• Cort@lemmy.world
    link
    fedilink
    arrow-up
    6
    ·
    4 hours ago

    Did you not read the part about n++ not changing/rotating credentials? I think there’s enough blame to go around.

    • PM_Your_Nudes_Please@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      54 minutes ago

      They also weren’t doing any kind of SSL verification for the download request, nor were they doing any kind of hash verification or signing. The former would have prevented a redirect attack in the first place, and the latter would have prevented downloaded files from being modified or swapped out.