Live data from Hacker News

New ‘Meow’ attack has deleted almost 4k unsecured databases

bleepingcomputer.com

401–410 of 544 posts

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#401
post #386

Earlier quoted context omitted.

Seriously this is the most annoying thing ever, especially if someone on your team things you need to expose the ports to redis in a docker compose. I’ve come back from a weekend where my redis instance was being used for crypto mining. Anything that is insecure by default in 2020 should be killed off IMO.

Secure by default is super onerous though. What if I just want to try out something before committing to it, do I really need to jump through a bunch of security hoops?

Absolutely. Laziness isn't an excuse for not caring about security. Security should be the top of your mind any time you connect anything to the internet.

The fact it's not, is why we're seeing major attacks/leaks/etc almost every single day now.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#402

Works great. You can already find questions on Stack Overflow from people getting their database deleted https://stackoverflow.com/questions/63067062/elastic-search-... Edit: The person raising that question is working for Atlassian (Jira), looks like Atlassian got their database deleted lol

If meant as a public service, it would have been much less destructive to use the change passwords API [0] to set random passwords for all of the users.

[0] https://www.elastic.co/guide/en/elasticsearch/reference/curr...

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#403
post #387
post #195

It's stuff like this that reminds me that the internet is in many ways still in a loosely regulated, "Wild West" state. This is pretty clearly willful destruction (I.e. vandalism; https://legal-dictionary.thefreedictionary.com/Willful+damag... ). It's illegal in the real world, and should be illegal in the digital world. A lot of people are saying that organizations that had these DBs in public "had it coming", or "n…

1) This is not the "real world". 2) Even if it were, and my twenty-something assistant left my shop door open at night consistently, to me, the question of the legality of the resulting damage would be rather secondary.

What if your shop door was locked but was laughably easy to open with lockpicks? I get to victim blame you for choosing an insecure lock and browbeat you into purchasing more expensive and onerous security.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#404

Works great. You can already find questions on Stack Overflow from people getting their database deleted https://stackoverflow.com/questions/63067062/elastic-search-... Edit: The person raising that question is working for Atlassian (Jira), looks like Atlassian got their database deleted lol

I hate to laugh when people's hard work is being destroyed, but this is some impressive trolling by the attacker:

> An interesting theory as to why the attacker used the term "meow" is because cats like to drop (or knock) items from tables.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#405

ELI5: Way back in the early 2000s I was a young mid level developer and we had a SQL Server backed solution. There was a wide spread attack on Sql Server installations that didn’t change the default blank SA password. We were one of the companies that didn’t. But, even then I knew not to have a publicly accessible database server. We just didn’t give the server a public IP address. Nothing fancy. We weren’t affected…

> Why do people keep making the same mistake?

Because there are always new developers showing up that haven't been taught. (Eternal September if you will)

The real solution would be:

1. We are past the point were our practice needs professional licensure. We need standards, a governing body, and ethics.

2. Those above items need to be taught to new developers. How long has security been an after thought to CS degree programs? I know I never touched it in an academic setting. We didn't even have a class that covered it. You wanted to learn about it you had to seek it out.

3. Vendors to do the right thing and stop offering default passwords. That isn't going to happen, so we have to force them to, either trough legislation or through other means.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#406

ELI5: Way back in the early 2000s I was a young mid level developer and we had a SQL Server backed solution. There was a wide spread attack on Sql Server installations that didn’t change the default blank SA password. We were one of the companies that didn’t. But, even then I knew not to have a publicly accessible database server. We just didn’t give the server a public IP address. Nothing fancy. We weren’t affected…

Because you're completely wrong; what you're advocating is nothing more than security by obscurity. An address is just an address; it tells you where something is. If you don't have a firewall in place, then any attacker who cares enough to actually route a packet to your internal servers can access them. If you do have a firewall in place, then an attacker gains nothing from knowing the address of a server they can't send any packets to. Private networks add a huge amount of complexity with its own security holes (they're easy to scan once you're inside them, a lot of operating systems treat them as somehow "safer" than the public internet...). They do more harm than good.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#407
post #386

Earlier quoted context omitted.

