Earlier quoted context omitted.
I think the "that have yielded any luck" part of that quote is pretty important.
The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?
Yahoo Hacked
51–60 of 258 posts
Re: Yahoo Hacked
#52This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.
Re: Yahoo Hacked
#53Earlier quoted context omitted.
They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.
Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
Re: Yahoo Hacked
#54Earlier quoted context omitted.
Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
This has nothing to do with "protection racket" and downvoters are going to be in for one hell of a reality check if you don't believe that this will happen. Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.
Re: Yahoo Hacked
#55Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.
Re: Yahoo Hacked
#56Earlier quoted context omitted.
They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.
Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
Re: Yahoo Hacked
#57Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
Re: Yahoo Hacked
#58Earlier quoted context omitted.
To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.
Could also be password guessing; lots of people use the "common word + number" pattern for their Yahoo! passwords.
All I know is that I've never had this problem on competing services.
Re: Yahoo Hacked
#59This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".
In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…
Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen. If the company being contacted does not personally know the person contacting them, it is not altogether unreasonable to treat the person with great suspicion.
That said, people that do have a public reputation for white-hat work probably deserve to get a pass. This of course raises the question of how you go about getting a whitehat reputation, because most whitehats get their rep by doing the same things the blackhats do, without the profit motive.
Re: Yahoo Hacked
#60Earlier quoted context omitted.
To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.
Another possible explanation is password reuse on a site that was breached.