5 ms·
Hey guys, I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactl
by ElliotSpeck 16y ago
Hey guys,
I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down.
phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site.
My work was slightly different, I was proving that the system was horribly exploitable. Throughout the process I burnt into the box, gained root access, and took a screenshot. I also gained access to the phpFog Twitter account and posted a bit. I didn't damage any files, and when I finally came into contact with Lucas, I explained my methodology directly and gave him a few security pointers for immediate causes for concern. As a result, the project is now on standby as they fix up the issues that were made apparent by my break-in.
I don't consider what I did to be a bad thing. It's better me break in and make the fact I did public, than someone break in silently and wipe the box, losing hundreds of hours of both the team's and clients' time. That is below any moral standard I could possibly even consider upholding.
What I did not do:
-Damage or otherwise alter any of the system files
-Damage, alter or view any client files
-Post or otherwise make public the methodology behind my access
-Post or otherwise make public the engine code for phpFog, this was done by someone else who I showed the code to in order to investigate further potential security holes before I alerted the phpFog team.
I'm posting here to clear the air, but if you have any questions you can contact me on Twitter: @ElliotSpeck.
- ianl 16y agoI would consider, " I also gained access to the phpFog Twitter account and posted a bit." to be a dick move.
- ElliotSpeck 16y agoWould you rather that I hadn't, and instead just wiped the box? How about I changed every DNS record for every domain to something like goatse.cx? In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lucas about an hour later.
- nbpoole 16y agoThat's a false dichotomy. You didn't have to post on their Twitter account, just like you didn't have to wipe a box or alter DNS. I hope if you learn one thing from this, it's how real responsible disclosure works.
- ElliotSpeck 16y agoI didn't have to at all, correct. But like you said, one doesn't have to wipe the box or redirect everything to goatse, however if you give many people the ability, there will be 10% who will do it. In perspective, me posting on the Twitter account (which was easily remedied, and like I said control was willingly relinquished) wasn't much of a bad thing.
- nbpoole 16y agoOn a relative scale? Yes, wiping the system is much worse. On an absolute scale? They're both still bad: the lesser of two evils is still an evil. ;) http://en.wikipedia.org/wiki/False_dilemma http://en.wikipedia.org/wiki/False_dilemma
- ElliotSpeck 16y agoI never claimed what I did was a good thing.
- nbpoole 16y agoWell, in your original post you said: "I don't consider what I did to be a bad thing." So if you don't consider your actions to be bad or good, that means you think they're neutral? ;-)
- ElliotSpeck 16y agoNo. I 'think' what I did was a relatively good thing. I never claimed it was, nor would I use that sort of thing as a defence. Everything that I have a say in is under control of phpFog now, and no data was lost. Anything further is completely out of my hands, I can only do so much.
- nbpoole 16y agoSo, just to clear something up: those links to PHPFog code are dumps that you leaked to a third party, who then posted up this website?
- ElliotSpeck 16y agoThe website was allegedly posted before I obtained the engine code, however it then went on the site after I gave a copy of the engine code to someone in order to analyze and look for further exploits. To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The files were destroyed from the server after.
- nbpoole 16y agoAha. That's an unfortunate situation for you. Ultimately though, it seems like you dropped the ball by leaking the code to someone else: even if you weren't responsible directly for the site or for posting the code publicly, you were the one who made it possible. Hopefully you can learn from this experience. --- Edit: You said "To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The files were destroyed from the server after." If that's the case, then mind explaining this? https://twitter.com/#!/communistcake/status/49340298677075968 https://twitter.com/#!/communistcake/status/4934029867707596...
- ElliotSpeck 16y agoYes, I can explain that. The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew. I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a rash and irresponsible person as you can tell from that tweet.
- sucuri2 16y agoIt seems to be from one of your friends: phpfogsucks.com is hosted with tomato.compwhizii.net: http://sharingmyip.com/?site=phpfogsucks.com http://sharingmyip.com/?site=phpfogsucks.com Which is owned by John Du Hart ( http://johnduhart.me/ http://johnduhart.me/ ) . You guys could be in a lot of legal trouble if they decide to press charges.
- citricsquid 16y agoThe worst thing is, this guy (compwhizii) is sort of important online, he is the system administrator for facepunch.com, a very large forum. I guess he'll be losing that job.