Secure by default is super onerous though. What if I just want to try out something before committing to it, do I really need to jump through a bunch of security hoops?

Absolutely. Laziness isn't an excuse for not caring about security. Security should be the top of your mind any time you connect anything to the internet. The fact it's not, is why we're seeing major attacks/leaks/etc almost every single day now.

Right, well now we know why secure by default isn't a thing. If your product is super onerous to use, people will switch to a competitor that is easier to work with.

A secure by default product is a dead on arrival product.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#408

Earlier quoted context omitted.

...wrong regardless... That obviously isn't true. Some data shouldn't exist: CP. Some data can exist, but it's backed-up so well that deletion is never a problem. For example, I'm not going to forget my birth date any time soon! In fact, very little of the information that businesses have about me needs preservation. I remember it all, and if I decide the business still deserves it I can give it to them again. It is…

So your argument is that any random person is in a position to evaluate whether someone else's "data shouldn't exist" and take unilateral action to delete it? And are you suggesting that in this particular case the person launching this attack is taking time to evaluate the nature of the data before taking action? > I'll just assume that all the "victims" who don't want to go into too much detail about the "lost" dat…

I didn't just invent this idea that businesses are careless with data their customers would prefer to be kept private. Basically every breach we ever hear about features this prominently. Somehow we've created an economy in which there exists a vast asymmetry between corporations who pad their books a few percentage points by abusing their position and the humans who suffer such abuses. The fact that the publicity of small bits of data about a human can cause that human massive harms is itself a contingent creation of our screwed-up system, which benefits the giant companies whose lobbyists write the laws. It's as if someone decided we should all live under the "protect your True Name at all costs" system from the Earthsea novels, without giving any of us any way to do that.

There's very little a customer can do to determine how or even whether her confidential data is protected. Even if she had this knowledge, in many cases she can't just decide to do business elsewhere. In many cases she was never a customer in the first place! In this context, an open database is like a shoddily constructed tall building that will collapse at the first stiff breeze. It shouldn't exist, and anyone who destroys it upon discovering it is doing humanity a service. Even if the building's owners had somehow kept the general public out (which you'd like us to assume), those owners themselves increased their danger with every bit of data added. Now, since the building has been destroyed, its owners and occupants are no longer in steadily increasing danger.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#409

Earlier quoted context omitted.

>tree^H^H^H^Hgraph If we pretend we're using readline here, ^W (yank previous word) and ^U (yank to the start of the line) should save you some key presses. Some recommended bedtime reading: https://catonmat.net/ftp/readline-emacs-editing-mode-cheat-s... https://en.wikipedia.org/wiki/GNU_Readline#Emacs_keyboard_sh...

These are not emacs commands. They aren't even unix shell commands. They are TTY commands, some of them dating back to the dot matrix teletype terminals. My favorite is ^U, which 90% of the time lets you start over on a password prompt when you are sure you just fat fingered but not sure how badly.

I think you might be conflating these (or maybe I should say the gp is). Nevertheless.

Do you have a reference to the history of key combos like ctrl f, b, n, p and a and e? Those are typically referred to as emacs style navigation and I am genuinely unaware of history of those as common tty control codes outside of emacs for cursor movement. They weren’t dec vt control codes. Ctrl-U was though and even has ASCII assignment as “NAK”. Ctrl-H and C are similar.. but people don’t typically refer to those as “emacs” keys.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#410
post #378
post #346

Earlier quoted context omitted.

First thing I always do on any new VPS is to sort out SSH (disable root login, disable password login), set up fail2ban, install and configure ufw... and if I need to set up something like redis or similar, make sure it only listens to internal connections and also that it is decently auth'd. For deployment and other things I make users that can only write to certain directories; no sudo. It's nothing new or special…

Do you know of any good resources for learning this stuff? I'm interested in being able to do this sort of thing on a small scale, but there seems to be an awful lot that I don't know I don't know.

https://github.com/konstruktoid/hardening

What the parent post said is pretty much it in a nutshell, but I use that GitHub for basic Ubuntu server setup.

Post reply on HN