Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

71–80 of 258 posts

Re: Yahoo Hacked

#71

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

You might find this paper about stealing a botnet interesting [0]. Even though its five years old, the crazy stuff these researchers found is still amazing.

[0] http://www.net.t-labs.tu-berlin.de/teaching/ws0910/IS_semina...

Re: Yahoo Hacked

#72
post #62

Earlier quoted context omitted.

Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

Dude your screen name is really telling. He reached out, and didn't have any luck. Companies truly need to learn how to deal with these breaches in a way that re-invites the public trust

You seem to be missing my point. I've repeated it in a bunch of other comments but I'll do it again here: You don't get points for "reaching out" when you don't spend a second to search for the right address to reach out to. Yahoo has a page dedicated to reporting bugs. If he had used that page he would have gotten a response. Yahoo has paid dozens of people for doing this https://hackerone.com/yahoo?show_all=true.

Re: Yahoo Hacked

#73

Earlier quoted context omitted.

In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…

Well, mostly because if it was good enough, it would be the first thing out of the mouth of every blackhat that was caught... Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . If the company being contacted does not personally kn…

Well, every time I've gone vigilante, I've logged the ever lovin' shit out of myself, just in case. Nothing interesting ever happened, though.

There was one time when I used a CnC channel to issue uninstall commands against a couple hundred bots. That was only after trying to contact a user or two to suggest that they uninstall the malware themselves... Those conversations went SO poorly! :)

Anyway, the only way to find a user's contact information via a piece of malware like that is arguably an invasion of privacy... Which brings us full circle.

Could we establish a metric for Good Samaritanism? Could we design a metric that is restrictive enough to prevent misuse but inclusive enough to allow unrequested, benevolent cleaning and patching?

Re: Yahoo Hacked

#74

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

The OP will go to prison? Seems a bit hyperbolic to me, without any sort of citation or basis for belief.

It probably would have been best to just notify Winzip.

Telling the FBI you broke into a server to see if you could, and that you found that someone else had also broken in before you is just plain stupid.

Re: Yahoo Hacked

#75

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

:) You're not the only one. First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf I read that shortly after it was originally published. And I thought to myself: COOL! I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also…

That PDF is fascinating. Thank you for posting.

Re: Yahoo Hacked

#76
post #30

Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.

I think therein lies the problem: yapache. It's their own version of (modified) Apache. So when these bugs like shellshock come out, it's harder to patch your own home-grown version.

Not sure that's the problem though. yapache and yphp solve a very important need and probably saved Yahoo!'s ass on multiple occasions with engineers making lazy or common mistakes.

There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache / php than anything else) isn't entirely crazy.

Just looks like this one slipped through the cracks.

Re: Yahoo Hacked

#77
post #21

This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

You can also use this resource http://www.globalshellshock.com to check if your IP address is vulnerable to ShellShock.

Re: Yahoo Hacked

#78

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

It was interesting the first few times watching them. Sometimes the commands are not even authenticated so you could do fun things like write a text file saying their computer was infected and then open it with notepad... or other things.[0] You aren't going to find many large scale botnets that still use IRC though. It is really amateur hour CnC.

[0] It probably is not really advisable to do even 'helpful' actions such as that, but when you are young you do careless things.

Re: Yahoo Hacked

#79

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

I used to do that for fun. It was a lot easier back when SDBot and AgoBot was the shit.

The trick I used was to go on some xdcc network, change nickname to one similar to the bots and just wait. Sooner or later one of the botnet owners tried to authenticate and soon after I would exit with a ping-timeout.

Then you could just log into one of them, get a list of processes and download the one with a random name. It was pretty easy and you could get your hands on a few thousand bots in a weekend.

Oh the joy of running "!uninstall" while the owners was in the chatroom...

Re: Yahoo Hacked

#80

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems.

> they will not differentiate between this and black hat intrusion

Should they? This reads like textbook unauthorized access to a computer system,

> A quick `ps aux` on the box yielded...

This isn't just poking at web servers to see what secrets they freely reveal, this is trespass.

Post reply on HN