Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

161–170 of 258 posts

Re: Yahoo Hacked

#161
post #30

Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.

What's the issue with Perl scripts on production web servers? Probably 90% of my (homegrown) scripts are written in Perl. What does Perl vs. PHP vs. Ruby vs. $languageoftheweek have to do with anything?

It's really just that Shellshock becomes viable only when HTTP headers are passed to your code as environment variables. For CGI, this is the way things are done, and most Perl scripts interact with the web server through CGI. On the other hand, Ruby and $languageoftheweek are usually called through a server framework like WSGI or Rack, which have their own ways of getting HTTP headers to the user code besides passing them as environment variables. Perl has PSGI ( plackperl.org ) but it's more commonly used in CGI.

Re: Yahoo Hacked

#162

Earlier quoted context omitted.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

> Certainly ordinary physical property law makes is an offense to trespass regardless of whether you are trespassing with malicious intent.

In the case of physical property the most common remedies for trespassing are either an injunction prohibiting future trespassing on the same property or a modest fine (e.g. $100). Applying the same penalties to the equivalent behavior in the computer context would be completely reasonable, but that empirically isn't what happens, because the CFAA is defective.

Re: Yahoo Hacked

#163
post #76

Earlier quoted context omitted.

Not sure that's the problem though. yapache and yphp solve a very important need and probably saved Yahoo!'s ass on multiple occasions with engineers making lazy or common mistakes. There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache…

The idea of still using Apache / PHP nowadays is pretty crazy if you ask me.

[deleted]

Re: Yahoo Hacked

#164

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

The OP will go to prison? Seems a bit hyperbolic to me, without any sort of citation or basis for belief.

The prosecution and charges brought against Aaron Swartz would lead me to believe that you are quite wrong.

Re: Yahoo Hacked

#165
post #154

Earlier quoted context omitted.

If person A walked up to your window and fired shots through it, killing a family member of yours, and then person B walked up to your window out of curiosity (trespassing), saw a dead person, and called 911 (or whatever your country's emergency number is), should person B be prosecuted for murder? Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as…

Since you asked for a downvote explanation: I couldn't make any sense of the comment, even after thinking about it. It's not that I disagree, I can't even figure out the analogy. Are you saying B shouldn't be charged with anything because they didn't murder, or B should be charged with trespassing but not murder, or B should be charged with felony murder because of the trespass, or something else?

The parent asked whether the OP should be treated differently from people actually doing the malicious act. My analogy was meant to illustrate that we should.

I didn't express a stance either way on whether he should be prosecuted for a more minor offense or not, in the analogy's case trespassing. (There are obviously both pros and cons in the precedent set by prosecuting people for revealing their own minor crime on account of reporting a terrible one.)

Re: Yahoo Hacked

#166

Not mentioned in the title, but important: Winzip.com has been hacked as well. Do not trust their binaries. Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him,…

Just to let you know, you can have a chocolate teapot: http://www.bbc.com/news/uk-england-york-north-yorkshire-2912...

Re: Yahoo Hacked

#167
post #160

Earlier quoted context omitted.

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

If you walk by a house seeing someone crack a window and crawl in, do you think it's morally acceptable to trespass on the property to ascertain whether this is a burglary in progress or someone who forgot their key? (This case seems somewhere between my and your example.)

Perhaps, but this case is more like walking by a house, seeing a cracked window, and crawling in yourself to take a look around and see if anyone else might have done the same.

Re: Yahoo Hacked

#168

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

Expose a vulnerable linux VM to the raw internet. Wait for it to get infected. Find the process thats connected to the cnc server using lsof. use gcore to dump its memory to a file. cat that into strings and look for the irc channel and server. Or just watch it all in wireshark but thats kinda boring. Have fun and stay safe.

Re: Yahoo Hacked

#169
post #49
post #8

Mirror of the response, since the site is loading really slow: http://cl.ly/image/2E3D2H2B2d2t

Classic. "Thanks for pointing out this insanely serious issue, which is unfortunately not eligible for our bug bounty program." Maybe they'll send him a free hat.

Embarrassing. People should just sell their zero-days on the black market for BTC until these companies wise up on paying out on "non-qualifying" bugs. Facebook has done this too.

Re: Yahoo Hacked

#170

Earlier quoted context omitted.

TIL - people still use WinZip

It is surprising how many 90s tools remain popular today: WinZip, WinRar, WinAmp, CCleaner, Icq, Real Player, etc. People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar). CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions…

It's a little ironic, but I still find WinAmp to be the best audio player.

I mean - all I want to do is to quickly setup a playlist out of a bunch of directories and eventually do searches in it, which is incredibly common at a party when you quickly assemble playlists from multiple sources. Other media players are completely retarded.

Post reply on HN