Странно что они не сразу заметили что 4 ключа имеют коннекты с tor
Первые два с root доступом к гиту, почте были успешно проданны. С разрешения покупателя я могу опубликовать информацию 3 доступа в паблик. Тем более тут ничего прям такого нет) Начал выгрузку их VDI (~120 Gb, диски с информацией о fortimonitor, fortivpn и forticloud)
fortimonitor.forticloud.com
Код:
2022-05-18T17:16:27.000Z forticwpbucket50490ba1-e13b-4e6e-b722-2e01af196fe7
2022-07-15T20:30:11.000Z forticwpbucket54b8dfba-f98a-470b-9bd5-c85ca1b07083
2022-11-22T20:26:35.000Z msk-broker-logs-bucket-devops
2016-04-11T18:40:23.000Z panopta-appliance
2020-10-17T19:28:22.000Z panopta-cornell
2018-07-27T15:48:12.000Z panopta-cybercube-exports
2019-07-22T19:56:19.000Z panopta-github-backups
2018-06-11T20:41:29.000Z panopta-terraform-state
2019-05-02T15:24:00.000Z prod-log-trail-bucket
Код:
fortimonitor.forticloud.com
Information
ID: /hostedzone/Z0818853MQOW8X8F9EZ7
ARN: arn:aws:route53:us-east-1::hosted-zone//hostedzone/Z0818853MQOW8X8F9EZ7
Caller Reference: d7355a2c-e71b-4d2a-8b80-9bf4d79c4695
Resource Record Set Count: 16
Lambda Functions
ARN: arn:aws:lambda:us-east-2:922052754006:function:clickupReleases
Description: None
Last Modified: Thu Feb 04 2021 15:02:10 GMT+0000 (Coordinated Universal Time)
Runtime: python3.7
Version: $LATEST
Revision ID: 711afd16-b3db-4191-8d3b-51ad7eca50df
Execution Role: clickupReleasesRole
Handler: function.lambda_handler
Code Size: 1446247
Memory Size: 128
Timeout: 60
ARN: arn:aws:lambda:us-east-2:922052754006:function:devOncallSlack
Description: None
Last Modified: Thu Mar 31 2022 18:30:04 GMT+0000 (Coordinated Universal Time)
Runtime: python3.8
Version: $LATEST
Revision ID: 3ca4fb7f-d0c2-44ae-9b83-07ecaa1107b7
Execution Role: devOncallSlack-role-4d7jnrrz
Handler: function.lambda_handler
Code Size: 2005244
Memory Size: 128
Timeout: 3
fortimonitor.forticloud.com
Код:
{
"ResourceRecordSets": [
{
"Name": "fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "35.186.248.171"
}
]
},
{
"Name": "fortimonitor.forticloud.com.",
"Type": "MX",
"TTL": 43200,
"ResourceRecords": [
{
"Value": "1 ASPMX.L.GOOGLE.COM."
},
{
"Value": "5 ALT1.ASPMX.L.GOOGLE.COM."
},
{
"Value": "5 ALT2.ASPMX.L.GOOGLE.COM."
},
{
"Value": "10 ALT3.ASPMX.L.GOOGLE.COM."
},
{
"Value": "10 ALT4.ASPMX.L.GOOGLE.COM."
}
]
},
{
"Name": "fortimonitor.forticloud.com.",
"Type": "NS",
"TTL": 172800,
"ResourceRecords": [
{
"Value": "ns-1673.awsdns-17.co.uk."
},
{
"Value": "ns-951.awsdns-54.net."
},
{
"Value": "ns-1494.awsdns-58.org."
},
{
"Value": "ns-291.awsdns-36.com."
},
{
"Value": "ns-cloud-a1.googledomains.com."
},
{
"Value": "ns-cloud-a2.googledomains.com."
},
{
"Value": "ns-cloud-a3.googledomains.com."
},
{
"Value": "ns-cloud-a4.googledomains.com."
}
]
},
{
"Name": "fortimonitor.forticloud.com.",
"Type": "SOA",
"TTL": 900,
"ResourceRecords": [
{
"Value": "ns-1673.awsdns-17.co.uk. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400"
}
]
},
{
"Name": "fortimonitor.forticloud.com.",
"Type": "TXT",
"TTL": 1800,
"ResourceRecords": [
{
"Value": "\"v=spf1 include:_spf.google.com include:sendgrid.net include:spf.sendinblue.com -all\""
}
]
},
{
"Name": "_dmarc.fortimonitor.forticloud.com.",
"Type": "TXT",
"TTL": 300,
"ResourceRecords": [
{
"Value": "\"v=DMARC1;p=none;rua=mailto:dmarc-rep@fortimonitor.forticloud.com;ruf=mailto:dmarc-rep@fortimonitor.forticloud.com;rf=afrf;pct=100\""
}
]
},
{
"Name": "s1._domainkey.fortimonitor.forticloud.com.",
"Type": "CNAME",
"TTL": 43200,
"ResourceRecords": [
{
"Value": "s1.domainkey.u4898203.wl204.sendgrid.net"
}
]
},
{
"Name": "s2._domainkey.fortimonitor.forticloud.com.",
"Type": "CNAME",
"TTL": 43200,
"ResourceRecords": [
{
"Value": "s2.domainkey.u4898203.wl204.sendgrid.net"
}
]
},
{
"Name": "api.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "35.186.205.228"
}
]
},
{
"Name": "dashboards.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "35.190.9.16"
}
]
},
{
"Name": "docs.fortimonitor.forticloud.com.",
"Type": "CNAME",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "packages.monitorengine.com"
}
]
},
{
"Name": "em9369.fortimonitor.forticloud.com.",
"Type": "CNAME",
"TTL": 43200,
"ResourceRecords": [
{
"Value": "u4898203.wl204.sendgrid.net"
}
]
},
{
"Name": "infra.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "35.186.227.87"
}
]
},
{
"Name": "rx.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "34.117.119.251"
}
]
},
{
"Name": "screenshots.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "107.178.244.214"
}
]
},
{
"Name": "status.fortimonitor.forticloud.com.",
"Type": "A",
"TTL": 3600,
"ResourceRecords": [
{
"Value": "35.190.10.70"
}
]
}
]
}