<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain! in Apps and SPoT</title>
    <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22094#M211</link>
    <description>&lt;P style="margin: 0;"&gt;Hi Robert. We are aware of this issue and fixing it.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 23:39:17 GMT</pubDate>
    <dc:creator>arsalan_habib</dc:creator>
    <dc:date>2021-02-01T23:39:17Z</dc:date>
    <item>
      <title>Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain!</title>
      <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22092#M209</link>
      <description>&lt;P style="margin: 0;"&gt;When I send an invitation thru the Ruckus Unleashed App (Android), the links the App sends starts like this:&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;http://unleasheddev.com/bmM9dW40MjE4MDIwMDU5[redacted]&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;It looks to me like the invitations created points to a site no longer under Ruckus control.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;BR /&gt;Have you been hacked or just allowed a domain to expire, letting someone else take over?&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;That site could register all clicks on links in invitations, &lt;STRONG&gt;including the GUID that should be a secret&lt;/STRONG&gt;!&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Looks to me like a MAJOR security issue. Will you look into it?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 18:34:19 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22092#M209</guid>
      <dc:creator>robert_winther</dc:creator>
      <dc:date>2021-02-01T18:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain!</title>
      <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22093#M210</link>
      <description>&lt;DIV data-cannedresponseid="" style="text-align: center;"&gt;Screendump from site the invitation mail links to:&lt;/DIV&gt;
&lt;DIV data-cannedresponseid="" style="text-align: center;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_601849d95f25f97dd176355e_b92927a868cef6618b7aa1560255a33c_Ruckussecurity-5fa84a39-003b-4731-87a1-0aab479ff760-768575644.jpg"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2148i764962AA0C00A0BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_601849d95f25f97dd176355e_b92927a868cef6618b7aa1560255a33c_Ruckussecurity-5fa84a39-003b-4731-87a1-0aab479ff760-768575644.jpg" alt="Image_ images_messages_601849d95f25f97dd176355e_b92927a868cef6618b7aa1560255a33c_Ruckussecurity-5fa84a39-003b-4731-87a1-0aab479ff760-768575644.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 18:35:05 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22093#M210</guid>
      <dc:creator>robert_winther</dc:creator>
      <dc:date>2021-02-01T18:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain!</title>
      <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22094#M211</link>
      <description>&lt;P style="margin: 0;"&gt;Hi Robert. We are aware of this issue and fixing it.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 23:39:17 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22094#M211</guid>
      <dc:creator>arsalan_habib</dc:creator>
      <dc:date>2021-02-01T23:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain!</title>
      <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22095#M212</link>
      <description>&lt;P style="margin: 0;"&gt;Thank you for the update.&lt;BR /&gt;&lt;BR /&gt;Should we worry about the invitations we have already sent? &lt;BR /&gt;&lt;BR /&gt;If the &lt;SPAN&gt;unleasheddev.com domain is not under your control, every request could have been logged.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 16:54:00 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22095#M212</guid>
      <dc:creator>robert_winther</dc:creator>
      <dc:date>2021-02-02T16:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Ruckus hacked or domain expired? Invite for Remote Management contains link to 
strange domain!</title>
      <link>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22096#M213</link>
      <description>&lt;P style="margin: 0;"&gt;Hi Robert, the invites by themselves do not expose any information. The app knows how to get the required information from it.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;By the way with this invite on Android you will see a prompt to either open it on the browser or the Unleashed mobile app. When the user selects Mobile App, the Mobile App opens and gets access to this link. In this case this link is not hit at all.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 01:52:07 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Apps-and-SPoT/Ruckus-hacked-or-domain-expired-Invite-for-Remote-Management/m-p/22096#M213</guid>
      <dc:creator>arsalan_habib</dc:creator>
      <dc:date>2021-02-03T01:52:07Z</dc:date>
    </item>
  </channel>
</rss>

