Live data from Hacker News

Phpfog "Down for maintenance"

phpfogsucks.com

91–100 of 125 posts

Re: Phpfog "Down for maintenance"

#91
post #72

Earlier quoted context omitted.

PHP is just as secure as any other language. It's the programmer's best practices (or lack of) and implementation that can make the code secure or insecure. The language is mature, actively maintained, and has a nice standard lib (debatable). Whether or not YOUR program will be secure depends on you the PROGRAMMER not the language.

So does that mean ec2 is insecure? Or is the flamewar about how the article is really about the writer blaming their problems on something thats really not at fault. Meaning php or ec2? Thanks!

phpfog's setup was insecure. It was completely unrelated to PHP. EC2, or anything other than phpfog's sysadmin's skills.

Re: Phpfog "Down for maintenance"

#92

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

"It's better me break in and make the fact I did public, than someone break in silently and wipe the box, losing hundreds of hours of both the team's and clients' time."

It's better yet to break in and discreetly notify the folks involved. Show a screenshot at Twitter.com that you COULD have tweeted. Voila-- you've done something positive.

Going public is an immature ego play that doesn't consider the feelings of lots of folks. Even if you want the the ego boost, post a "How I saved PHPfog" post-mortem when the issue is resolved.

Shame on you.

Re: Phpfog "Down for maintenance"

#93

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

I see:

"I was proving that the system was horribly exploitable."

but I read:

"I was exploiting a horribly exploitable system that, had I notified the admins, almost certainly would have been dealt with fast by some guys who obviously care about their service. If it wasn't, I could have still released it publicly a few days later like every other pen tester anywhere. Instead I went for the lulz. Now I'm backpedaling by justifying bad behavior with worse behavior, editing posts, and blaming people who I told, instead of just admitting I handled it really, really badly."

Personally, I didn't know PHPFog beyond the name, but your jackass move makes me want to actively support them.

And don't kid yourself - nothing you did after finding the vulnerability was in the best interest of PHPFog's users. This isn't pen testing or stumbling across a vulnerability. Telling someone else who released stolen code makes it quite black hat.

Re: Phpfog "Down for maintenance"

#94

Earlier quoted context omitted.

Do you have a link for that tweet? Or a screen-capture?

http://twitter.com/compwhizii/status/48172082667864065 (I had to create a different account because I have no_procrast activated on my main account. It'd be awesome if no_procrast would be automatically disabled during the weekend.)

During which weekend? For my new place of work that would be on Friday & Saturday..

(Just a quick note that some features are harder than it seems at first)

Re: Phpfog "Down for maintenance"

#95
post #79

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

It seems to be from one of your friends: phpfogsucks.com is hosted with tomato.compwhizii.net: http://sharingmyip.com/?site=phpfogsucks.com Which is owned by John Du Hart ( http://johnduhart.me/ ) . You guys could be in a lot of legal trouble if they decide to press charges.

The worst thing is, this guy (compwhizii) is sort of important online, he is the system administrator for facepunch.com, a very large forum. I guess he'll be losing that job.

Re: Phpfog "Down for maintenance"

#96
post #78
post #33

Earlier quoted context omitted.

This is just precious: @ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :) As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowled…

> broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime. This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.

There are numerous facts which disclosing would be considered a crime. For one thing, copyright infringement is a crime; all that is, in essence, is disclosing a fact. Disclosing trade secrets may be a crime. Disclosing personal health records can be a crime. Disclosing insider information to a third party can be a crime. There are plenty of facts which can be criminal to disclose.

Now, this particular case may or may not be criminal, but it is at least incredibly irresponsible.

Re: Phpfog "Down for maintenance"

#97

Earlier quoted context omitted.

I don't think they are obfuscating it. If I remember correctly, their pricing page made perfectly clear that they used dedicated EC2 instances. Just for the record - the cheapest EC2 instance type is t1.micro, and amounts to ~15 USD/month (+EBS and IP costs). I didn't see their business plan so I can't tell what is their big picture about that :-)

If they use reserved instances, it should be even less than that. They still need to control abuse in terms of bandwidth, etc. and that is the difficult part.

It should be easy enough to throttle bandwidth on the instances.

Re: Phpfog "Down for maintenance"

#99

Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down. phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site. My work was slightly different, I was proving that the system was horribly exploitable. Throughout the…

Hi Elliot,

I appreciate that you discovered a security flaw and took action to get it fixed. Thank you.

However, the WAY you did this really screwed up a bunch of people. I have an app running on PHP Fog that serves 25,000 people a day, and I woke up on Sunday morning to a stream of complaints that it had been down for hours. You seem technically capable, so I'm sure you have a lot of interesting (and useful) projects and hacks to come. But next time you do something like this, model it after this:

http://daverecycles.com/post/2858880862/heroku-hacked-dissec...

If you're hacking to help people and make the world a better place, do it like David Chen. With your abilities you will get a lot of respect and appreciation if you do it like that. If you act destructively, some people might appreciate your technical chops but you won't get real respect in the field.

And don't worry too much if it feels like you're at the center of a cyclone right now. It'll pass, and as long as you act more deliberately in the future you'll be okay. :)

- Jason

Re: Phpfog "Down for maintenance"

#100
post #90
post #49

Earlier quoted context omitted.

Did you not RTFA? The article is about a PHP hosting company that is getting merc'd because of the security flaws inherent in PHP that lead to their design decision to use Amazon EC2.

The exploit was not anything to do with PHP. A section of their site was allowing to users to execute commands under a user which they should not have been allowed to. This could have happened under any programming language.

Especially given that their codebase is apparently Ruby and not PHP.
Post reply on HN