Live data from Hacker News

Tell HN: Whole Yandex Git repository leaked

news.ycombinator.com

51–60 of 369 posts

Re: Tell HN: Whole Yandex Git repository leaked

#51
post #19
post #16

Earlier quoted context omitted.

When you're judging them, think about the space of possibilities as well. Is any example of a Russian business of such volume not tied to the government?

I mean they were pretty much forced to sell business to the government recently. Coincidence? Maybe…

what business and to what government? are you in your dreams?

Re: Tell HN: Whole Yandex Git repository leaked

#52
post #23

Yandex reverse image search is very good. I use it more than tineye, bing, or goog. It either gives you the exact matches if it can find them, or else it can infer what is desired and show many similar matches.

It's also unexpectedly good at finding the original full images from cropped versions.

Re: Tell HN: Whole Yandex Git repository leaked

#53

Can anyone confirm there's nothing obviously malicious implanted in the code and they are legit?

Why on earth would you execute anything from the dump?

Well there was a critical git RCE less than 7 days ago that could be triggered by cloning a malicious repo so you might not have to execute anything to get owned

Re: Tell HN: Whole Yandex Git repository leaked

#55
They use p0f for TCP fingerprinting in their nginx config :)

Edit: Cool spam factors in extsearch/robot/index/metadoc/lib/links/spam_factors.h:

    SF_WEB_HOST_RANK = 0,
    SF_GREEN_TRAFFIC_SHARE_NORMALIZED = 1,
    SF_ADULTNESS_BETA = 2,
    SF_NOT_FOUND_RANKS = 3,
    SF_RANK_DOOR_TUMBLR = 4,
    SF_NASTY_CONTENT = 5,
    SF_LANGUAGE = 6,
    SF_IS_SHOP = 7,
    SF_WEB_HOST_SIZE = 8,
    SF_RANK_HACKED_NOVA_PHP = 9,
    SF_IS_FOREIGN_HOST = 10,
    SF_PESS_LEVEL = 11,
    SF_SPAMNESS = 12,
    SF_NASTY_HOST = 13,
    SF_MORE_120SEC_VISITS_SHARE = 14,
    SF_GREEN_TRAFF_SHARE_CORRECT = 15,
    SF_RESERVED_16 = 16,
    SF_WEB_RANDOM_LOG_HOST_ERRATUM_LOG_QUERY_PROBABILITY_AVG = 17,
    SF_RESERVED_18 = 18,
    SF_WEB_VISITORS_RETURN_MONTH_SHARE = 19,
    SF_WEB_RANDOM_LOG_HOST_SYNT_QUALITY_AVG = 20,
    SF_WEB_RU_TRAFF_SHARE = 21,
    SF_RESERVED_22 = 22,
    SF_RESERVED_23 = 23,
    SF_RESERVED_24 = 24,
    SF_RESERVED_25 = 25,
    SF_WEB_MORE_160_VISITORS_SHARE = 26,
    SF_RESERVED_27 = 27,
    SF_RESERVED_28 = 28,
    SF_WEB_TOUCH_WIFI_TRAFF_SHARE = 29,
    SF_WEB_LOG_CTR_MEAN = 30,
    SF_RESERVED_31 = 31,
    SF_RESERVED_32 = 32,
    SF_SPAM_FORMULA_MEDIAN = 33,
    SF_AVG_GEOV_SQ = 34,
    SF_AVG_TH3973_SQ = 35,
    SF_RUS_DOCS_COUNT = 36,
    SF_AVG_SKACHKI_SOFT_FIX = 37,
    SF_RANK_MFA_RU_42 = 38,
    SF_DEV_PFC_TOTAL_LINKS = 39,
    SF_RANK_DOOR2_2 = 40,
    SF_AVG_QC_1 = 41,
    SF_QUERIES_CHAR_LEN = 42,
    SF_HOST_IMG_CLICKS = 43,
    SF_AVG_DOORWAY_BIGWEIGHT_NORM = 44,
    SF_AVG_QS_FTOP_FREQ_IN_ARATIO = 45,
    SF_HOST_RANK = 46,
    SF_AVG_TITLE_CAPITAL_LETTERS_RATIO = 47,
    SF_RANK_COMM_GOODNESS_UA = 48,
    SF_YABAR_AVG_URL_LEN = 49,
    SF_MAX_OWNER_QS_RANK = 50,
    SF_DIFF_MAX_QS_RANK_ON_NUMHOPS_255 = 51,
    SF_YABAR_SEARCH_VIS_AVG_DEPTH = 52,
    SF_AVG_QS_F_WND_500_NOFILTER = 53,
    SF_QUERIES_WORD_LEN = 54,
    SF_RANK_UNBAN_MX2 = 55,
    SF_AVG_QS_F_PARA_WORDS_REQ_SQRT_MAX_OF_SUM_WORD_WEIGHT = 56,
    SF_RANK_ASESSOR_GOODNESS_RELATIVE = 57,
    SF_RANK_COMM_BAR_GOODNESS_SITE = 58,
    SF_QUERIES_AVG_TEXT = 59,
    SF_MIN_QS_DOC_CLASS_QS_RANK_PTH_QUERY_SPAM = 60,
    SF_SERP_CLICKS_BY_SLASH_PART_2_30 = 61,
    SF_MAX_QS_DOC_CLASS_QS_RANK_PTH_QUERY_SPAM = 62,
    SF_RANK_COMM3 = 63,
    SF_DEV_QS_F_PUNCT_BLANKS_RAT = 64,
    SF_RANK_UNBAN_MX = 65,
    SF_FROM_SEARCH_SHARE_NORMALIZED = 66,
    SF_RANK_XIT_DOOR = 67,
    SF_AVG_QS_RANK_ON_NOT_SUBDOMAINS_DOCS = 68,
    SF_AVG_OWNER_QS_RANK = 69,
    SF_HOST_CLIPART_IMAGE_COUNT = 70,
    SF_RANK_HACKED_NOVA2 = 71,
    SF_WEB_RANDOM_LOG_HOST_QI_QUERY_COUNT_AVG = 72,
    SF_WEB_COMM_LINKS_HOST_CEO = 73,
    SF_WEB_YABAR_HOST_AVG_TIME2 = 74,
    SF_LINK_IN_SEO_PART = 75,
    SF_LAST_PESS_TIME = 76,
    SF_WEB_OWNER_MEAN_RELEV_MX = 77,
    SF_NASTY_URL = 78,
    SF_PAGE_RANK = 79,
    SF_HAS_MAIN_CONTENT = 80,
    SF_AVG_SPAM = 81,
    SF_RANK_ARTROZ = 82,
    SF_RANK_AGS4 = 83,
    SF_AVG_NUM_HOPS = 84,
    SF_MIN_OWNER_QS_RANK = 85,
    SF_FROM_SEARCH_SHARE_YA_BRO = 86,
    SF_OWNER_MEAN_RELEV = 87,
    SF_HOST_FACE_IMAGE_COUNT = 88,

