Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

61–70 of 258 posts

Re: Yahoo Hacked

#61

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

:) You're not the only one. First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf I read that shortly after it was originally published. And I thought to myself: COOL! I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also…

Do you still idle in that help channel?

Re: Yahoo Hacked

#62
post #23

Earlier quoted context omitted.

Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…

Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

Dude your screen name is really telling.

He reached out, and didn't have any luck. Companies truly need to learn how to deal with these breaches in a way that re-invites the public trust

Re: Yahoo Hacked

#63

Earlier quoted context omitted.

I think the "that have yielded any luck" part of that quote is pretty important.

The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?

I don't see how you're reaching this conclusion. He said, there are no publicly available contact methods that have "yielded any luck". He didn't say there are no publicly available contact methods or that he didn't e-mail yahoo's "security" e-mail address.

Re: Yahoo Hacked

#64
post #13

Earlier quoted context omitted.

That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.

A number of times in recent memory Yahoo has been subject to attacks using XSS and similar. One example of one that was exploited (there was a disclosure back in May, but that didn't have reports of active exploits): http://thenextweb.com/insider/2013/01/31/yahoo-mail-users-st...

It may explain it for other users, but at the time I hadn't logged into any yahoo service for months.

Re: Yahoo Hacked

#65
post #3

This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".

In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…

Everyone thinks they are the good guy

Re: Yahoo Hacked

#66
post #61

Earlier quoted context omitted.

:) You're not the only one. First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf I read that shortly after it was originally published. And I thought to myself: COOL! I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also…

Do you still idle in that help channel?

Not for a while. I'm Sebboh. :)

Re: Yahoo Hacked

#67

Earlier quoted context omitted.

The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?

I don't see how you're reaching this conclusion. He said, there are no publicly available contact methods that have "yielded any luck". He didn't say there are no publicly available contact methods or that he didn't e-mail yahoo's "security" e-mail address.

I'm reaching this conclusion because the only person he mentions emailing is Yahoo's CEO.

Re: Yahoo Hacked

#69
post #41

Earlier quoted context omitted.

Are these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.

I'd say: "Are these people concerned with receiving income for difficult, highly specialized, valuable work, or are they running a charity?" I guess it's a matter of perspective.

Not really. We have a system for ensuring that people get paid for valuable work: they're called contracts.

Re: Yahoo Hacked

#70
post #23

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…

> I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration

And the feds are standing at his front door in 3 .. 2 .. 1.

Post reply on HN