Earlier quoted context omitted.
According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer. It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme." [1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new... EDIT: The quote…
They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.
Yahoo Hacked
41–50 of 258 posts
Re: Yahoo Hacked
#42Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
TIL - people still use WinZip
Re: Yahoo Hacked
#43Earlier quoted context omitted.
According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer. It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme." [1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new... EDIT: The quote…
Please read the follow up: http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the... (and HN discussion: https://news.ycombinator.com/item?id=6488897 )
Re: Yahoo Hacked
#44Earlier quoted context omitted.
Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.
> that have yielded any luck with trying to contact them regarding this Might be the important part of the quote you missed.
Re: Yahoo Hacked
#45This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
I identified that a few major sites were actually compromised using the vulnerability - Yahoo! being one in
particular. Tripod/Lycos and WinZip.com were also compromised. Yahoo! reached out and gave me a response, albeit a very
weak one, only after the FBI, media and CEO Marissa Mayers was contacted... WinZip patched their boxes and didn't
bother responding or notifying me that they got it done.
And, amusingly, an apology for his rambling:Please do excuse the scattered nature of the email sent to Marissa Mayers @ Yahoo! - there were other correspondences that are currently being kept private, and at the time that I wrote that one, I had been awake for roughly 48 hours and was fueled on caffeine and nicotine.
Re: Yahoo Hacked
#46Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?
First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf
I read that shortly after it was originally published. And I thought to myself: COOL!
I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also script the behavior of an IRC client.
At the time I was a channel operator in a relatively popular IRC channel on EFnet... "Don't ask to ask!" :) Users would come in and request assistance with malware all the time, so I was already roughly familiar with the mechanisms of infection and CnC.
This is a long story that I must cut short: I ended up in the same CnC room as Gibson did. Not the same type--the same one. I met some of the people in the story. :D
Re: Yahoo Hacked
#47Earlier quoted context omitted.
They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.
Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
Re: Yahoo Hacked
#48Re: Yahoo Hacked
#49Mirror of the response, since the site is loading really slow: http://cl.ly/image/2E3D2H2B2d2t