Earlier quoted context omitted.
It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?
I wouldn't be happy at all if someone went into my cellar without my permission and told me that my gas line was weakening. Despite good intentions, trespass is trespass.
Yahoo Hacked
151–160 of 258 posts
Re: Yahoo Hacked
#152Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
Re: Yahoo Hacked
#153Mirror of the response, since the site is loading really slow: http://cl.ly/image/2E3D2H2B2d2t
Re: Yahoo Hacked
#154Earlier quoted context omitted.
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
If person A walked up to your window and fired shots through it, killing a family member of yours, and then person B walked up to your window out of curiosity (trespassing), saw a dead person, and called 911 (or whatever your country's emergency number is), should person B be prosecuted for murder? Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as…
Re: Yahoo Hacked
#155Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
Re: Yahoo Hacked
#156This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?
Then he wouldn't bring attention to his consultancy firm. "Gee, these guys sure did show the Yahoo CEO! We need to hire them!" Says the MBA.
Re: Yahoo Hacked
#157This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.
The servers compromised were more like content servers though, not user data servers? Yahoo says no user data was accessed. But could the affected servers be used to more easily get at user databases from 'inside'?
For the user's data for each property (games, mail, etc) they have their own data stores, and those would have been compromised for sure.
Re: Yahoo Hacked
#158Re: Yahoo Hacked
#159Earlier quoted context omitted.
Not sure that's the problem though. yapache and yphp solve a very important need and probably saved Yahoo!'s ass on multiple occasions with engineers making lazy or common mistakes. There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache…
The idea of still using Apache / PHP nowadays is pretty crazy if you ask me.
Re: Yahoo Hacked
#160Earlier quoted context omitted.
His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…
I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…