is much appreciated.

- incognito

Comments
  • 8
    Leave a paper trail. Don't just tell management but write it to them in a email. Tell them what could/will happen and offer them solutions. Maybee even make a calculation of the costs (they love that stuff) and what it could save. That way, if shit hits the fan and they try to blame it on other people or more specific you "as you knew it but didn't bring it (enough) to theor attention", you'll be able to prove it.
Add Comment