Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

131–140 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#131
post #119

Earlier quoted context omitted.

No, we call them juvenile delinquents and treat them like children. And we certainly don't call the bank the victim.

1. We don't treat them like adult criminals (necessarily), but we certainly treat them like criminals. Here are some examples (some harsher than others): Bank robber, 13, could get 21 years in US jail ( http://www.breitbart.com/article.php?id=CNG.cb17379375828ffc... ) Teen bank robber to be held for two years ( http://www.morningjournal.com/articles/2011/02/18/news/doc4d... ) Boy, 15, Charged in Armed Bank Robbery in…

You're conflating armed robbery, a violent crime, with hacking a web site? That's the end of this thread.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#132
post #122

Earlier quoted context omitted.

Downvotes because of phrasing? Here. So called 'white hat hackers' tend to be fraudulent script kiddies who couldn't hack their way out of a gibs0n. They often attend classes like this http://www.infosecinstitute.com/blog/ethical_hacking_compute... and read a book or two like this http://www.google.com/products/catalog?q=hacking+exposed&#38... . Some times they'll even have a sweet certification like this https://www…

Can you explain your "1% are sellouts" comment? Are you saying that top-tier crackers that accept money for their services are sellouts?

I'm sure this is going to ruffle feathers, but whatever.

The way you become a 'top tier hacker' is by exploiting and reversing in the community (black/grey hats). Much of this is done through working with people who you respect and may have more experience than you.

Through this comes a certain level of respect, to where going public with exploits and such is a hindrance to the community and only serves your selfish agenda for fame or whatever.

Your exploiting all the people you've worked with in the past, ripping their ideas, and handing them off to assholes who then try to teach classes on 'ethical hacking' or whatever.

So yes, I'm calling them sellouts.

*Edit - Another problem I have is that these people generally tend to misrepresent 'black hacks' as a whole and try to play themselves off as bigger than life personas.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#133
post #124
post #121

Earlier quoted context omitted.

> This need to shift some responsibility to a bunch of kids is nauseating. They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it. Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to securi…

> They aren't shifting responsibility Yes PHPFog is. The only reason these kids are even mentioned in the blog post is to shift blame. Their part in the post serves no other purpose. The entire event could have been recounted without a single personification of the hackers in the blog post.

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#134
post #124
post #121

Earlier quoted context omitted.

> This need to shift some responsibility to a bunch of kids is nauseating. They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it. Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to securi…

> They aren't shifting responsibility Yes PHPFog is. The only reason these kids are even mentioned in the blog post is to shift blame. Their part in the post serves no other purpose. The entire event could have been recounted without a single personification of the hackers in the blog post.

No, they are mentioned because they are the criminals who intruded and vandalized the system! Without them, none of this would have happened. There's no shifting of responsibility, since the kids who vandalized their system are responsible for their vandalism.

I can't honestly imagine what kind of moral system you have in which you don't believe that criminals are responsible for their own actions. If someone breaks into your home, is it your locksmith's fault, or the police's fault, or your alarm company's fault? No, it's the fault of the person who broke into your home. Perhaps one of the other parties mentioned was negligent, or perhaps not negligent but they could improve their security practices (install stronger locks, upgrade your alarm system, do more patrols in your neighborhood), but it's still the fault of the person who broke in and vandalized your home.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#135
post #128

Earlier quoted context omitted.

The problem with pressing charges as a detterrent is that it is fundamentally unjust, because the punishment is set up as a detterrent and is disproportionate to the crime. Example: imagine the country of Dictatoria where if you jaywalk you are publicly tortured for a couple of weeks and then put to death. "As a detterrent" A little extreme? Well, consider the 10-20 (or more) year sentences for cyber-terrorism these…

Why do you think these kids would get 10-20 year sentences? Have you ever heard of a computer crime getting that high of a sentence? No one on http://en.wikipedia.org/wiki/List_of_convicted_computer_crim... has gotten more than 5 years, and they include people who have sold access to botnets of hundreds of thousands of machines. A quick Google search reveals someone sentenced to 20 years, but for stealing millions of…

There is a story along these lines, it happened recently in New Zealand.

