Live data from Hacker News

Hacker tries to compromise and resell an internet-facing Linux server

morris.guru

21–30 of 73 posts

Re: Hacker tries to compromise and resell an internet-facing Linux server

#21
post #16

Absolutely fascinating. I've been "in and around" the security community (not a part of) for years now, and never heard of a company offering a service like this. I love how he gives advise to the company at the end. I mean c'mon you get root access via dictionary attack within a quick timeframe and you don't think it is a honeypot?

I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.

[deleted]

Re: Hacker tries to compromise and resell an internet-facing Linux server

#22

All of this is outside my experience, so I have to ask - how does the attack, as described, prove HutHos is the perpetrator? The poster was able to find the HutHos site owner's full information "in a few minutes", due to "poor operational security practices." Doesn't this raise the possibility that the HutHos server was compromised by the malware's true owner?

It's because the script appears to be taking control of servers for hosting purposes. In other words, the simplest explanation is that Huthos is taking control of machines so that they can sell them to customers as their own VPS service.

A VPS provider having a server provisioning script available doesn't seem to be such a crazy thing to me - it still doesn't prove that Huthos are behind the attacks.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#24
Not to say that Huthos are innocent, but I don't see any concrete proof that they are behind this attack. The fact that they are hosting a server provisioning script is hardly crazy, given that they are a hosting provider. What's to say that the ACTUAL attacker didn't just come across the provisioning script and decide to use it for themselves? The script URL is listed publicly online: http://yandicunk.blogspot.co.uk/2015/03/cara-setting-dan-ins... & http://huthos.com/tutorial/autoscripthuthos.html

"It also appears that the hackers attack machine may be hosting an unauthenticated web proxy" makes it sound like the attacker owns the machine they were connecting from. IMO, chances are that "49.213.23.171" is just another compromised box.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#26
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

Given that the attacker is unknown, the correct term would be they or them. Gender is unknown, a gender neutral description should be used.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#27
post #14

While interesting, I'm not sure how I feel about him ending the article with solid advice for criminals on how to avoid getting caught.

I'm the author of this post. You mention a tough philosophical quandary that I struggle with every time I share information with the rest of the world.

As much as I hate giving attackers anything, I am very dedicated to information sharing so that people can learn as much as possible from my posts. The truth is always out there one way or another. I would rather everybody be as educated as possible. Hopefully that makes sense.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#28
post #16

Earlier quoted context omitted.

I rather doubt they actually care if the target server is a honeypot or not, it looks like they're just looking for free hosting.

If that honeypot is a blogging security activist that is going to out them, they might care.

If they didn't want to get outed they would probably be trying to conceal themselves in the first place. Often there's no need for that.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#29
There are three 'knobs' to the cloud today: compute, storage and networking. A new emergent 'knob' for the cloud is trust. Trust affects three primary features of the cloud: how it's paid for (credit vs. capital expenditure), how it works (standards vs. custom solutions) and who I am (identity management vs. anonymous use). I won't go into it much here, but cryptocurrencies play a part in this knob, big time.

In Huthos case, they 'hack' the credit part by simply taking a machine with poor identity management in place (honeypot) and then provide a high level of anonymization for their customers (the 'who I am' above) and providing it as a standard way for extending a VPS offering (which itself provides 'who I am' services).

It's all about trust, and what's the most irritating part about it is that the violate it first before they get to selling it to others. Crazy.

Re: Hacker tries to compromise and resell an internet-facing Linux server

#30
post #18

On a slightly unrelated note, I like how the author referred to the attacker with she/her, a small detail I can appreciate since they normally refer to them with he/him.

Considering the writer supposedly knows the attackers identity, I don't really see why they'd use the wrong gender pronouns.
Post reply on HN