Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

71–80 of 125 posts

Re: Phpfog "Down for maintenance"

#71
post #69

Earlier quoted context omitted.

On a relative scale? Yes, wiping the system is much worse. On an absolute scale? They're both still bad: the lesser of two evils is still an evil. ;) http://en.wikipedia.org/wiki/False_dilemma

I never claimed what I did was a good thing.

Well, in your original post you said: "I don't consider what I did to be a bad thing."

So if you don't consider your actions to be bad or good, that means you think they're neutral? ;-)

Re: Phpfog "Down for maintenance"

#72
post #49

Earlier quoted context omitted.

Did you not RTFA? The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2.

Whats up with the attitude? Seriously. The arrogance and self righteousness on HN is ridiculous sometimes and really kills the conversation. To your point though no i didnt read the article because there was so much noise between it and the flamewar going on here that it was difficult to figure out what was even going on. However, to quote you, "The article is about a PHP hosting company that is getting merc'd becaus…

PHP is just as secure as any other language. It's the programmer's best practices (or lack of) and implementation that can make the code secure or insecure. The language is mature, actively maintained, and has a nice standard lib (debatable). Whether or not YOUR program will be secure depends on you the PROGRAMMER not the language.

Re: Phpfog "Down for maintenance"

#73
post #60

Earlier quoted context omitted.

I would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

It's not like your two options were either wipe the box or take over their twitter account.

A responsible pen-tester would have reported the issue privately and disclosed it publicly at a later date.

Take a look here for a protocol to follow in future http://www.wiretrip.net/rfp/policy.html

Re: Phpfog "Down for maintenance"

#74
post #71

Earlier quoted context omitted.

I never claimed what I did was a good thing.

Well, in your original post you said: "I don't consider what I did to be a bad thing." So if you don't consider your actions to be bad or good, that means you think they're neutral? ;-)

No.

I 'think' what I did was a relatively good thing. I never claimed it was, nor would I use that sort of thing as a defence. Everything that I have a say in is under control of phpFog now, and no data was lost. Anything further is completely out of my hands, I can only do so much.

Re: Phpfog "Down for maintenance"

#75
post #68

Earlier quoted context omitted.

The website was allegedly posted before I obtained the engine code, however it then went on the site after I gave a copy of the engine code to someone in order to analyze and look for further exploits. To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The f…

Aha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience. --- Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. An…

Yes, I can explain that.

The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew.

I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a rash and irresponsible person as you can tell from that tweet.

Re: Phpfog "Down for maintenance"

#76
post #73

Earlier quoted context omitted.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

It's not like your two options were either wipe the box or take over their twitter account. A responsible pen-tester would have reported the issue privately and disclosed it publicly at a later date. Take a look here for a protocol to follow in future http://www.wiretrip.net/rfp/policy.html

Interesting. Link bookmarked for when it's not midnight, I'll definitely take a read through that. It'd be nice to have a guideline of sorts, I guess.

Re: Phpfog "Down for maintenance"

#77
post #59

Lucas notes some of the security improvements they plan on: http://help.phpfog.com/discussions/questions/84-details-on-t... 1) Every environment is going to be chrooted and Apache will be running under per-user mpm 2) The dedicated ec2 servers will be running in a way that has no security credentials of any sort, a walled garden that will not have access anywhere else.

Chroot will only delay an attacker a bit of time [1]

----

[1] http://serverfault.com/questions/19473/does-using-chroot-for...

Re: Phpfog "Down for maintenance"

#78
post #33
post #32

Even at 16, you should be mature enough to know that this is classless. I hope for their sake they never start their own business and never fuck up, because that'd be awfully sad if the next kids to come along decided to show them the same courtesy they've shown here.

This is just precious: @ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :) As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowled…

> broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal

I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime.

This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.

Re: Phpfog "Down for maintenance"

#79

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

It seems to be from one of your friends:

phpfogsucks.com is hosted with tomato.compwhizii.net:

http://sharingmyip.com/?site=phpfogsucks.com

Which is owned by John Du Hart ( http://johnduhart.me/ ) .

You guys could be in a lot of legal trouble if they decide to press charges.

Re: Phpfog "Down for maintenance"

#80
post #32

Even at 16, you should be mature enough to know that this is classless. I hope for their sake they never start their own business and never fuck up, because that'd be awfully sad if the next kids to come along decided to show them the same courtesy they've shown here.

Well said.
Post reply on HN