Re: Tell HN: Whole Yandex Git repository leaked

#57
post #43

Earlier quoted context omitted.

It's not about whether it applies, but whether there is any will to enforce it. Would the US government cooperate in the indictment and prosecution of a US citizen, on behalf of a de-facto enemy nation, for a company that has ties and is allegedly controlled by the government of said nation?

it's not criminal law, yandex can hire a lawyer in the US

But could they find a judge/jury sympathetic to any Russian concerns?

Re: Tell HN: Whole Yandex Git repository leaked

#58

Anyone have insight what “skynet.tar.bz2” is?!

Skynet is a command execution and metric collection layer used in basic cluster ops. Nothing cool to be honest. Essentially it allows you to run a command on all the hosts matching a predicate.

This was the easiest way to disrupt a whole datacenter for those who had enough privileges, I did it at least once. Also several times unnoticed bugs in my code shut down literally everything for noticeable periods of time. I've been developing the search orchestration system.

Re: Tell HN: Whole Yandex Git repository leaked

#60

What are the short-term and long-term implications of this? I assume a drastically increased attack surface and potentially a boon for open-source development? Anything else?

Probably Yandex will start watching their infrastructure very closely, and go through all known attack vectors that haven't been prioritized before to fix them ASAP. Won't be a boon for OSS, any author would be idiotic to read stolen source code and then decide to create a OSS library/project based on what they learn from it.

> Won't be a boon for OSS, any author would be idiotic to read stolen source code and then decide to create a OSS library/project based on what they learn from it.

This is naive. This generation seems very sensitive to the prospect of computer crime.

The stolen source code will almost certainly be read, and if deemed novel enough will be turned into open source projects. It may be tough to figure out those projects are derivatives of stolen code, but most likely they will be passed around in black market repos.

I looked through some of my telegram channels to see if anything has been posted yet. Lo and behold, the stolen files are in fact available… from a server in Ukraine.

Post reply on HN