Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It seems to me to get the attack going the attackers needed to accomplish 2 things (at least):

1. Get the source-code of SolarWinds.Orion.Core.BusinessLayer.dll so they could know how to modify it

2. Get their modified source OR modified compiled DLL somehow into the build-pipeline at SolarWinds.

If SolarWinds could have prevented either of these two things from happening this attack would not have worked. Am I correct?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: