
From: dammitjosie— via Fulldisclosure <fulldisclosure () seclists org>
Date: Sat, 18 Feb 2023 02:42:46 +0100 (CET)
security bug: go sumologic.com (big company, many customer) make free account log in account, make access key - help.sumologic.com/docs/manage/security/access-keys/ <http://help.sumologic.com/docs/manage/security/access-keys/> download collector for windows - help.sumologic.com/docs/send-data/installed-collectors/collector-installation-reference/download-collector-from-static-url/ <http://help.sumologic.com/docs/send-data/installed-collectors/collector-installation-reference/download-collector-from-static-url/> install collector by `cmd` using access key - help.sumologic.com/docs/send-data/installed-collectors/windows/ <http://help.sumologic.com/docs/send-data/installed-collectors/windows/> ex: SumoCollector.exe -console -q "-Vsumo.accessid=<accessId>" "-Vsumo.accesskey=<accessKey>" look c:\users\(you)\appdata\local\temp\i4j_nlog_1.log accessid and accesskey in log file !! give access to whole api !!: help.sumologic.com/docs/api/ <http://help.sumologic.com/docs/api/> api.sumologic.com/docs/ <http://api.sumologic.com/docs/> _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Sumo Logic keep api credentials on endpoints dammitjosie— via Fulldisclosure (Feb 22)