Live data from Hacker News

Hacker tries to compromise and resell an internet-facing Linux server

morris.guru

31–40 of 73 posts

Re: Hacker tries to compromise and resell an internet-facing Linux server

#31
post #26
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

Given that the attacker is unknown, the correct term would be they or them. Gender is unknown, a gender neutral description should be used.

Yeah, true. Most authors seem to like to assume male, though. :(

Re: Hacker tries to compromise and resell an internet-facing Linux server

#32
post #14

While interesting, I'm not sure how I feel about him ending the article with solid advice for criminals on how to avoid getting caught.

I'm the author of this post. You mention a tough philosophical quandary that I struggle with every time I share information with the rest of the world. As much as I hate giving attackers anything, I am very dedicated to information sharing so that people can learn as much as possible from my posts. The truth is always out there one way or another. I would rather everybody be as educated as possible. Hopefully that ma…

I couldn't agree more.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#33
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

At the same time the author referred to the attacker as a "guy", so that just proves how difficult it can be to get rid of the gender bias (assuming this was the author's intent).

Re: Hacker tries to compromise and resell an internet-facing Linux server

#34

Not to say that Huthos are innocent, but I don't see any concrete proof that they are behind this attack. The fact that they are hosting a server provisioning script is hardly crazy, given that they are a hosting provider. What's to say that the ACTUAL attacker didn't just come across the provisioning script and decide to use it for themselves? The script URL is listed publicly online: http://yandicunk.blogspot.co.uk…

Should have waited for customers for proof.

I bet it would actually run as a proxy/VPN to post spam on forums.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#35

Not to say that Huthos are innocent, but I don't see any concrete proof that they are behind this attack. The fact that they are hosting a server provisioning script is hardly crazy, given that they are a hosting provider. What's to say that the ACTUAL attacker didn't just come across the provisioning script and decide to use it for themselves? The script URL is listed publicly online: http://yandicunk.blogspot.co.uk…

Hi, thanks for your comment. It wasn't really my objective to find the smoking gun and bring Huthos' operation crumbling to the ground. Like you, I don't definitively know that the operators of the website are the same people that broke into my honeypot without permission. It seems more likely than another totally-unrelated bad guy knowing where the file paths are to the Huthos provisioning scripts when directory listing isn't enabled, as well as other small nuances that I gathered while investigating this attack (the operators of the website posting videos of them exploiting Shellshock on their youtube channel, etc).

Re: Hacker tries to compromise and resell an internet-facing Linux server

#36
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

At the same time the author referred to the attacker as a "guy", so that just proves how difficult it can be to get rid of the gender bias (assuming this was the author's intent).

"guy" is gender neutral in my dialect.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#37

Looks like the owner of Huthos doesn't even bother hiding the nature of his operations. The author mentions he has "poor operational security practices" which is rather charitable given that the "buy a vps" links on the website simply link directly to his Facebook profile.

Or maybe Huthos was hacked and being used to host these scripts.

I'd want a bit more proof, like it actually being used by a Huthos customer, before going after them.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#39
post #26
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

Given that the attacker is unknown, the correct term would be they or them. Gender is unknown, a gender neutral description should be used.

I agree "they"/"them" sounds cleaner than "he or she"/"him or her" but isn't it officially incorrect? I do like that Facebook has started using "they"/"them".

Re: Hacker tries to compromise and resell an internet-facing Linux server

#40
post #26
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

Given that the attacker is unknown, the correct term would be they or them. Gender is unknown, a gender neutral description should be used.

But they is plural, so wouldn't the author technically need to say "he or she" for each occurrence? Sadly, English has no singular gender neutral pronoun.
Post reply on HN