Live data from Hacker News

Astalavista.com hacked, including details

astalavista.com

31–40 of 68 posts

Re: Astalavista.com hacked, including details

#32
post #26
post #8

This somewhat concludes the whole point of the hax0rs: Quote: "plaintext passwords? yes, those so called "security professionals" who charge you $6.66 / month to register at their hack-proof portal, save your passwords in plaintext... brilliant!"

I especially liked "philip"... one of the 100 most common boy names. dark side of me : I wonder how many of those passwords work to get into those e-mail accounts...

or bank accounts

Re: Astalavista.com hacked, including details

#34
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

Offtopic, but please, don't use 'virii'. The correct plural is 'viruses'. 'Virii' is wrong for two reaons: 1) The Latin plural of word ending in -us is not -ii. -i at best. 2) 'Virus' doesn't have a Latin plural, because its meaning is like (in the sense of not having a plural) 'sand': it already denotes a multitude.

Why is it that the plural of "radius" is "radii" but the plural of "virus" is not "viri"? I don't see "virus" as inherently denoting a multitude in the dictionary. Just curious.

Re: Astalavista.com hacked, including details

#35
post #14
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

They did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).

Definitely a much better method of handling backups. Completely agreed.

Re: Astalavista.com hacked, including details

#36

Earlier quoted context omitted.

Good point. The kernel version in the transcript looks like the version I've got on a CentOS machine, so it's probably patched. Interestingly, the strings ("r00tr00t", "Executing shell") from the local-root tool they're using don't appear anywhere online, suggesting that it's something private and potentially unknown.

maybe it's just not indexed.

It's easy to modify strings in a simple C function/program. That's all that would be needed to modify and display the "r00tr00t" etc you are mentioning.

Re: Astalavista.com hacked, including details

#38
post #33

When a site is reported as 'hacked', am I alone in not wanting to visit it for a look-see? Aren't the same people who deface sites likely to try fresh browser compromises against rubberneckers?

I doubt quality folks such as the one's participating here at HN would ever post a link to a site, even a defaced one, that would potentially harm anyone visiting it.

Re: Astalavista.com hacked, including details

#39
post #9

That was painful to "watch" happen to them. Lesson learned. Do NOT f * with hackers...

Yes and the fact that there are always smarter people with more time on their hands than you out there on the internet.

Well, I guess they deserve it for screwing people over $6.66/month at a time for 15 years for distributing publically available material (literally).
Post reply on HN