Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

251–258 of 258 posts

Re: Yahoo Hacked

#251

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

[deleted]

Re: Yahoo Hacked

#252
post #251

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

[deleted]

">

Re: Yahoo Hacked

#253

Earlier quoted context omitted.

How much are e.g. SANS certifications worth? I subscribe to their vulnerablity emails but they push the certification programs so hard it smells a little like University of Phoenix.

I'm not a fan of any security certification.

You make hiring decisions off of a home-grown security "course", right? You've found that valuable -- would others?

Re: Yahoo Hacked

#254

Earlier quoted context omitted.

I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.

Does your "successful" bug bounty program still only pays $12,50 in store credit per bug? That could explain the lack of interest in contacting you about any bug at all.

I was curious. So I went to the link secalex posted. Bountys start at $50; max is $15k.

Re: Yahoo Hacked

#255

Earlier quoted context omitted.

I'm not a fan of any security certification.

You make hiring decisions off of a home-grown security "course", right? You've found that valuable -- would others?

That's not an accurate summary of how we hire. We don't make decisions based on the crypto challenges or Microcorruption; we use them to find people to talk to. We have a whole process that actively evaluates candidates.

Re: Yahoo Hacked

#256

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

Patched twice? There are 7 known shellshock exploits (and 30 patches) so far.. https://shellshocker.net/ Not knocking on you or anything, just more interested to know if all exploits have been patched against, more than the # of patches applied.

The 30 patches are the number of total patches on that version of bash (bash's version release cycle is major.minor.patch), not the number of patches related to shellshock.

Re: Yahoo Hacked

#257

Earlier quoted context omitted.

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

> Certainly ordinary physical property law makes is an offense to trespass regardless of whether you are trespassing with malicious intent. In the case of physical property the most common remedies for trespassing are either an injunction prohibiting future trespassing on the same property or a modest fine (e.g. $100). Applying the same penalties to the equivalent behavior in the computer context would be completely…

This isn't quite trespassing, though: this is breaking and entering (without malicious intent). This is someone noting that your door lock is easily pickable and then going on a quest to see just how far they can get, maybe finding a key to the car in the garage and then going into their glove compartment. The equivalent situation with physical property is clearly "criminal".

Re: Yahoo Hacked

#258
post #240

Earlier quoted context omitted.

It looks like the guy who originally posted this has pretty much accused you of flat out lying about this[1]. What do you have to say to his comments, particularly about the sports servers being internal. [1] - http://www.futuresouth.us/wordpress/?p=25

Yes, the systems with the log parsing bug are part of an internal subnet. As with most web scale companies HTTPS requests are terminated on a unified edge and load-balanced to web service hosts in internal clusters. In this case the malicious header was maintained in the backend requests and ended up in the application log, which triggered the command injection. Everything I wrote above is correct and is in no way in…

Thanks for that. Understandably, the presence of an RFC1918 address doesn't necessarily mean a site isn't inaccessible, but for everyone else there's no way to tell without poking around Yahoo! which, lets face it, isn't something many of us would condone.
Post reply on HN