Earlier quoted context omitted.
Contrary to his claim, OP is clearly not a white hat "ethical hacker", since he does not have consent from the owners of any of these systems. > they will not differentiate between this and black hat intrusion Should they? This reads like textbook unauthorized access to a computer system, > A quick `ps aux` on the box yielded... This isn't just poking at web servers to see what secrets they freely reveal, this is tre…
This thread has a lot of shaky analogies with physical trespassing. Here's an article on trespass laws (in California) - the article is more interesting than you would expect and the trespass laws are more complicated than you'd expect. http://www.shouselaw.com/trespass.html
Yahoo Hacked
181–190 of 258 posts
Re: Yahoo Hacked
#182Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
Re: Yahoo Hacked
#183Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
Re: Yahoo Hacked
#184Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
Not knocking on you or anything, just more interested to know if all exploits have been patched against, more than the # of patches applied.
Re: Yahoo Hacked
#185Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
Patched twice? There are 7 known shellshock exploits (and 30 patches) so far.. https://shellshocker.net/ Not knocking on you or anything, just more interested to know if all exploits have been patched against, more than the # of patches applied.
His team also recently poached Chris Rohlf, from his own company no less!, and Chris is probably one of the best vulnerability researchers working.
(I have no affiliation whatsoever with Yahoo and while I like Alex fine, we're not close friends. I'm pretty biased about Chris, though.)
This is more "vote of confidence" than your comment asked for; I'm just heading off a potentially unproductive thread at the pass. :)
Re: Yahoo Hacked
#186This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.
Thanks. This guy writes a lot of text but it takes him forever to get to the point.
Re: Yahoo Hacked
#187Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
If you want hackers to report you vulnerabilities via Yahoo Bug Bounty Program, at least pay more than 50$ for a minimum bounty, 50$ is a joke https://hackerone.com/yahoo ...
Re: Yahoo Hacked
#188Earlier quoted context omitted.
Patched twice? There are 7 known shellshock exploits (and 30 patches) so far.. https://shellshocker.net/ Not knocking on you or anything, just more interested to know if all exploits have been patched against, more than the # of patches applied.
Before Yahoo poached him to be their CISO, Alex was one of the principals behind iSEC Partners, our former arch-competitor and now sister company. He knows what he's talking about. If he says they're on top of shellshock, my money would be on him being right. His team also recently poached Chris Rohlf, from his own company no less!, and Chris is probably one of the best vulnerability researchers working. (I have no a…
However, genuine question - how does the laymen (like myself) rate infosec specialists? Imagine for a second I'm a senior exec at Target and IBN (IBM's fake arch-competitor) comes to me and says "no worries about security, we use 256-bit encryption, bank grade security, etc etc". Do I believe him?
I feel like infosec is a "I don't know what I don't know" industry and the consequences could be potentially dire.
Re: Yahoo Hacked
#189Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
If you want hackers to report you vulnerabilities via Yahoo Bug Bounty Program, at least pay more than 50$ for a minimum bounty, 50$ is a joke https://hackerone.com/yahoo ...
Re: Yahoo Hacked
#190Earlier quoted context omitted.
Before Yahoo poached him to be their CISO, Alex was one of the principals behind iSEC Partners, our former arch-competitor and now sister company. He knows what he's talking about. If he says they're on top of shellshock, my money would be on him being right. His team also recently poached Chris Rohlf, from his own company no less!, and Chris is probably one of the best vulnerability researchers working. (I have no a…
This all sounds good - especially given your reputation for infosec. However, genuine question - how does the laymen (like myself) rate infosec specialists? Imagine for a second I'm a senior exec at Target and IBN (IBM's fake arch-competitor) comes to me and says "no worries about security, we use 256-bit encryption, bank grade security, etc etc". Do I believe him? I feel like infosec is a "I don't know what I don't…