Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?
:) You're not the only one. First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf I read that shortly after it was originally published. And I thought to myself: COOL! I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also…
Yahoo Hacked
61–70 of 258 posts
Re: Yahoo Hacked
#62Earlier quoted context omitted.
Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…
Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.
He reached out, and didn't have any luck. Companies truly need to learn how to deal with these breaches in a way that re-invites the public trust
Re: Yahoo Hacked
#63Earlier quoted context omitted.
I think the "that have yielded any luck" part of that quote is pretty important.
The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?
Re: Yahoo Hacked
#64Earlier quoted context omitted.
That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.
A number of times in recent memory Yahoo has been subject to attacks using XSS and similar. One example of one that was exploited (there was a disclosure back in May, but that didn't have reports of active exploits): http://thenextweb.com/insider/2013/01/31/yahoo-mail-users-st...
Re: Yahoo Hacked
#65This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".
In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…
Re: Yahoo Hacked
#66Earlier quoted context omitted.
:) You're not the only one. First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf I read that shortly after it was originally published. And I thought to myself: COOL! I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also…
Do you still idle in that help channel?
Re: Yahoo Hacked
#67Earlier quoted context omitted.
The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?
I don't see how you're reaching this conclusion. He said, there are no publicly available contact methods that have "yielded any luck". He didn't say there are no publicly available contact methods or that he didn't e-mail yahoo's "security" e-mail address.
Re: Yahoo Hacked
#68Re: Yahoo Hacked
#69Earlier quoted context omitted.
Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
I'd say: "Are these people concerned with receiving income for difficult, highly specialized, valuable work, or are they running a charity?" I guess it's a matter of perspective.
Re: Yahoo Hacked
#70This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…
And the feds are standing at his front door in 3 .. 2 .. 1.