Live data from Hacker News

Hacker tries to compromise and resell an internet-facing Linux server

morris.guru

11–20 of 73 posts

Re: Hacker tries to compromise and resell an internet-facing Linux server

#16

Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?

I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#17

All of this is outside my experience, so I have to ask - how does the attack, as described, prove HutHos is the perpetrator? The poster was able to find the HutHos site owner's full information "in a few minutes", due to "poor operational security practices." Doesn't this raise the possibility that the HutHos server was compromised by the malware's true owner?

It's because the script appears to be taking control of servers for hosting purposes.

In other words, the simplest explanation is that Huthos is taking control of machines so that they can sell them to customers as their own VPS service.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#19
Looks like the owner of Huthos doesn't even bother hiding the nature of his operations. The author mentions he has "poor operational security practices" which is rather charitable given that the "buy a vps" links on the website simply link directly to his Facebook profile.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#20
post #16

Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?

I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.

If that honeypot is a blogging security activist that is going to out them, they might care.
Post reply on HN