Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

81–90 of 125 posts

Re: Phpfog "Down for maintenance"

#81
post #60

Earlier quoted context omitted.

I would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

One thing you should probably watch out for in all this is that you've used your real name and your website is personally identifiable. Depending on the Laws in your jurisdiction, what you've done (getting root on the phpfog server and accessing their twitter account) could be a criminal offence.

Indeed a quick look at Queenslands Cybercrime laws shows up

"The Queensland law introduced in 1997 uses the heading 'computer hacking and misuse' but the offence is defined as the use of a restricted computer without the consent of the computer's controller. A restricted computer is defined as one that requires a 'device, code or sequence of electronic impulses' to gain access. There is a penalty scale of two, five or 10 years maximum term of imprisonment depending on whether (1) an offender simply uses a computer, (2) causes detriment or damage, or gains or intends to gain a benefit, or (3) the detriment, damage or gain is valued at more than $5,000."

Re: Phpfog "Down for maintenance"

#82

Earlier quoted context omitted.

Would you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lu…

Would you rather that I hadn't, and instead just wiped the box? We would prefer if you had done neither. This is a false dichotomy. You know it is. Feigned ignorance is the lowest form of intellectual dishonesty.

> You know it is

Don't forget that he is a 16 year old brat.

Re: Phpfog "Down for maintenance"

#83
post #78
post #33

Earlier quoted context omitted.

This is just precious: @ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :) As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowled…

> broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime. This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.

Disclosing a fact? No, that's not necessarily criminal.

Publicly admitting to having committed a "computer crime"? That's a different story.

I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.

Re: Phpfog "Down for maintenance"

#85
Anyone actually read the exploit? This is not so much hacking as it is PHPFog being extraordinarily stupid. The fact is that such an obvious vulnerability (that I'm sure many of their experience customers have noticed) went ignored by the PHPFog team.

The phpfogsucks site is tasteless and mean spirited, but it is good information to have for potential PHPFog customers that the service they are shipping their valuable code too is extremely poorly managed.

Re: Phpfog "Down for maintenance"

#86

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

I think the takeaway that you should have from this is; the person you showed this exploit to is not trustworthy, I'd avoid associating with them in the future.

Re: Phpfog "Down for maintenance"

#87
post #68

Earlier quoted context omitted.

Aha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience. --- Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. An…

Yes, I can explain that. The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew. I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a r…

Yeah, except you posted the links on facepunch, in this post: http://www.facepunch.com/threads/1070158-phpfog-it-s-like-he... before you edited and removed it.

Re: Phpfog "Down for maintenance"

#88
post #72

Earlier quoted context omitted.

Whats up with the attitude? Seriously. The arrogance and self righteousness on HN is ridiculous sometimes and really kills the conversation. To your point though no i didnt read the article because there was so much noise between it and the flamewar going on here that it was difficult to figure out what was even going on. However, to quote you, "The article is about a PHP hosting company that is getting merc'd becaus…

PHP is just as secure as any other language. It's the programmer's best practices (or lack of) and implementation that can make the code secure or insecure. The language is mature, actively maintained, and has a nice standard lib (debatable). Whether or not YOUR program will be secure depends on you the PROGRAMMER not the language.

So does that mean ec2 is insecure? Or is the flamewar about how the article is really about the writer blaming their problems on something thats really not at fault. Meaning php or ec2?

Thanks!

Re: Phpfog "Down for maintenance"

#89
post #68

Earlier quoted context omitted.

Aha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience. --- Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. An…

Yes, I can explain that. The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew. I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a r…

By your own admission you:

1) Hacked PHPFog.

2) Stole their source code and distributed it to others.

3) Unlawfully accessed and defaced their Twitter account.

Yes, you're clever, but your behavior is "rash and irresponsible." If I were you, I'd be on the phone with Lucas apologizing and getting ready for some community service.

Re: Phpfog "Down for maintenance"

#90
post #49
post #41

Earlier quoted context omitted.

Did you RTFA? This had nothing to do with php.

Did you not RTFA? The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2.

The exploit was not anything to do with PHP. A section of their site was allowing to users to execute commands under a user which they should not have been allowed to. This could have happened under any programming language.
Post reply on HN