Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.
What's the issue with Perl scripts on production web servers? Probably 90% of my (homegrown) scripts are written in Perl. What does Perl vs. PHP vs. Ruby vs. $languageoftheweek have to do with anything?
Yahoo Hacked
161–170 of 258 posts
Re: Yahoo Hacked
#162Earlier quoted context omitted.
His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…
I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…
In the case of physical property the most common remedies for trespassing are either an injunction prohibiting future trespassing on the same property or a modest fine (e.g. $100). Applying the same penalties to the equivalent behavior in the computer context would be completely reasonable, but that empirically isn't what happens, because the CFAA is defective.
Re: Yahoo Hacked
#163Earlier quoted context omitted.
Not sure that's the problem though. yapache and yphp solve a very important need and probably saved Yahoo!'s ass on multiple occasions with engineers making lazy or common mistakes. There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache…
The idea of still using Apache / PHP nowadays is pretty crazy if you ask me.
Re: Yahoo Hacked
#164Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
The OP will go to prison? Seems a bit hyperbolic to me, without any sort of citation or basis for belief.
Re: Yahoo Hacked
#165Earlier quoted context omitted.
If person A walked up to your window and fired shots through it, killing a family member of yours, and then person B walked up to your window out of curiosity (trespassing), saw a dead person, and called 911 (or whatever your country's emergency number is), should person B be prosecuted for murder? Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as…
Since you asked for a downvote explanation: I couldn't make any sense of the comment, even after thinking about it. It's not that I disagree, I can't even figure out the analogy. Are you saying B shouldn't be charged with anything because they didn't murder, or B should be charged with trespassing but not murder, or B should be charged with felony murder because of the trespass, or something else?
I didn't express a stance either way on whether he should be prosecuted for a more minor offense or not, in the analogy's case trespassing. (There are obviously both pros and cons in the precedent set by prosecuting people for revealing their own minor crime on account of reporting a terrible one.)
Re: Yahoo Hacked
#166Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…
Re: Yahoo Hacked
#167Earlier quoted context omitted.
I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…
If you walk by a house seeing someone crack a window and crawl in, do you think it's morally acceptable to trespass on the property to ascertain whether this is a burglary in progress or someone who forgot their key? (This case seems somewhere between my and your example.)
Re: Yahoo Hacked
#168Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?
Re: Yahoo Hacked
#169Mirror of the response, since the site is loading really slow: http://cl.ly/image/2E3D2H2B2d2t
Classic. "Thanks for pointing out this insanely serious issue, which is unfortunately not eligible for our bug bounty program." Maybe they'll send him a free hat.
Re: Yahoo Hacked
#170Earlier quoted context omitted.
TIL - people still use WinZip
It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…
I mean - all I want to do is to quickly setup a playlist out of a bunch of directories and eventually do searches in it, which is incredibly common at a party when you quickly assemble playlists from multiple sources. Other media players are completely retarded.