Don’t Let Working Remotely Turn Your Life Into Hell

I must warn you, the story you are going to read contains as much horror as the Stephen King books.

A friend of mine got a job during the pandemic. He thought it was a great opportunity because the company he started with was his dream company and he was afraid to make a mistake. He wrote to me via Whatsapp so as not to forget the VPN access password and username they used. Since I was wondering whether it would be possible, I typed the password and username into the company’s system and tried it. Bumm… I was inside! They did not take a second security measure. 

Although I was wondering how there is no second security measure in such a large company working internationally, what I was more curious about was what else I could access. I was able to access all of their systems and reach the e-mail addresses of other users. After ending this little adventure, I started to see what malicious people could do. As I thought about it, I realized that the data could be sold. When I thought about who would buy it even if I sell it, this time Dark Web came to my mind. The situation was getting more interesting, so I reached out to an IT expert working in the same company through my friend and told him that I heard that they only use a password as a security measure. The IT expert said that they are doing research to take additional security measures and are aware of the danger of the current situation. Even though I couldn’t say they were not aware enough, I wished them luck and did my part.

Is This Your Employee or Someone Else ?

After authentication with the username and password in VPN access, the user becomes able to access all the data of the company. From this point on, while company personnel provide their daily tasks with remote access, malicious people who introduce themselves as authorized persons start stealing, leaking or selling company data. They do this by capturing or cracking user passwords. What we need to do is to make the passwords we use hard to capture or to stop using passwords.

