Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

101–110 of 125 posts

Re: Phpfog "Down for maintenance"

#101
post #34
post #31

Not the first "you've been pwned" message on the Internet and won't be the last. It just happens to be the first I've seen use Google Analytics to track the lulz with CSS and @font-face. With that layout I was expecting to see a customer rant, not a "pwned" message. On a more serious note are they going to be able to afford to have a separate EC2 instance per customer to avoid having to write a proper sandbox?

After serious reputation damage… will they still have customers?

They're still in beta and they got back online ridiculously quickly considering what happened. I've been happy with them since day 1.

Re: Phpfog "Down for maintenance"

#102
post #72

Earlier quoted context omitted.

Whats up with the attitude? Seriously. The arrogance and self righteousness on HN is ridiculous sometimes and really kills the conversation. To your point though no i didnt read the article because there was so much noise between it and the flamewar going on here that it was difficult to figure out what was even going on. However, to quote you, "The article is about a PHP hosting company that is getting merc'd becaus…

PHP is just as secure as any other language. It's the programmer's best practices (or lack of) and implementation that can make the code secure or insecure. The language is mature, actively maintained, and has a nice standard lib (debatable). Whether or not YOUR program will be secure depends on you the PROGRAMMER not the language.

PHP is, by no means, just as secure as any other language. It has a horrid security track record when compared to any other language.

Re: Phpfog "Down for maintenance"

#103
post #78
post #33

Earlier quoted context omitted.

This is just precious: @ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :) As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowled…

> broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime. This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.

I think this is a Federal Crime in the US. If he was an idiot and actually disclosed his details, they can find him and actually extradite him from Australia for this.... not a lawyer but wow, but he did not think this one through

Re: Phpfog "Down for maintenance"

#104

Earlier quoted context omitted.

http://twitter.com/compwhizii/status/48172082667864065 (I had to create a different account because I have no_procrast activated on my main account. It'd be awesome if no_procrast would be automatically disabled during the weekend.)

During which weekend? For my new place of work that would be on Friday & Saturday.. (Just a quick note that some features are harder than it seems at first)

I realize that it's harder than it looks. However, it would be trivial to allow people to choose the days they don't want the procrastination setting enabled (based on a standard timezone like PST.)

Re: Phpfog "Down for maintenance"

#105

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

Dude, are you aware that this is a federal crime in the US? They have extradition treaties with AUS. You need to get your parents to get you a lawyer - FAST

Re: Phpfog "Down for maintenance"

#106
post #68

Earlier quoted context omitted.

Aha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience. --- Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. An…

Yes, I can explain that. The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew. I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a r…

Get a lawyer dude - FAST

Re: Phpfog "Down for maintenance"

#107
Actually, I'm going to go sign up for an invite over at phpfog... it looks like something I could make real use of. In a way, this incident may turn out to be a boon for the folks over there.

Re: Phpfog "Down for maintenance"

#108

Earlier quoted context omitted.

If they use reserved instances, it should be even less than that. They still need to control abuse in terms of bandwidth, etc. and that is the difficult part.

It should be easy enough to throttle bandwidth on the instances.

As far as I know that cannot be done with standard Amazon tools

Re: Phpfog "Down for maintenance"

#109

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

"It's better me break in and make the fact I did public, than someone break in silently and wipe the box, losing hundreds of hours of both the team's and clients' time." It's better yet to break in and discreetly notify the folks involved. Show a screenshot at Twitter.com that you COULD have tweeted. Voila-- you've done something positive. Going public is an immature ego play that doesn't consider the feelings of lot…

[deleted]

Re: Phpfog "Down for maintenance"

#110

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

I see: "I was proving that the system was horribly exploitable." but I read: "I was exploiting a horribly exploitable system that, had I notified the admins, almost certainly would have been dealt with fast by some guys who obviously care about their service. If it wasn't, I could have still released it publicly a few days later like every other pen tester anywhere. Instead I went for the lulz. Now I'm backpedaling b…

[deleted]
Post reply on HN