Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

101–110 of 258 posts

Re: Yahoo Hacked

#101

Earlier quoted context omitted.

It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…

Can you point me to a description of CCleaner's problems? It's still my go-to tool for cleaning computers, and I've never had a problem or heard of anything major (besides the normal bugs that get fixed). It also isn't a 90s tool, being first released in 2003. What's your idea of a better alternative?

I listed the alternatives already. They're all built in.

CCleaner's registry cleaner is the main issue (aside from the fact it makes computers literally slower by clearing every single cache it can find). Some of the issues it has caused:

- Registry damage: Windows 8 store was damaged/corrupted by a previous version (you had to run DISM to repair it), Windows uninstaller corruption (this impacted Mcafee anti-virus around 2009, the uninstaller would become unusable), deletes preferences for unconnected devices (USB sticks, external drives, network drives, etc) so if you have any software installed externally the drive letter may shift and the software will break, deletes unmounted but valid COM objects, and so on...

- Damage: http://features.en.softonic.com/the-dangers-of-using-ccleane....

- Article: https://bitsum.com/regcleanerfacts.php

- Wikipedia: https://en.wikipedia.org/wiki/Registry_cleaner

- Microsoft support article ("serious issues can occur when you modify the registry incorrectly using these types of utilities"): https://support2.microsoft.com/kb/2563254

- Microsoft Article: http://windows.microsoft.com/en-us/windows/are-registry-clea...

Everyone is saying the same thing. Registry Cleaning is unnecessary, won't improve performance, and really only offers you a chance of doing damage. Registry cleaning hasn't been important since XP, and XP shipped over ten years ago.

Everyone else CCleaner does is either stupid (clearing caches) or duplicated of internal functionality (IE cache clearing, Recycling Bin emptying, etc). Plus Disk Cleanup isn't a new addition to Windows.

Re: Yahoo Hacked

#102
post #99
post #92

Earlier quoted context omitted.

Bank robber calling the cops to report the safe has already been cleaned out...

That would imply OP had malicious intentions, which he apparently did not.

Malice is in the eye of the beholder. He logged into a server he didn't own and ran commands without authorization. That is malicious from the perspective of the law.

Re: Yahoo Hacked

#103
post #92
post #74

Earlier quoted context omitted.

It probably would have been best to just notify Winzip. Telling the FBI you broke into a server to see if you could, and that you found that someone else had also broken in before you is just plain stupid.

Bank robber calling the cops to report the safe has already been cleaned out...

It's a safe cracker calling the cops in this scenario. "I wanted to see what banks I could break into" is a much more reasonable defense in this situation seeing as he's alerting others to the intrusions when he clearly could have just kept quiet and stayed out of trouble.

Not that it says anything about whether he'll be in legal trouble. Laws are crazy.

Re: Yahoo Hacked

#104
post #100

Earlier quoted context omitted.

Can you point me to a description of CCleaner's problems? It's still my go-to tool for cleaning computers, and I've never had a problem or heard of anything major (besides the normal bugs that get fixed). It also isn't a 90s tool, being first released in 2003. What's your idea of a better alternative?

Before anything else, I should mention that I haven't worked help desk in over 5 years. Back when I worked help desk, the most common reason for a completely FUBAR and need a re-install was that the user ran CCleaner on it.

Your organization likely did something unconventional with the registry that made systems break when touched by CCleaner (perhaps a groupware tool, or perhaps the broken systems had already been FUBAR'd by intrusive software and CCleaner's attempt to fix that FUBAR triple-FUBAR'd it).

That doesn't mean CCleaner's behavior is correct, but it's probably a situation the developers haven't been able to test against. For what it's worth, I've run CCleaner's registry cleaner on dozens of machines and never had a problem of any type, and I still use CCleaner sometimes because it's a simple way to clean the temp/junk files left by many common applications with one button click.

I always feel a little nervous when I run the registry cleaner, and while I haven't noticed any problems, I also haven't noticed a meaningful improvement after running it either. I should probably stop doing it just for that reason.

Re: Yahoo Hacked

#105
post #21

This writeup doesn't really get to the point so, the tl;dr He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

You can also use this resource http://www.globalshellshock.com to check if your IP address is vulnerable to ShellShock.

IP addresses are not vulnerable to ShellShock

Re: Yahoo Hacked

#106
post #92
post #74

Earlier quoted context omitted.

It probably would have been best to just notify Winzip. Telling the FBI you broke into a server to see if you could, and that you found that someone else had also broken in before you is just plain stupid.

Bank robber calling the cops to report the safe has already been cleaned out...

You poke into someone's house when you see their front door wide open, see it has been cleaned up and then notify the cops...

Re: Yahoo Hacked

#107
post #99
post #92

Earlier quoted context omitted.

Bank robber calling the cops to report the safe has already been cleaned out...

That would imply OP had malicious intentions, which he apparently did not.

Only good to a certain extent, and since hackers are often easy targets and successful computer prosecutions are a good feather in the cap of prosecutors ever more concerned about having something on their resumes related to the "cybersecurity" buzzword, they'll frequently get harsh sentences.

Weev got 3.5 years and also did nothing malicious with the data he found: http://www.wired.com/2013/03/att-hacker-gets-3-years/

Re: Yahoo Hacked

#108
post #105

Earlier quoted context omitted.

You can also use this resource http://www.globalshellshock.com to check if your IP address is vulnerable to ShellShock.

IP addresses are not vulnerable to ShellShock

The services running on the machine assigned your IP address?

I knew what he meant...

Re: Yahoo Hacked

#109

Earlier quoted context omitted.

TIL - people still use WinZip

It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…

I see CCleaner on probably at least 50% of the desktops shown by people streaming on Twitch. Seems so odd to me.

Then again, I used WinRAR up until probably 2010 or so, whenever ninite made it easier to install 7zip.

A sort of related oddity is how often I see OpenOffice on the desktops in doctors offices - usually alongside Microst Office icons. I have no idea what they would use it for.

Re: Yahoo Hacked

#110

Earlier quoted context omitted.

It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…

To this day I can't figure out how ICQ ever became popular, but yes I can vouch that there are still people who use it and probably always will.

It originally became popular simply due to lack of competition.

AOL Instant Messenger (AIM) was popular but full of ads and didn't offer many features. MSN Messenger (later "Live Messenger" ".Net Messenger Service") didn't exist yet (1999) and while Windows had something called Netmeeting it was simply terrible.

ICQ technically came around before AIM, being released in 1996 Vs. 1997 but AIM hit the ground running as AOL hooked up their massive (then) subscriber base. So while AIM was a more popular service, ICQ became popular with a certain more savvy class of user (e.g. tech' nerds, who wanted more functionality, and something NOT tied to their email address).

ICQ offered that. Less ads, more features, and slightly anonymous (ICQ numbers). ICQ sucks by todays' standards, but in 1996-1999 it was really competing with AIM. There's also Yahoo! Messenger that came out in 1998 which was fairly popular (particularly as an "AIM replacement").

ICQ just somehow remained popular in certain parts of the world for the same reason Facebook isn't going away: It reached a critical mass, now "everyone" is using it which means "everyone" has to continue using it...

Post reply on HN