Live data from Hacker News

Former Hostgator employee arrested, charged with rooting 2,700 servers

arstechnica.com

51–60 of 61 posts

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#51
This smells really funny. They could have buried this instead of going to court (with a 1+ year delay!) and committing PR seppuku by making this public and giving their clients a reason of distrust. Now, this is indeed the right thing to do, the guy shouldn't go unpunished and they should disclose their security breach, but if they are doing it for the "right" reasons, why is it 1 year later?

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#53

Did these 2700 servers play a role in any DDoS attacks as well? It would be quite a lucrative stance for the employee to sell access to these servers to one or more groups who could potentially make more use of them.

2700 servers all on the same network makes for far less of a DDoS attack then 2700 similar servers on different networks - and it's far easier to detect and block too. They would be more valuable for bitcoin mining most likely.

2700 servers probably wouldn't be worth much for that. It would be noticed fairly quickly, given that only CPU mining would be available, and how monitored servers usually are.

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#55
post #53

Earlier quoted context omitted.

2700 servers all on the same network makes for far less of a DDoS attack then 2700 similar servers on different networks - and it's far easier to detect and block too. They would be more valuable for bitcoin mining most likely.

2700 servers probably wouldn't be worth much for that. It would be noticed fairly quickly, given that only CPU mining would be available, and how monitored servers usually are.

If you can hide the fact that you've rooted a box, you should be able to hide the fact that you're doing bitcoin mining. Worst case, run the mining in the kernel idle thread...

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#56

This all seemed like a pretty run of the mill story about an insider violating company trust, and then getting caught - until the final sentence: "Among other things, a desktop monitoring system that took screenshots of employee workstations in one-minute increments helped Hostgator officials quickly zero in on Gisse." Not something I'd want on my personal system, but it's exactly the sort of thing that I think every…

I don't think this is appropriate for general office use simply because you might leach private data from employees (bank accounts, retirement accounts, medical records, whatever), but in secure, restricted environments I think it's totally appropriate and probably needed.

There is an argument to made that you shouldn't be looking at your personal bank accounts or medical records on a work computer, particularly if you work at a company that cares so little about their employees that they'd implement a system like this.

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#57
post #53

Earlier quoted context omitted.

2700 servers probably wouldn't be worth much for that. It would be noticed fairly quickly, given that only CPU mining would be available, and how monitored servers usually are.

If you can hide the fact that you've rooted a box, you should be able to hide the fact that you're doing bitcoin mining. Worst case, run the mining in the kernel idle thread...

The apocalyptic heat and power use might be a giveaway.

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#58
> "He did not access customer content," Pelanne told Ars. "We caught it well before he had any chance to do any of that."

> Given the rapid discovery, the malware was on Hostgator systems for less than a month.

Then yes, he did. If the malware was on there for more than a few days, I find it extremely unlikely that at least some data wasn't compromised.

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#59

Earlier quoted context omitted.

Anything that lives outside of userspace. If one has root and patience - flash BIOS and wait for a coldboot. One can even get an IP stack to pull down new firmware between boots. The user sees a normal post screen and your hypervisor sees normal hardware adapters. See Jonathan Brossard's 'prior work' slide from his Defcon talk on his work [1] for more details on the state of X86 backdooring. 'Trusted computing' and a…

I know how they work, I'm asking GP to name one that he could have used. There isn't actually much "out there" that is undetectable. You'd likely have to write your own, which is highly non-trivial.

You get what you paid for.

Re: Former Hostgator employee arrested, charged with rooting 2,700 servers

#60
post #56

Earlier quoted context omitted.

I don't think this is appropriate for general office use simply because you might leach private data from employees (bank accounts, retirement accounts, medical records, whatever), but in secure, restricted environments I think it's totally appropriate and probably needed.

There is an argument to made that you shouldn't be looking at your personal bank accounts or medical records on a work computer, particularly if you work at a company that cares so little about their employees that they'd implement a system like this.

It's not so much that the company cares so little about their employees, but that they have so many responsibilities for the data and systems they are entrusted with.

Seriously, though - what everyone I know does in this situation does is just bring their own laptop into work for personal stuff, and treats the work console for precisely that - work activity.

Post reply on HN