Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

141–150 of 258 posts

Re: Yahoo Hacked

#141
post #21

This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

I think its important to mention the fact that he wasn't just looking for places to exploit shellshock. He was actively exploiting it by sending himself reverse shells from the computers. He wrote code to collect and exploit the reverse shells. He wrote code to spider sites to try to find more exploitable hosts. Then he was logging and exploring the infrastructure and servers he penetrated.

His actions enabled him to cause damage if he chose, but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe.

If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under his real name.

He seems honest to a fault, loquacious to the point of legally endangering himself just to spread awareness of some horrible things he witnessed.

In my opinion, spinning his actions as anything other than heroic is itself an order of magnitude more malicious than what you're claiming, because it contributes to a false narrative in which the end goal is to completely destroy another human being's life when he was just trying to help.

Re: Yahoo Hacked

#142
post #54

Earlier quoted context omitted.

This has nothing to do with "protection racket" and downvoters are going to be in for one hell of a reality check if you don't believe that this will happen. Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?

I frankly don't believe you. I think you vastly overestimate how much you can sell a vulnerability for and vastly underestimate the morals of white hat hackers reporting bugs for a bounty. There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.

Microsoft will pay up to $100,000 plus $50,000 bonus for defense submissions (http://technet.microsoft.com/en-us/security/dn425049)

Facebook has paid $12,500 for one (http://techcrunch.com/2013/09/02/security-researcher-discove...)

Google will pay up to $20,000 for one (http://www.google.com/about/appsecurity/reward-program/#rewa...)

Forbes even posted an article a couple years ago on the market of zero day exploits and listed prices someone could get for zero day exploits with prices in the tens/hundreds of thousands. (http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...) It should be noted that they state in this article that the groups that will buy these exploits for these prices are generally western governments.

Re: Yahoo Hacked

#143
post #132

Earlier quoted context omitted.

Trespassing is a good analogy. Neither all laws or violations of laws are equal. On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment. On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it. Now that guy willingly alert…

It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?

Would you allow a police officer to do the same?

Re: Yahoo Hacked

#144
post #102

Earlier quoted context omitted.

Malice is in the eye of the beholder. He logged into a server he didn't own and ran commands without authorization. That is malicious from the perspective of the law.

Out of curiosity, wouldn't this also apply to the security researcher at erratasec.com that did an earlier survey? That scan logged into peoples boxes and executed a ping going out. Now obviously there isn't any damage, but what legal theory is protecting these legit security researchers?

The lack of anybody attempting to prosecute them.

Re: Yahoo Hacked

#145
post #132

Earlier quoted context omitted.

Trespassing is a good analogy. Neither all laws or violations of laws are equal. On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment. On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it. Now that guy willingly alert…

It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?

Trespass to land doesn't require damage, all it requires is the willful, unauthorized, entry onto land in another's exclusive possession. Vandalism requires that there by some property damage.

Re: Yahoo Hacked

#146

Earlier quoted context omitted.

I think its important to mention the fact that he wasn't just looking for places to exploit shellshock. He was actively exploiting it by sending himself reverse shells from the computers. He wrote code to collect and exploit the reverse shells. He wrote code to spider sites to try to find more exploitable hosts. Then he was logging and exploring the infrastructure and servers he penetrated.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.)

But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offense to trespass regardless of whether you are trespassing with malicious intent. Certainly it is worse to break into a house intending to steal something than to walk into someone else's house out of curiosity, but neither is legal or, in my view, morally acceptable.

So I say: good for him for making these breaches known, but he definitely should not have been in there poking around in the first place.

Re: Yahoo Hacked

#147

Earlier quoted context omitted.

I think its important to mention the fact that he wasn't just looking for places to exploit shellshock. He was actively exploiting it by sending himself reverse shells from the computers. He wrote code to collect and exploit the reverse shells. He wrote code to spider sites to try to find more exploitable hosts. Then he was logging and exploring the infrastructure and servers he penetrated.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

[deleted]

Re: Yahoo Hacked

#148

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…

If person A walked up to your window and fired shots through it, killing a family member of yours, and then person B walked up to your window out of curiosity (trespassing), saw a dead person, and called 911 (or whatever your country's emergency number is), should person B be prosecuted for murder?

Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as a sarcastic attack rather than an analogy. If it incorrectly came across as the former, that would be my fault, but I don't know if that's what caused the downvote, so an explanatory comment would be appreciated.

Re: Yahoo Hacked

#149

Earlier quoted context omitted.

It originally became popular simply due to lack of competition. AOL Instant Messenger (AIM) was popular but full of ads and didn't offer many features. MSN Messenger (later "Live Messenger" ".Net Messenger Service") didn't exist yet (1999) and while Windows had something called Netmeeting it was simply terrible. ICQ technically came around before AIM, being released in 1996 Vs. 1997 but AIM hit the ground running as…

Don't forget that the A in AOL stands for 1/193 countries. In AU (yes - anecdote != data) -- friends I would chat with were all on ICQ - before switching over to msn. Never heard of AIM

Second datapoint. In FI everyone who did not use IRC used ICQ and then switched to MSN.

Re: Yahoo Hacked

#150

Earlier quoted context omitted.

I think its important to mention the fact that he wasn't just looking for places to exploit shellshock. He was actively exploiting it by sending himself reverse shells from the computers. He wrote code to collect and exploit the reverse shells. He wrote code to spider sites to try to find more exploitable hosts. Then he was logging and exploring the infrastructure and servers he penetrated.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

It's been stated here several times before. The reward for pointing out lapses in security like the aforementioned are generally awarded in the form of hostility. He'll probably get a big reward for this one.

That said, it was a well-written article by an obviously talented hacker, though I did find the simile about the infant with a genital wart to be unsettling.

Post reply on HN