He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.
Yahoo Hacked
21–30 of 258 posts
Re: Yahoo Hacked
#22Re: Yahoo Hacked
#23This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
> I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough.
> This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have deemed as an improper response, or lack thereof ...
Seems pretty straight forward: hackers have already downloaded all the personal data out of these organizations and are probably using it in ways harmful to the general public already. This guy is forgoing his probable bug bounty payouts as this is, as he says, a really serious issue.
Thank you to him!
Re: Yahoo Hacked
#24This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
Re: Yahoo Hacked
#25Re: Yahoo Hacked
#26Re: Yahoo Hacked
#27This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
"Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.
It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme."
[1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new...
EDIT: The quote previously included "Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise." but I moved it here as it caused confusion regarding which issue the article was referencing.
Re: Yahoo Hacked
#28Is this a new phenomenon? I always felt that Yahoo's systems weren't secure. Until I shut down my Yahoo accounts, it would be a semi-regular occurrence for both my Yahoo email and IM to send out spam to everyone in my Yahoo contacts list. Am I wrong? I've since shut down my account since I got sick of dealing with it.
That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.
Re: Yahoo Hacked
#29Earlier quoted context omitted.
That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.
To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.
Re: Yahoo Hacked
#30All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI.
They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available.
Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd.
I wonder if they still have them.