3 ms·
Default web server set up would log all HTTP requests. It's trivial to see which (internal) IP addresses connecting around that timestamp.
by boomzilla 13y ago
Default web server set up would log all HTTP requests. It's trivial to see which (internal) IP addresses connecting around that timestamp.
- untog 13y agoIt wouldn't be an internal address. As the article states, an Uber employee logged on using their friend's laptop. I'd be surprised if they did that at an Uber office.
- dclusin 13y agoYou can subpoena ISP's to see who owned an address (I believe) up to 6 months back. How exactly do you think the RIAA filed so many lawsuits against internet pirates?
- ChuckMcM 13y agoThink that through, the Uber dashboard is going to be protected by a login regardless of the IP used. Somebody's login was used to access the dashboard at that exact time stamp which will be in the logs. And every web server logs this stuff as a matter of course, and every operations group keeps those logs to scan for unexpected accesses from outside the company or from former employees etc etc.
- potatolicious 13y agoI don't know any company - even small ones - that keep internal stuff like that in the open. I'm willing to bet the Uber employee was on a VPN at the time, which narrows the search considerably. I doubt Uber was secure/paranoid enough that the timestamp will immediately yield the leaker - but between webserver logs, VPN logs, etc etc, there's probably enough information there to deduce the culprit, especially if this occurred outside business hours.
- untog 13y agoGiven that the Valleywag article (flagged off HN of course) said that they were able to load up the admin interface themselves (just not log in) I'm going to say that yes, its open.
- steveklabnik 13y agoI don't think it was flagged off, I think Valleywag is in the banned site list.
- grey-area 13y agoIn that case it's going to be simple to find them, something like: grep /log-in server.log to find the admin user id which logged in around that time and viewed that page from an external IP. I'm sure if they really want to they could find the IP at least, and track which user accessed the resource, which other pages were accessed, which will probably lead them to the leaker. Quite a lot is logged by default by the web server usually, and then on top of that their app will do more logging, maybe even associating page views with user ids.