php... a language by amateurs, for amateurs. phpfog... a service by amateurs, for amateurs.
for all the downvoters, it's pretty undeniable that as far as security is concerned, it was amateur hour at phpfog.
How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
91–100 of 202 posts
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#922:56:45 AM Elliot : then I used the method detailed by turby 2:56:46 AM Elliot : to gain root Has anything been said about what this method was?
1. Use the post-deploy hook to chmod /home/ubuntu/.ssh so that it could be written to.
2. Upload a PHP shell, use it to write your public key into /home/ubuntu/.ssh/authorized_keys, and get the public IP of the EC2 instance.
3. SSH into the box, sudo su will get you root.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#93I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…
Unfortunately, this situation was much more severe than your average multi-million dollar AAA gaming title being leaked before release (http://www.ea.com/crysis-2/blog/crysis-leak ), so this requires the FBI and prosecution.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#94Earlier quoted context omitted.
As soon he says "I don't believe I did a bad thing" I thought this boy needs to be prosecuted.
Personally, I'm a fan of some of his post-hoc justification: " Following this, I took a hold of their Twitter account and posted a couple of bits to draw attention to the fact. This did two things. One, it showed people the system was insecure, but on the other hand people always subconsciously root for the underdog; I drew attention to the company and the product. I know a number of people have actually registered (…
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#95I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…
I read him being very apologetic for their security shortcomings in all of the appropriate places, and only blaming delayed fixes on timing issues. He was very contrite and forthcoming about their security issues. Accountability was all over the article.
Lucas's post does not say "We screwed up." He says "We got screwed by Elliot."
I'm saddened most because Lucas is not embarrassed to point out he was outwitted by children.
When I foul up at my job I don't send an email detailing how some nasty client did something. I summarize what went wrong, how it should have been prevented and what steps I will be taking to prevent it in the future.
I would never write an email:
James Smith, a really evil customer (who happened to be working while there was thunder and lightning like Dr Frankenstein!), decided to try system("rm -fr /"). I knew it was possible, but I didn't feel like fixing it. Also I didn't feel like securing any of our other systems which explains those tweets, blog posts, DNS changes, and email compromises. I was lazy, but It's not my fault.
gg, parfe
P.S. Credit cards probably didn't get compromised. Tim the intern was the one who implemented the payment system and he had his own passwords set.
(Note: I move this comment as I replied by mistake to CGamesPlay.)
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#96Earlier quoted context omitted.
for all the downvoters, it's pretty undeniable that as far as security is concerned, it was amateur hour at phpfog.
If you wanted to get that point across, you could have said it much better. Your analogy to the PHP language itself is completely false and not in any way useful.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#97Earlier quoted context omitted.
Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…
> PHPFog built a castle out of sand and you're upset that a wave came and demolished it. Technology analogies invariably suck, but I'm pretty sure this is provably better: When a teenager smashes in a storefront window, do we say they should've had bars over it?
Depends what's behind the storefront windows.
On the other hand I can certainly agree that we stop with the technology analogies before a car analogy is let loose and someone gets hurt.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#98I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…
Yup, ruin a kids life to act as a deterrent to other kids. Fortunately this strategy has been keeping our products protected and secure for years after Valve had the FBI track that kid that leaked half-life 2's source code and put him in prison. Unfortunately, this situation was much more severe than your average multi-million dollar AAA gaming title being leaked before release ( http://www.ea.com/crysis-2/blog/crysi…
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#99Earlier quoted context omitted.
Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…
> PHPFog built a castle out of sand and you're upset that a wave came and demolished it. Technology analogies invariably suck, but I'm pretty sure this is provably better: When a teenager smashes in a storefront window, do we say they should've had bars over it?
If a storefront was under constant attack, then yes, they should have bars over it. In fact, in my hometown, there was a streak of vandalisms where kids were throwing bricks through windows. After getting hit 3 times, one store replaced their huge glass windows with smaller plexiglass ones.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#100Earlier quoted context omitted.
He could have made his point in a more intelligent way.
Just, do be aware that there are a lot of people that fit the description he gave; they are particularly numerous among the people who use the words "white hat" or "hacker" (with any modifier) in their services.
So called 'white hat hackers' tend to be fraudulent script kiddies who couldn't hack their way out of a gibs0n.
They often attend classes like this http://www.infosecinstitute.com/blog/ethical_hacking_compute... and read a book or two like this http://www.google.com/products/catalog?q=hacking+exposed&.... Some times they'll even have a sweet certification like this https://www.eccouncil.org/certification/certified_ethical_ha....
And at the end of the day all they're doing is getting the down low on your system with nmap and then going all turbo with metasploit. And if they are feeling up to a challenge they might even rip someone's exploit from milw0rm.
99% of them are frauds and the other 1% are sellouts.