Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?
I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.
Hacker tries to compromise and resell an internet-facing Linux server
21–30 of 73 posts
Re: Hacker tries to compromise and resell an internet-facing Linux server
#22All of this is outside my experience, so I have to ask - how does the attack, as described, prove HutHos is the perpetrator? The poster was able to find the HutHos site owner's full information "in a few minutes", due to "poor operational security practices." Doesn't this raise the possibility that the HutHos server was compromised by the malware's true owner?
It's because the script appears to be taking control of servers for hosting purposes. In other words, the simplest explanation is that Huthos is taking control of machines so that they can sell them to customers as their own VPS service.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#23On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#24"It also appears that the hackers attack machine may be hosting an unauthenticated web proxy" makes it sound like the attacker owns the machine they were connecting from. IMO, chances are that "49.213.23.171" is just another compromised box.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#25Re: Hacker tries to compromise and resell an internet-facing Linux server
#26On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#27While interesting, I'm not sure how I feel about him ending the article with solid advice for criminals on how to avoid getting caught.
As much as I hate giving attackers anything, I am very dedicated to information sharing so that people can learn as much as possible from my posts. The truth is always out there one way or another. I would rather everybody be as educated as possible. Hopefully that makes sense.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#28Earlier quoted context omitted.
I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.
If that honeypot is a blogging security activist that is going to out them, they might care.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#29In Huthos case, they 'hack' the credit part by simply taking a machine with poor identity management in place (honeypot) and then provide a high level of anonymization for their customers (the 'who I am' above) and providing it as a standard way for extending a VPS offering (which itself provides 'who I am' services).
It's all about trust, and what's the most irritating part about it is that the violate it first before they get to selling it to others. Crazy.
Re: Hacker tries to compromise and resell an internet-facing Linux server
#30On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.