10 ms·
GhostShell hacker leaks 39M accounts in security “protest”
- agumonkey 10y agoReading the title I had visions of digital vaccines.
- ryanlol 10y agoHere's another classic team GhostShell zine http://pastebin.com/raw/tEX6yGX6 http://pastebin.com/raw/tEX6yGX6
- aw3c2 10y agoDirect link http://pastebin.com/raw/aNmdgGg4 http://pastebin.com/raw/aNmdgGg4
- kjaftaedi 10y agoThe most interesting thing to me was the evidence posted that other hackers had already penetrated these systems, which I guess goes without saying when you have little to no security in place. Many many years ago when I was younger and playing with buffer overflows and learning shellcode, I'm not saying that I'm proud of this either, but in my journeys I had breached a couple of online retailers, had full access to their databases and internal networks.. of course I alerted them via anonymous e-mails, but what always struck me was the amount of times that I encountered files from 'hackers' just saying that they were here or what have you. Many of them just placing files because they couldn't transverse the NAT, and others who had uploaded ftp scripts but had typos in them so the scripts didn't get deleted like they had planned. Evidence of crimes and theft laying all over the internal network for months or years, and nobody finding it. At some point it's hard not to side with people like ghostshell, because when you're supposed to be responsible for important information, but have seemingly no interest in protecting it, at some point the system is bound to fall apart. I'm reminded of something I read posted by l0pht, way back when, and they just said how much better they were than everyone else because they had jobs at burger king and were dedicated to spending all of their time penetrating networks while their opponents were a bunch of overpaid nobodies who hated their jobs and overall really didn't care, and that they would always win. I think that still holds true today.
- ourmandave 10y agowhile their opponents were a bunch of overpaid nobodies who hated their jobs and overall really didn't care Every sysadmin I've met cares a lot. But they get to rely on products from disparate vendors that are full of zero day exploits and helpful users who are easily socially engineered.
- NuSkooler 10y agoI've known many admins that truly don't give a shit. I've met many incompetent admins as well. Like anyone, they come in many flavors.
- coroutines 10y agoLike Pepperjack? :o)
- ourmandave 10y agoYeah, I read the article and a lot of these were on open accounts with no password required. The most charitable read is they're trying security through obscurity. I wonder if any of them have heard of VNC Roulette.
- arca_vorago 10y agoIve seen my fair share of incompetence and apathy in sysadmin land, but it annoys me so many prople jump straight to that, when it is often management that ties hands and forces sysadmins into those positions. IT is seen as such a money sink, that true and proper workload and therefore workforce requirments are almost never understood, much less met, so you end up with a one man miracle show sysadmin working a 40k job, always on call, who literally doesn't have the time to be proactive. If he or she brings it up with management, their work is often criticized and the budget is whined about and they are lucky to get a teir 1 helper (maybe only part time too!). Companies dont like spending money when they don't have to, and admins are on a whole spectacularly failing to emphasize the risks being introduced to the business because of it, all while generally being overworked and paid crappily and often overtime exempt. I ought to know, I helped start up an IT consultancy and I'd say 3/4 of the clients were picking up after a half incompetent, half apathetic admin... but often it was just because at the end of the day, the admins arent getting payed enough to care that much. So something breaks, costs $money in downtime, forces the C levels to call consultants, and end up spending more than if they had just hired a few extra good people in the first place. So, you arent wrong, but lets not lose sight of the fact that at the end of the day it's managements job to ensure the admins are given the tools they need to succeed, and to check competence levels with metrics you font have to be an admin to understand. They arent though, so thats why I think sysadmins ought to revolt, kick back with a scotch, and watch the world burn.
- pmorici 10y agoWouldn't a better "protest" have been to delete all the databases. That would harm the people responsible for the problem in the first place.
- suprjami 10y agoYou've obviously never heard of backups.
- williamstein 10y agoMongoDB
- amjo324 10y ago"NoSQL, or rather NoAuthentication, has been a huge gift to the hacker community. Just when I was worried that they'd finally patched all of the authentication bypass bugs in MySQL, new databases came into style that lack authentication by design" https://ghostbin.com/paste/6kho7 https://ghostbin.com/paste/6kho7
- update 10y ago> The size of the downloadable cache alone puts it at one of the largest breaches this year -- but it could have been far larger, given time and resources. > "The worst part is that this is barely a fraction of what I could get my hands on," the hacker said. So why didn't GhostShell release everything he could get his hands on?
- 0x4a42 10y agoBecause he didn't bother. His POC is more than enough.
- rincebrain 10y agoPresumably because GhostShell didn't want to leak every bit of accessible data, but merely a subset to illustrate that this wasn't hot air, and shame parties involved into action.
- jlg23 10y agoWhat happened to hacker ethics? Screw over 39 million people to protest the sorry state of the security of a service they have been using? Back in the good old days one would have secured the systems instead of harming the victims again. GhostShell, please stay away from IoT or connected medical devices, I'm afraid you'll kill people just to make a point every security professional already understands.
- Joof 10y agoImplying those people weren't already screwed over. The difference is that now somebody knows about it.
- vonklaus 10y agoI agree with joof. I consider this grey tipping towards white rather than black hat. s/he basically just automated default credentials or autologin attempts, the door was already wide open and there were already numerous pieces of evidence s/he wasn't the only person to know that. If you see a door wide open a curious hacker will look.