Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

51–60 of 258 posts

Re: Yahoo Hacked

#51

Earlier quoted context omitted.

I think the "that have yielded any luck" part of that quote is pretty important.

The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?

Pretty sure that if he's actually talking with Yahoo and the FBI then someone would have pointed him to that address if he really hadn't found it himself! More likely, they just told him "hang on, we'll look into this.. eventually" and he felt this was important enough that a delay like that is unacceptable. Which it is. If you know you've just lost all your customers data, you don't wait a few days to tell them - you schedule a press release for same day release.

Re: Yahoo Hacked

#52
post #21

This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

[deleted]

Re: Yahoo Hacked

#53
post #41

Earlier quoted context omitted.

They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.

Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.

Yes, the market for security vulnerabilities is essentially a protection racket, and everyone knows it.

Re: Yahoo Hacked

#54
post #41

Earlier quoted context omitted.

Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.

This has nothing to do with "protection racket" and downvoters are going to be in for one hell of a reality check if you don't believe that this will happen. Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?

I frankly don't believe you. I think you vastly overestimate how much you can sell a vulnerability for and vastly underestimate the morals of white hat hackers reporting bugs for a bounty.

There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.

Re: Yahoo Hacked

#55
post #30

Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.

I think therein lies the problem: yapache. It's their own version of (modified) Apache. So when these bugs like shellshock come out, it's harder to patch your own home-grown version.

Re: Yahoo Hacked

#56
post #41

Earlier quoted context omitted.

They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.

Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.

I'd say: "Are these people concerned with receiving income for difficult, highly specialized, valuable work, or are they running a charity?" I guess it's a matter of perspective.

Re: Yahoo Hacked

#57

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

The OP will go to prison? Seems a bit hyperbolic to me, without any sort of citation or basis for belief.

Re: Yahoo Hacked

#58

Earlier quoted context omitted.

To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.

Could also be password guessing; lots of people use the "common word + number" pattern for their Yahoo! passwords.

If I remember correctly it was a random alpha-numeric password with both different cases and a special character or two, and I've never used the same password on a different service.

All I know is that I've never had this problem on competing services.

Re: Yahoo Hacked

#59
post #3

This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".

In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…

Well, mostly because if it was good enough, it would be the first thing out of the mouth of every blackhat that was caught...

Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen. If the company being contacted does not personally know the person contacting them, it is not altogether unreasonable to treat the person with great suspicion.

That said, people that do have a public reputation for white-hat work probably deserve to get a pass. This of course raises the question of how you go about getting a whitehat reputation, because most whitehats get their rep by doing the same things the blackhats do, without the profit motive.

Re: Yahoo Hacked

#60

Earlier quoted context omitted.

To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.

Another possible explanation is password reuse on a site that was breached.

I don't reuse my passwords.
Post reply on HN