Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

151–160 of 258 posts

Re: Yahoo Hacked

#151
post #132

Earlier quoted context omitted.

It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?

I wouldn't be happy at all if someone went into my cellar without my permission and told me that my gas line was weakening. Despite good intentions, trespass is trespass.

What if his house was next to yours and he smelled a gas leak but wasn't sure, so his investigation led him to your cellar?

Re: Yahoo Hacked

#152

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…

This thread has a lot of shaky analogies with physical trespassing. Here's an article on trespass laws (in California) - the article is more interesting than you would expect and the trespass laws are more complicated than you'd expect. http://www.shouselaw.com/trespass.html

Re: Yahoo Hacked

#153
post #8

Mirror of the response, since the site is loading really slow: http://cl.ly/image/2E3D2H2B2d2t

Sorry but if this is not I wonder what is? A remote OpenSSH root exploitation technique or a CSS3 misconfiguration (smiley doesn't display on all browsers), can't believe this.

Re: Yahoo Hacked

#154

Earlier quoted context omitted.

Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…

If person A walked up to your window and fired shots through it, killing a family member of yours, and then person B walked up to your window out of curiosity (trespassing), saw a dead person, and called 911 (or whatever your country's emergency number is), should person B be prosecuted for murder? Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as…

Since you asked for a downvote explanation: I couldn't make any sense of the comment, even after thinking about it. It's not that I disagree, I can't even figure out the analogy. Are you saying B shouldn't be charged with anything because they didn't murder, or B should be charged with trespassing but not murder, or B should be charged with felony murder because of the trespass, or something else?

Re: Yahoo Hacked

#155

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…

trespassing is not illegal

Re: Yahoo Hacked

#156
post #24

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

Then he wouldn't bring attention to his consultancy firm. "Gee, these guys sure did show the Yahoo CEO! We need to hire them!" Says the MBA.

And this is different from what everyone else on HN does...how?

Re: Yahoo Hacked

#157
post #21

This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

The servers compromised were more like content servers though, not user data servers? Yahoo says no user data was accessed. But could the affected servers be used to more easily get at user databases from 'inside'?

Yahoo! keeps their user information mainly in a DB called 'UDB'... User Database. It is a key, value store and clients are only allowed to access permitted keys. So the encrypted user password, plain-text answers to 'secret questions' (for password rests), etc. were not accessed unless a login server was compromised.

For the user's data for each property (games, mail, etc) they have their own data stores, and those would have been compromised for sure.

Re: Yahoo Hacked

#159
post #76

Earlier quoted context omitted.

Not sure that's the problem though. yapache and yphp solve a very important need and probably saved Yahoo!'s ass on multiple occasions with engineers making lazy or common mistakes. There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache…

The idea of still using Apache / PHP nowadays is pretty crazy if you ask me.

Half the world must be crazy. What is better and why?

Re: Yahoo Hacked

#160

Earlier quoted context omitted.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

If you walk by a house seeing someone crack a window and crawl in, do you think it's morally acceptable to trespass on the property to ascertain whether this is a burglary in progress or someone who forgot their key? (This case seems somewhere between my and your example.)
Post reply on HN