Multiple top-security sites hacked (zf05)
blog.sucuri.net
Multiple top-security sites hacked (zf05)
1–5 of 5 posts
Re: Multiple top-security sites hacked (zf05)
#2choice quote:
"You cannot outsource blame. You HAVE to take responsibility for your mistakes, whether they are mistakes in your code, mistakes in code you are using, mistakes by your host, or mistakes in who you trust. These are all security choices. Learn to control this shit. Learn how to read code. A lot of the time it only takes a very shallow audit to realise that the code is crap and is bound to have bugs. In a smarter world, security professionals get paid to stop people from getting owned. End of. These is no limit to the scope of an audit."
Re: Multiple top-security sites hacked (zf05)
#3Ouch. looks like they rm -rf /* mitnick's box. I'd like to know how they got in. I see some logs of phpmyadmin directory traversal attempts so maybe that and a weak system password?
Re: Multiple top-security sites hacked (zf05)
#4cat zf05.txt | grep gloryfish
Re: Multiple top-security sites hacked (zf05)
#5cat zf05.txt | grep gloryfish
ptacek rates a mention