World's worst hacker
george.hedfors.com
george.hedfors.com
I had no idea the reflex was so strong, but I almost starting twitching. I caught myself reaching for the keyboard to hammer out "ls -l". What a tragedy.
(I leave it as an exercise to the reader to determine whether the tragedy is the hacker's incompetence or my reflexive neckbeard response to it.)
# rm -rf a.tar
But to be fair, maybe it's not that hair-raising if your only experience is with other people's command prompts.Back then there were free guest accounts on all the systems (mostly TOPS-10 and TENEX systems along with some wierd one-off machines like the UCSB symbolic math system on a 360/65), and we (at HARV-10) had a hacker who'd come in and mess things up.
So the sysadmin (Geoff Steckel) started a logging process that dumped all suspicious incoming telnet connections input to a local TTY (yes, a physical teletypewriter).
We used to gather around the TTY when it started chattering, to watch the hacker at work. Geoff pretty quickly figured out what he was doing and patched our TOPS-10 monitor source.
If you're interested in the same and want to display stats about the connection attempts, passwords tried etc. I have developed a "kippo stats" webapp in Perl/Mojolicious, at https://github.com/mfontani/kippo-stats
Also, this is pretty funny, and seems like it could be the same guy: http://kippo.rpg.fi/playlog/?l=20100316-233121-1847.log
I also enjoy how the tar had a file called "scam." Shows the generation gap in what used to be in a swiss army tar. Bot nets and things of that nature aren't fully utilized to terrorize the infected and targets! They can be used to click ads, send emails, give website hits; oh endless possibilities for MONEY.
http://themostboringblogintheworld.wordpress.com/2006/09/13/...
Luckily, the hacked computer wasn't a real computer but a honey pot [2] and everything the script kiddie does is recorded for our amusement.
It's a bit like watching a bank robber sporting a big gun without knowing which way to point it.
[1] http://en.wikipedia.org/wiki/Script_kiddie [2] http://en.wikipedia.org/wiki/Honeypot_%28computing%29
I guess one should be really careful before calling someones actions stupid. Lesson learned.
To summarize, a wannabe hacker got access to a system and didn't know what to do.
I found it curious that he was copy/pasting those wget links so quickly though. THAT part nearly seemed automated. Strange behaviour.
telnet 94.255.168.108
1) not doing ls commands
2) having rescue plans like trying different directories in case a directory doesn't exist
3) doing instant URL pastes
4) doing stuff in loop
5) acting similarly to a robot
6) [feel free to add more here]
A script sophisticated enough to replicate the behaviour of a real user at a shell like this would likely actually achieve something.
Anyone clever enough to write a script that does this, wouldn't, because they'd also be clever enough to realise that it's utterly pointless.
The win2k service pack was likely filling the role of "a big file from a fast CDN," for the purposes of testing the machine's connection.
I assumed it was something he'd seen as a way to sortof-conceal a directory, since it's both hidden and looks a lot like the [dot] directory that you'd expect to find everywhere.
1. Get others involved by leaving fake tracks. 2. Distract attention. 3. Make you think your honey pot is doing right while some other heavy duty scripts are running on the 'right' direction.
Edit: Another would-be hacker: http://www.youtube.com/watch?v=fPypZSZiF3g
Oh yeah, he's really covered his tracks now...
I could just here the steam start to build.