Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

61–70 of 125 posts

Re: Phpfog "Down for maintenance"

#61
post #60

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

I would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.

Would you rather that I hadn't, and instead just wiped the box?

How about I changed every DNS record for every domain to something like goatse.cx?

In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lucas about an hour later.

Re: Phpfog "Down for maintenance"

#62
post #60

Earlier quoted context omitted.

I would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

That's a false dichotomy. You didn't have to post on their Twitter account, just like you didn't have to wipe a box or alter DNS. I hope if you learn one thing from this, it's how real responsible disclosure works.

Re: Phpfog "Down for maintenance"

#63

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

So, just to clear something up: those links to PHPFog code are dumps that you leaked to a third party, who then posted up this website?

Re: Phpfog "Down for maintenance"

#64
post #63

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

So, just to clear something up: those links to PHPFog code are dumps that you leaked to a third party, who then posted up this website?

The website was allegedly posted before I obtained the engine code, however it then went on the site after I gave a copy of the engine code to someone in order to analyze and look for further exploits.

To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The files were destroyed from the server after.

Re: Phpfog "Down for maintenance"

#65
post #62

Earlier quoted context omitted.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

That's a false dichotomy. You didn't have to post on their Twitter account, just like you didn't have to wipe a box or alter DNS. I hope if you learn one thing from this, it's how real responsible disclosure works.

I didn't have to at all, correct. But like you said, one doesn't have to wipe the box or redirect everything to goatse, however if you give many people the ability, there will be 10% who will do it. In perspective, me posting on the Twitter account (which was easily remedied, and like I said control was willingly relinquished) wasn't much of a bad thing.

Re: Phpfog "Down for maintenance"

#66
post #60

Earlier quoted context omitted.

I would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

Would you rather that I hadn't, and instead just wiped the box?

We would prefer if you had done neither.

This is a false dichotomy. You know it is. Feigned ignorance is the lowest form of intellectual dishonesty.

Re: Phpfog "Down for maintenance"

#67
post #49
post #41

Earlier quoted context omitted.

Did you RTFA? This had nothing to do with php.

Did you not RTFA? The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2.

Whats up with the attitude? Seriously. The arrogance and self righteousness on HN is ridiculous sometimes and really kills the conversation.

To your point though no i didnt read the article because there was so much noise between it and the flamewar going on here that it was difficult to figure out what was even going on. However, to quote you, "The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2."

Ya wasnt that the question i just asked? Seriously maybe you should read the question before just downvoting it and replying with no reply. My question was actually a serious question. I want to know if there are security flaws in php as i am looking at it for a few projects and would like to know if there are issues with it before i start them.

Re: Phpfog "Down for maintenance"

#68
post #63

Earlier quoted context omitted.

So, just to clear something up: those links to PHPFog code are dumps that you leaked to a third party, who then posted up this website?

The website was allegedly posted before I obtained the engine code, however it then went on the site after I gave a copy of the engine code to someone in order to analyze and look for further exploits. To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The f…

Aha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience.

---

Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The files were destroyed from the server after."

If that's the case, then mind explaining this?

https://twitter.com/#!/communistcake/status/4934029867707596...

Re: Phpfog "Down for maintenance"

#69
post #62

Earlier quoted context omitted.

That's a false dichotomy. You didn't have to post on their Twitter account, just like you didn't have to wipe a box or alter DNS. I hope if you learn one thing from this, it's how real responsible disclosure works.

I didn't have to at all, correct. But like you said, one doesn't have to wipe the box or redirect everything to goatse, however if you give many people the ability, there will be 10% who will do it. In perspective, me posting on the Twitter account (which was easily remedied, and like I said control was willingly relinquished) wasn't much of a bad thing.

On a relative scale? Yes, wiping the system is much worse.

On an absolute scale? They're both still bad: the lesser of two evils is still an evil. ;)

http://en.wikipedia.org/wiki/False_dilemma

Re: Phpfog "Down for maintenance"

#70
post #69

Earlier quoted context omitted.

I didn't have to at all, correct. But like you said, one doesn't have to wipe the box or redirect everything to goatse, however if you give many people the ability, there will be 10% who will do it. In perspective, me posting on the Twitter account (which was easily remedied, and like I said control was willingly relinquished) wasn't much of a bad thing.

On a relative scale? Yes, wiping the system is much worse. On an absolute scale? They're both still bad: the lesser of two evils is still an evil. ;) http://en.wikipedia.org/wiki/False_dilemma

I never claimed what I did was a good thing.
Post reply on HN