Live data from Hacker News

New ‘Meow’ attack has deleted almost 4k unsecured databases

bleepingcomputer.com

231–240 of 544 posts

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#231

People are talking about more responsible disclosure. Is it feasible to even track down the owners of 4,000 different unsecured databases, much less go through the whole process with them to ensure the database is properly secured?

When that SQL Server worm was going around I had three or four different machines spamming my firewall trying to search for more victims, but I was only able to track one of the IP addresses back to contact information.

That person was very grateful for the heads up, but the other three were SOL.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#233
post #195

It's stuff like this that reminds me that the internet is in many ways still in a loosely regulated, "Wild West" state. This is pretty clearly willful destruction (I.e. vandalism; https://legal-dictionary.thefreedictionary.com/Willful+damag... ). It's illegal in the real world, and should be illegal in the digital world. A lot of people are saying that organizations that had these DBs in public "had it coming", or "n…

> It's illegal in the real world, and should be illegal in the digital world

It is illegal in the USA. And is easily an arguable civil case as well. The problem is identifying the perportrator.

Organizations are only way to hold poor actors accountable. Bad PR and going out of business cause data critical to operations has all been deleted are strong incentives. Unfortunately businesses typically lobby for harsh laws, tyrancial surveillance rather than the expensive and difficult process of improving their operational security.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#234

Earlier quoted context omitted.

My blame scale for breaches, most to least: 1) the cultural and economic forces driving everything online way before that’s anything like a good idea, 2) companies storing more than they need to, 3) the people who left it unsecured (bigco, tech startups, and anything very sensitive), 4) the people stealing data, 5) the people who left it unsecured (Smaller shops that’ve been made to feel they must be online), [large…

Why is the person doing the deleting so low, relatively speaking, in your ranking of people's responsibility for them doing the deleting? Also, do you think that this person or persons would refrain from deleting the data if they had the opportunity, but it qualified as a "good idea" to keep online? I.e. they might review, say, medical records, spend some time thinking to themselves whether it was 'necessary' to be o…

For me, it's because the odds of this person showing up quickly approach 1 as time approaches infinity, and that person's effect would be nil if it weren't for necessary causes 1) through 19).

Blaming the person that hacked you is like blaming the individual rock that sinks your boat when you navigate too close to a rocky shore. The rock may have done 100% of the damage to your boat, but if it hadn't been that rock, it would have been another one.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#235

Earlier quoted context omitted.

My guess would be that they went with "ports" instead of "expose" which makes it public. But even with careful composition of your docker-compose you might want to be careful, Docker can interact with iptables in surprising ways and long iptables rulesets are almost comically difficult to validate sometimes. The result is that if you're using both Docker (and even more if you use Compose, Kubernetes, some other orche…

Friendly FYI, "EXPOSE" is a no-op that is only meant as visual documentation to end-users. "The EXPOSE instruction does not actually publish the port. It functions as a type of documentation between the person who builds the image and the person who runs the container, about which ports are intended to be published." Second paragraph: https://docs.docker.com/engine/reference/builder/#expose

I'm referring to docker-compose, where 'port' and 'expose' are container configuration options that behave differently from the Dockerfile keyword.

Although the similar words with different meanings no doubt contribute to confusion.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#236
post #32

Earlier quoted context omitted.

This is more akin to a person knowing the basics of driving a car but not which side of the road to use or what to do at a traffic light. They are a danger to themselves and others, the others in this case being the users of whatever services the unsecured databases provide. My sympathy for people learning the basics of our field and missing a few points stops when others are harmed.

Although the parent's analogy is arguably flawed, there's a very good point in the fact that there are users who are not involved in the implementation of the service - "People with IoT apps for their home". They're not drivers, to follow the driving analogy. It's unrealistic to expect that the population at large starts to pay a significant attention, in particular because the services/gadgets are a black box. How d…

> Given the large-scale nature, probably some form of regulation would be the most realistic mitigation.

Rather than regulation, how about trademark-protected certification? I.e., similar to what Underwriter Laboratories ("UL") does for consumer electrical products in the U.S.?

Except rather than the government requiring certification by UL or similar, organizations could simply decide for themselves whether or not to use uncertified products. And perhaps insurance companies could price certification status into relevant policies.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#237
post #90
post #88

Earlier quoted context omitted.

I don't find your example very convincing. Any database storing personal data needs to be properly secured, and if that gym also has ID credit card or other more sensitive data, that data might better be destroyed than stolen. If it's a publicly accessible wiki with no sensitive data whatsoever, and that's meant to be publicly accessible, then there's a reasonable excuse for the poor security and it's not helping any…

Why should innocent users be punished? Why not just send a pic confirming you have full db access? This is just unnecessary vandalism.

The point is that, if my credit card info is staying in a web-exposed, insecure DB, it is safer for me that it be destroyed than left alone.

I have no idea of that is the intention of the attackers, or if they are maybe even stealing the info before deleting it. But assuming they were good Samaritans and just deleting it, that is the best outcome for me as a user, better than if it stayed up for another day.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#238
post #27

If the databases in question (Elastic, MongoDB, others) make it too easy to set up unsecured access, possibly because they default to an unsecured state on installation, then some good may come of this: The reputation hit to the database vendors should encourage them to mend their ways. If that happens, then the attack can arguably be justified despite the damage — consider all the future database installations which…

Apparently these guys don't have a firewall setup and haven't heard about private networks and VPNs. reads TFA again Wait, one of the victims is a VPN provider???

I've read that there are now VPN providers that just use someone else's VPN engine. So they don't have to know wtf they are doing.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#239

Earlier quoted context omitted.

The possibility of someone stealing your identity (or worse) far outweighs the damages from losing some coupons. Deleting exposed databases is genious, there need to be real repercussions for companies if they leak user data.

> The possibility of someone stealing your identity (or worse) far outweighs the damages from losing some coupons. That is a very rich person statement.

Not really, it's much easier for rich people to reclaim their identity than it is for poor people.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#240
post #146

Earlier quoted context omitted.

What happens when mom & pop are storing your name and credit card # in plain text and then your identity gets stolen and credit ruined? Should we still be "charitable" to them and their d-bag nephew?

Your credit card number being stolen is a problem for your bank, not a problem for you. You can't steal someone's identity with a credit card number. The concern in this case is when there is some social problem with being in Mom & Pop Inc's customer database. There are probably some people that buy some things that they don't want other people to know about. When the database gets hacked and you are linked to being…

It's still a PITA when my credit card has to be swapped.
Post reply on HN