Some parents had an argument with their teenage son, and he went off in a huff taking the family car (technically without asking permission). His parents thought to themselves "I know, we'll teach him a lesson", so they reported the car stolen. They intended to later on drop the charges (which would have royally peeved the police, making a false charge is also a crime).

Anyway, the cops caught the kid, and because Grand Theft Auto (or whatever the NZ equivalent is) is rated as amongst the most serious crimes, he got sent off (before formal charges were laid) to a maximum security facility in the back of a paddy wagon.

He didn't even make it to the maximum security facility. One of the other prisoners being transported there in the same van killed him.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#136
post #81

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

It's pretty simple: both parties are to blame. PHP Fog did not do due diligence in securing their servers, and the attackers committed illegal and distasteful acts.

If I leave my front door unlocked and someone walks in, there are several possibilities. If they just look around and leave, or say lock the knob behind them and walk out, that is one thing. If they smash my furniture and knock over all my plants, that was their choice, right? That action is illegal and immoral regardless of the fact that it was my negligence which made it possible. We all know these dumb kids should have reported the vulnerability responsibly. That would have benefited everyone, especially themselves. They might have been getting job offers instead of bad reputations.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#137
post #134
post #124

Earlier quoted context omitted.

> They aren't shifting responsibility Yes PHPFog is. The only reason these kids are even mentioned in the blog post is to shift blame. Their part in the post serves no other purpose. The entire event could have been recounted without a single personification of the hackers in the blog post.

No, they are mentioned because they are the criminals who intruded and vandalized the system! Without them, none of this would have happened. There's no shifting of responsibility, since the kids who vandalized their system are responsible for their vandalism. I can't honestly imagine what kind of moral system you have in which you don't believe that criminals are responsible for their own actions. If someone breaks…

>No, they are mentioned because they are the criminals who intruded and vandalized the system!

"They" are not relevant in any way! "They" are tabloid meat for an internet drama. "They" are a distraction from the fact that a hosting company had piss poor security surrounding the core product. The entire story could be told without mentioning the hackers by name, or providing any biographical information. The only reason to include them is to distract from the real issue.

Replace "16 year old" with Russian, Chinese etc. Yes, vandals are bad. That's not exactly in question. In question is the sheer gall of PHPFog to shift blame to some kids to try and cover their embarrassment.

I think the blog post should be rewritten. Instead any mentions of the hackers should be completely neutral. Then it will be PHPFog getting out there and taking responsibility for their mistakes.

No distraction. No hand waving. And no tabloid drama.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#139
post #92
post #89

2:56:45 AM Elliot : then I used the method detailed by turby 2:56:46 AM Elliot : to gain root Has anything been said about what this method was?

If it's what was on the PHP Fog Sucks website, it worked something like this (I may be misremembering a step): 1. Use the post-deploy hook to chmod /home/ubuntu/.ssh so that it could be written to. 2. Upload a PHP shell, use it to write your public key into /home/ubuntu/.ssh/authorized_keys , and get the public IP of the EC2 instance. 3. SSH into the box, sudo su will get you root.

Ok, thanks. I was wondering if there was some other root exploit at play, not just bad system configuration.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#140
post #34

Earlier quoted context omitted.

Amazon is happy to. The limits you cite are merely the point at which you need to have a conversation with Amazon staff. They are quite happy to accomodate _much_ heavier usage from customers.

When I asked for a raise to my limit they denied me, on the basis that my usage was insufficient. Of course, my usage was low because I hadn't launched my product fully because I didn't have enough instances to serve a lot of customers ... catch 22. So I had to build out a rather convoluted architecture that used the loophole of deploying to multiple regions and failing over to whichever region would give me an insta…

Sorry you had a bad experience. I have gotten nothing but superb support from Amazon staff. I'm surprised they weren't willing to accommodate you, doubly so if you were ready to pay.

One thing that surprises me is when people talk about utilizing multiple availability zones in EC2 as some sort of burden. It's very clear from their documentation and architecture that you need to be capable running in at least 2 availability zones regardless if you want any sort of availability.

Post reply on HN