Live data from Hacker News

Astalavista.com hacked, including details

astalavista.com

51–60 of 68 posts

Re: Astalavista.com hacked, including details

#51
post #14
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

They did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).

What's the point in offsite backups (for security reasons) if they're connected over network connections?

Re: Astalavista.com hacked, including details

#53
post #14
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

They did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).

I thought the typical definition of offsite backup also means data is backed up to a media like tape and stored in a different location.

How is your offsite backup implemented? Is the data stored on a network drive, or backed up to tape?

Re: Astalavista.com hacked, including details

#54
post #51
post #14

Earlier quoted context omitted.

They did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).

What's the point in offsite backups (for security reasons) if they're connected over network connections?

Physical security, i.e. protection against fires floods and comets, etc.

Re: Astalavista.com hacked, including details

#55

Earlier quoted context omitted.

Offtopic, but please, don't use 'virii'. The correct plural is 'viruses'. 'Virii' is wrong for two reaons: 1) The Latin plural of word ending in -us is not -ii. -i at best. 2) 'Virus' doesn't have a Latin plural, because its meaning is like (in the sense of not having a plural) 'sand': it already denotes a multitude.

Being a Latin geek myself I can't help but point out that nouns in the fourth declension (u stem) also end in -us in singular and receive an -us affix in plural as well. "Virus" is however, in the second declension (virus -i n. "slime, poison, goo") with the oddity of being neutral while having a second declension -us ending which is normally a feature of masculine nouns. And indeed, its plural would be "viri".

Neuter nouns of the second declension don't generally have plurals that end in -i, but rather in -a, so "vira" would be equally possible.

It's also important to note that scholars don't actually know the proper plural of virus because they haven't really found one in extant literature.

Wikipedia has a longer discussion at http://en.wikipedia.org/wiki/Plural_of_virus#Virus

Re: Astalavista.com hacked, including details

#56
post #14
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

They did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).

We use tarsnap (http://www.tarsnap.com) to handle our offsite backups. If you give your production servers write only keys you can mitigate this risk (and not send your backups across the wire in the clear).

Re: Astalavista.com hacked, including details

#57
2.6.18-128.1.10.el5 is the latest patchlevel of RHEL or CentOS kernels. It seems like their security officers are sleeping on their keyboards. Good news for so-called enterprise linux customers. amazon.com? =)

btw, this is merely good quality of system maintaince (of course, their backup system is very funny), but this is very usual way people uses linux and oss nowadays - no one cares to much, thanks to apt-get and yum and xen.

Linux is a mainstream now, nothing special, just stupid, plain activity. It was cool when they were migrated from 2.4 to 2.6 kernel, or even from 2.1 to 2.2 glibc. Today it lost all its coolness and romance.

Just imagine what happening in corporate sector, who hires cheap boys or guys from third-world, like me.

Re: Astalavista.com hacked, including details

#58
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

Offtopic, but please, don't use 'virii'. The correct plural is 'viruses'. 'Virii' is wrong for two reaons: 1) The Latin plural of word ending in -us is not -ii. -i at best. 2) 'Virus' doesn't have a Latin plural, because its meaning is like (in the sense of not having a plural) 'sand': it already denotes a multitude.

The correct term in Hixie English is virii. You need to learn your Hixie English (even the HTML5 standard is written in it).

Re: Astalavista.com hacked, including details

#59
post #34

Earlier quoted context omitted.

Offtopic, but please, don't use 'virii'. The correct plural is 'viruses'. 'Virii' is wrong for two reaons: 1) The Latin plural of word ending in -us is not -ii. -i at best. 2) 'Virus' doesn't have a Latin plural, because its meaning is like (in the sense of not having a plural) 'sand': it already denotes a multitude.

Why is it that the plural of "radius" is "radii" but the plural of "virus" is not "viri"? I don't see "virus" as inherently denoting a multitude in the dictionary. Just curious.

If the plural of goose is geese why is the plural of moose not meese?

Re: Astalavista.com hacked, including details

#60
post #2

Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups. For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer…

you're mistaking astalavista.box.sk with astalavista.com.

astalavista.com stole their name to ride on their popularity.

Post reply on HN