- ErrantX 16y agoI think the takeaway that you should have from this is; the person you showed this exploit to is not trustworthy, I'd avoid associating with them in the future.
- webwright 16y ago"It's better me break in and make the fact I did public, than someone break in silently and wipe the box, losing hundreds of hours of both the team's and clients' time." It's better yet to break in and discreetly notify the folks involved. Show a screenshot at Twitter.com that you COULD have tweeted. Voila-- you've done something positive. Going public is an immature ego play that doesn't consider the feelings of lots of folks. Even if you want the the ego boost, post a "How I saved PHPfog" post-mortem when the issue is resolved. Shame on you.
- deleted 16y ago[deleted]
- troydavis 16y agoI see: "I was proving that the system was horribly exploitable." but I read: "I was exploiting a horribly exploitable system that, had I notified the admins, almost certainly would have been dealt with fast by some guys who obviously care about their service. If it wasn't, I could have still released it publicly a few days later like every other pen tester anywhere. Instead I went for the lulz. Now I'm backpedaling by justifying bad behavior with worse behavior, editing posts, and blaming people who I told, instead of just admitting I handled it really, really badly." Personally, I didn't know PHPFog beyond the name, but your jackass move makes me want to actively support them. And don't kid yourself - nothing you did after finding the vulnerability was in the best interest of PHPFog's users. This isn't pen testing or stumbling across a vulnerability. Telling someone else who released stolen code makes it quite black hat.
- deleted 16y ago[deleted]
- jpadvo 16y agoHi Elliot, I appreciate that you discovered a security flaw and took action to get it fixed. Thank you. However, the WAY you did this really screwed up a bunch of people. I have an app running on PHP Fog that serves 25,000 people a day, and I woke up on Sunday morning to a stream of complaints that it had been down for hours. You seem technically capable, so I'm sure you have a lot of interesting (and useful) projects and hacks to come. But next time you do something like this, model it after this: http://daverecycles.com/post/2858880862/heroku-hacked-dissecting-herokus-critical-security http://daverecycles.com/post/2858880862/heroku-hacked-dissec... If you're hacking to help people and make the world a better place, do it like David Chen. With your abilities you will get a lot of respect and appreciation if you do it like that. If you act destructively, some people might appreciate your technical chops but you won't get real respect in the field. And don't worry too much if it feels like you're at the center of a cyclone right now. It'll pass, and as long as you act more deliberately in the future you'll be okay. :) - Jason
- wooter 16y agoUnfortunately, that cyclone may not be as easy to get past. Yes, people won't forever care about phpfog. However, if phpFog (which was at least PARTIALLY at fault here) presses charges, thats a criminal record and will come up on every background check for the rest of his life. This effects job opportunities, VISA opportunities, loans (not to mention lawyer debt from fighting it), hell even insurance prices. What the kids did was bad, but I think pressing charges and seriously hindering two smart sixteen year-olds is a knee-jerk, over-zealous application of law and retaliation/punishment. Especially (I know I'm going to draw a lot of heat for this) when they found THEIR irresponsible storage of sensitive data. I am a dev. I have also worked in the computer security field for a reputable firm. What phpfog did was irresponsible(actually, stupid!) and it was relatively easily avoidable. I know this because I (along with pretty much every dev) have used the exact stopgaps and quick-fixes that phpFog did. BUT (big lesson) cleaning up after your self is as much a part of programming as putting those quick-fixes in place. Unfortunately, its not the "fun" part and its not the most obvious money maker. Like they (pretty much) said, phpFog put off the fixes because they wanted to deliver quickly. Thats THEIR decision and THEIR risk/reward assessment. I've made the same assessments in my work. They should suck it up and learn the lesson. Not hurt little kids. They're lucky it was found by these kids and not someone that knows how to conceal their identities and/or wants to do more serious damage (For example, hurting a phpFog clients). If I knew some dev at my hosting company was keeping system passwords on a web server, they wouldn't be my hosting company. What about the trust/confidence of the clients that phpFog was knowingly betraying? Edit: Yes, there is a proper way to disclose information. They're kids. I'm surprised they handled it as well as they did to be honest. I was a much dumber 16 year old.
- Timzzz 16y agoDude, are you aware that this is a federal crime in the US? They have extradition treaties with AUS. You need to get your parents to get you a lawyer - FAST
- deleted 16y ago[deleted]