Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

121–125 of 125 posts

Re: Phpfog "Down for maintenance"

#121
post #99

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

Hi Elliot, I appreciate that you discovered a security flaw and took action to get it fixed. Thank you. However, the WAY you did this really screwed up a bunch of people. I have an app running on PHP Fog that serves 25,000 people a day, and I woke up on Sunday morning to a stream of complaints that it had been down for hours. You seem technically capable, so I'm sure you have a lot of interesting (and useful) project…

Unfortunately, that cyclone may not be as easy to get past. Yes, people won't forever care about phpfog. However, if phpFog (which was at least PARTIALLY at fault here) presses charges, thats a criminal record and will come up on every background check for the rest of his life. This effects job opportunities, VISA opportunities, loans (not to mention lawyer debt from fighting it), hell even insurance prices.

What the kids did was bad, but I think pressing charges and seriously hindering two smart sixteen year-olds is a knee-jerk, over-zealous application of law and retaliation/punishment. Especially (I know I'm going to draw a lot of heat for this) when they found THEIR irresponsible storage of sensitive data.

I am a dev. I have also worked in the computer security field for a reputable firm. What phpfog did was irresponsible(actually, stupid!) and it was relatively easily avoidable. I know this because I (along with pretty much every dev) have used the exact stopgaps and quick-fixes that phpFog did. BUT (big lesson) cleaning up after your self is as much a part of programming as putting those quick-fixes in place. Unfortunately, its not the "fun" part and its not the most obvious money maker.

Like they (pretty much) said, phpFog put off the fixes because they wanted to deliver quickly. Thats THEIR decision and THEIR risk/reward assessment. I've made the same assessments in my work. They should suck it up and learn the lesson. Not hurt little kids. They're lucky it was found by these kids and not someone that knows how to conceal their identities and/or wants to do more serious damage (For example, hurting a phpFog clients).

If I knew some dev at my hosting company was keeping system passwords on a web server, they wouldn't be my hosting company. What about the trust/confidence of the clients that phpFog was knowingly betraying?

Edit: Yes, there is a proper way to disclose information. They're kids. I'm surprised they handled it as well as they did to be honest. I was a much dumber 16 year old.

Re: Phpfog "Down for maintenance"

#122

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

[deleted]

Re: Phpfog "Down for maintenance"

#123
post #71

Earlier quoted context omitted.

Well, in your original post you said: "I don't consider what I did to be a bad thing." So if you don't consider your actions to be bad or good, that means you think they're neutral? ;-)

No. I 'think' what I did was a relatively good thing. I never claimed it was, nor would I use that sort of thing as a defence. Everything that I have a say in is under control of phpFog now, and no data was lost. Anything further is completely out of my hands, I can only do so much.

I think we're in danger here of arguing in circles, but let me just say that I think the mindset of "I could've done so much worse, but I showed restraint, therefore It's (relatively) okay" is very troubling to hear (and I know it's not just you that thinks this way). If you broke into a home, and only broke a few lamps and changed the locks on the doors, and then tell the homeowner "no hard feelings, I mean I could've burnt the place to the ground", you sound like a mad-man -- but because this is virtual, the impacts of your actions aren't so immediate or easy to feel, but they're still there (downtime leads to loss of consumer confidence, leads to loss of sales, leads to loss of jobs and livelihoods, and on and on). However, it doesn't mean there aren't real, financial, consequences to the actions.

I realize everyone makes mistakes, especially as teens, but I just wanted to voice my opinion that this mindset people seem to have where because they didn't {burn the server to the ground}, they shouldn't feel bad is both naive and dangerous, and if I were you, I'd do my best to drop it, learn your lesson, and move on. Best of luck.

Re: Phpfog "Down for maintenance"

#124
post #113
post #83

Earlier quoted context omitted.

Disclosing a fact? No, that's not necessarily criminal. Publicly admitting to having committed a "computer crime"? That's a different story. I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.

Exactly; as I said, "disclosing a fact without a reasonable wait" which is fair and ethical in the security world. I'm all for full disclosure, but give the affected parties time to clean up the mess and get PR ready. After berating one of the "d00ds" involved on Twitter, it looks to me like he told his friend how to exploit the problem, and his friend (or his friend's friend) made the site and exploited the hole. If…

FYI, when I found about an open ASP.NET padding oracle at Subway.com, all I did was to run PadBuster to exploit it without damaging the servers in any other way. Eventually I reported it to feedback@subway.com, and only after a week of no response only then I finally posted it to reddit: http://www.reddit.com/r/netsec/comments/g9crj/open_aspnet_pa...

Re: Phpfog "Down for maintenance"

#125
post #49
post #41

Earlier quoted context omitted.

Did you RTFA? This had nothing to do with php.

Did you not RTFA? The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2.

Thanks for the downvotes, I'll take them on board
Post reply on HN