Live data from Hacker News

The story around the Linode hack

straylig.ht

161–170 of 175 posts

Re: The story around the Linode hack

#161

Earlier quoted context omitted.

> The access that HTP obtained does not, full stop, lead to root on Linode instances without at least one shutdown job or change of root password job showing up in your Linode's history that you did not ask for. ... the access they obtained does not lead to root on the Linode host fleet itself I wouldn't bet on that. > There will always be targets but harboring SwiftIRC is probably a malicious-actor magnet. Isn't tha…

> I wouldn't bet on that. I don't need to wager, and can speak with authority based on what I know (which I'd prefer to leave vague). There are two vectors into a Linode's filesystem from the perspective of an internal attacker: having root on the Xen host or gaining a login on the Linode. Knocking over the database and Web server gives you neither unless the person reused their account's password as their root passw…

Thanks for the clarification.

ISTR being able to back up Linode images, migrate them around, and perform some other admin tasks from the web interface. So I still wonder if the "air gap" API is a bit more powerful than simply the ability to request a reboot. But, again, I don't know.

Re: The story around the Linode hack

#162
post #60

Earlier quoted context omitted.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

> I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect. Ah yes, the "might makes right" philosophy that we all know and admire from primary school.

Not everybody believes in rights, per se. He did put scare underscores around the word. Just saying, if you believe your position to be the moral high ground, you shouldn't need to mischaracterize the positions of others.

Re: The story around the Linode hack

#164

Earlier quoted context omitted.

> I wouldn't bet on that. I don't need to wager, and can speak with authority based on what I know (which I'd prefer to leave vague). There are two vectors into a Linode's filesystem from the perspective of an internal attacker: having root on the Xen host or gaining a login on the Linode. Knocking over the database and Web server gives you neither unless the person reused their account's password as their root passw…

Thanks for the clarification. ISTR being able to back up Linode images, migrate them around, and perform some other admin tasks from the web interface. So I still wonder if the "air gap" API is a bit more powerful than simply the ability to request a reboot. But, again, I don't know.

Those buttons just instruct the hosts to do things and don't actually have power themselves.

Re: The story around the Linode hack

#165

Earlier quoted context omitted.

Thanks for the clarification. ISTR being able to back up Linode images, migrate them around, and perform some other admin tasks from the web interface. So I still wonder if the "air gap" API is a bit more powerful than simply the ability to request a reboot. But, again, I don't know.

Those buttons just instruct the hosts to do things and don't actually have power themselves.

The buttons belie the existence of an API that can "instruct the hosts to do things". Some of those "things" are pretty powerful.

Without knowing what those things are, I'll just take your word for it that none of them could ever possibly be leveraged to compromise a host or guest without unmaskable and permanent messages appearing in the logs.

Re: The story around the Linode hack

#166

Earlier quoted context omitted.

Everyone bitching about HTP or AnonOps or any other hacking group that likes bragging should at least be thankful that they talk about their hacks. I would bet that the crime syndicates have better hacks and keep their mouths shut about them. Those vulnerabilities don't get patched, those customers never get notified. I am not defending HTP or the like, just saying, at least they boast.

I worry more about governments than organized crime these days.

You mean, how much did the 'mole' see/hear/do before getting booted from HTP?

Re: The story around the Linode hack

#167
post #14
post #11

Definitely worth reading the full zine, some scary stuff in there (including very readable python LFI-based exploits for unpatched MoinMoin and ColdFusion). Highlights: 1900+ days uptime on a sparc box somewhere in sourceforge.net, root on ICANN, root on Debian repositories..

Link to full zine: http://straylig.ht/zines/HTP5/

Any chance someone saved a copy? Link seems dead from here

Re: The story around the Linode hack

#168

Earlier quoted context omitted.

They didn't utilize the access to go after Linode. They intended to utilize it to go after SwiftIRC, which nobody gives a shit about. That's where my comments came from. Linode just happened to be a nice prize on the way.

Yeah, I mean, it's supposed to come off as showing off, right? "Sure, we're so crazy good, that we can take out name.com and linode just cause some script kiddies pissed us off, no sweat. Don't mess with us. And we're so in it for the lulz, that' SURE we'd take out linode and name.com just to get some script kiddies, and not bother trying to sell the CCs or anything." Or, they're lying. I mean, they could be lying ab…

You hit the nail on the head right here.

Assuming the account is completely true though, I would say they succeeded in showing off. It's pretty impressive that they took over name.com and discovered a CF 0-day just to get into Linode, all just to fuck with one IRC network no one cares about.

Re: The story around the Linode hack

#170
post #166

Earlier quoted context omitted.

I worry more about governments than organized crime these days.

You mean, how much did the 'mole' see/hear/do before getting booted from HTP?

No, that's not what I mean. What I mean are things like the Chinese government hacking Google and the New York Times, not HTP hacking some IRC provider for revenge.
Post reply on HN