5 ms·
As to the second point. This "fiddling" with "miscellaneous" input characters could also be interpreted cover brute-forcing login attempts. I'm not sure that's
by void-star 12y ago
As to the second point. This "fiddling" with "miscellaneous" input characters could also be interpreted cover brute-forcing login attempts. I'm not sure that's a good precedent...
- nmjohn 12y agoIf there is an external server that is vulnerable to a brute force attack, it is trivial to exploit it anonymously. People who get caught trying to brute force servers (do people even get caught for this???) are the lowest hanging fruit and are the ones least harmful to society. My point is precedent doesn't really matter, because realistically, you won't have anyone to actually prosecute except for the 13 year old "hacker" who had no idea what they were doing.
- cesarb 12y agoIf it was "miscellaneous" input characters, it probably wasn't brute-forcing login attempts. Brute-forcing logins would use mostly alphanumeric input characters, not "miscellaneous" input characters. The word "miscellaneous" to me implies things like quotes, backticks, and similar non-alphanumeric characters. "Fiddling" with them would be attempting to find somewhere that didn't quote an input value correctly: they were attempting to find something like an SQL injection.
- tedunangst 12y agoMy understanding is that they attempted a login a few times. User: dpr. Password: ababa, dada, bobo, etc. This in turn triggers the web app to display a captcha after too many failures. The img src for the captcha revealed the IP. It wasn't much of a "brute force" attack, it wasn't SQL injection (though it's possible they were poking at that too), but just the simple question, what happens if we try to login five times with "miscellaneous" passwords? Hey, look, a captcha! I wonder what server the image comes from...
- DINKDINK 12y agoWhat would cause the captcha's image to leak the ip but a regular image on the tor website not?
- patio11 12y agoSomething as simple as using 3rd party code for the capcha with a config file that said "host name goes here." Would you be at all surprised to find this in a WordPress plugin or similar?
- cnvogel 12y agoThis is purely guessing, but checking regular images (right size, format, ...) will be the "day-to-day" business of looking after a website. And more often than not the administrator will therefore "Open image in new tab..." and become aware of an incorrect image path. The Captchas, on the other hand, might have been using an existing software. Remember: These captcha images will have to be autogenerated by a script which, as a convenience to the user, might have used some kind of mechanism to determine "fully qualified" URLs. And this had slipped below the radar, as it's a feature used much less often, and hence likely to receive much less scrutiny. I think it's pretty likely that these kinds of information leaks can happen when you deal with a larger codebase or system. Hence following the advice of some other HN users, who recommend a strictly firewalled system for this kind of use-case, looks like a prudent thing to do.
- gvb 12y agoThe site was misconfigured WRT serving the captcha image resulting in the image link pointing directly to the SR server rather than being routed through TOR.
- deleted 12y ago[deleted]
- pbhjpbhj 12y agoTrying a series of passwords is unauthorised access though, surely? Like opening a barrel lock, you try a few positions because that gives up the code eventually, it's not brute force but it's not authorised access by a long shot. Deciding which way the decision should go must be causing quite a few hours of concentrated legal consideration - there are downsides in both directions for the government.