Accellion Attack Involved Extensive Reverse Engineering
"Let’s move off this platform as soon as possible." In the case of Accellions FTA, reverse engineering enabled attackers to drop a web shell - a script that enables remote execution of commands - onto any server running the FTA software, according to FireEyes Mandiant incident response group, which Accellion hired to investigate. The web shell allowed attackers to bypass authentication, remotely execute code on the vulnerable systems and steal data. In at least some cases, stolen data ende...
Source: bankinfosecurity.com