Why didn't he use Shellshock to update bash on the vulnerable servers?
Yahoo Hacked
131–140 of 258 posts
Re: Yahoo Hacked
#132Earlier quoted context omitted.
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
Trespassing is a good analogy. Neither all laws or violations of laws are equal. On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment. On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it. Now that guy willingly alert…
Re: Yahoo Hacked
#133Earlier quoted context omitted.
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
Trespassing is a good analogy. Neither all laws or violations of laws are equal. On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment. On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it. Now that guy willingly alert…
Re: Yahoo Hacked
#134Earlier quoted context omitted.
This has nothing to do with "protection racket" and downvoters are going to be in for one hell of a reality check if you don't believe that this will happen. Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
I frankly don't believe you. I think you vastly overestimate how much you can sell a vulnerability for and vastly underestimate the morals of white hat hackers reporting bugs for a bounty. There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.
Re: Yahoo Hacked
#135Earlier quoted context omitted.
To this day I can't figure out how ICQ ever became popular, but yes I can vouch that there are still people who use it and probably always will.
It originally became popular simply due to lack of competition. AOL Instant Messenger (AIM) was popular but full of ads and didn't offer many features. MSN Messenger (later "Live Messenger" ".Net Messenger Service") didn't exist yet (1999) and while Windows had something called Netmeeting it was simply terrible. ICQ technically came around before AIM, being released in 1996 Vs. 1997 but AIM hit the ground running as…
Re: Yahoo Hacked
#136Earlier quoted context omitted.
Trespassing is a good analogy. Neither all laws or violations of laws are equal. On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment. On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it. Now that guy willingly alert…
It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?
Re: Yahoo Hacked
#137Earlier quoted context omitted.
The OP will go to prison? Seems a bit hyperbolic to me, without any sort of citation or basis for belief.
It probably would have been best to just notify Winzip. Telling the FBI you broke into a server to see if you could, and that you found that someone else had also broken in before you is just plain stupid.
He did not break there to make himself rich or to cause any trouble for the server owner; quite the contrary.
Re: Yahoo Hacked
#138This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".
Re: Yahoo Hacked
#139Earlier quoted context omitted.
TIL - people still use WinZip
It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…
ICQ was popular here way more than in the rest of the world, but it got displaced by Facebook Messenger (and to some smaller extent Google Talk/Hangout/what's the name now).
I have no idea about Russia or Israel, where it was too popular.