Disposable Root Servers
blog.thc.org
blog.thc.org
> "We research and publish tools and academic papers to expose fishy IT security that just isn’t secure. We also develop and publish tools to help the IT Security movement."[1]
0. https://en.wikipedia.org/wiki/Hydra_%28software%29Absolutely not, no assurance whatsoever.
or just me…
#!/usr/bin/expect
set timeout -1
spawn torsocks ssh root@segfault.net
while (true) {
expect " password:"
send "segfault\n"
expect "\[~]"
send "gsocket -s NzdlMWQxNGQM ssh root@segfault.net\n"
expect "t\])? "
send "yes\n"
}
Eventually starts showing this in response: [ERROR]
--> You (172.22.0.21) have to many servers running
--> Read https://www.thc.org/segfault/youcheapfuck
--> Contact us on Telegram: https://t.me/thorg
Connection to 127.31.33.7 closed.
Also their Tor hidden service currently seems to be inaccessible. Perhaps there's a hard limit on the number of connections via that route, given that one can't restrict per any individual source due to the design of Tor.If you are so paranoid about your security and anonymity, why would you take promises made by a third party at face value?
Why would you trust anyone or anything with an ounce of your identity?
Here, you don't have to take many promises at face value. You do have to assume that everything you do on that server is monitored if you don't trust it, but you can connect to it via Tor and/or a VPN.
SSHing into a VPS from the family computer is definitely a lower barrier to entry. You can get dirt-cheap VPS for $3/month, but this free offer is even cheaper and comes without the hassle of payment methods (no explaining to your parents why you need to use their credit card for this).
Big Thanks to the Creators!!
If you do such a thing through here, you deserve whatever happens to you.
I often want test or observe something i'm doing from outside my environment...
lynx https://news.ycombinator.com
curl https://jsonplaceholder.typicode.com/todos/1 Is it safe?
Nobody ever got arrested for choosing segfault.net.
Take a close look at how that question isn't answered. It's best not to do any work on these, where you need to trust the platform. You might even get blamed for people's actions on their box next to you.Not much remains outside of this being a honeypot or for criminals.
I think that's the joke. I prefer this non-answer over a long-winded bullshit answer that ultimately means nothing.
I don't mean to be snarky, but I don't think the target audience for these servers trusts them one bit, and the operators know this.
There are people on this page talking about logging into other services from there, so I think you can see one very easy way.
If you use a service that says they don't track anything, delete the machine upon logout, and so forth, who do you think will use that box?
I agree that a target of interest could be located to this service, but to correlate activity of two users would seem to require detailed logs from the provider - the logs they claim not to keep.
Also, by visiting a bank, there’s a chance you could end up being mistaken for a bank robber; or by jogging through a neighborhood, there’s a chance you could be mistaken for a thief; etc. We don’t usually give much thought to these possibilities, although they do sometimes happen. Is there any reason to treat this differently?
Sure, it's perfectly reasonable from a privacy perspective but it raises questions: I don't run around showing my passport to everyone (except for my authoritarian government) and yet I drive around with an id that the authorities can link to my identity.
Don't get me wrong, I'm all for removing layers of surveillance, but I will still assume tor users on my website are either trying to hack it or have something to hide from their government.
I assume they are talking about logging into, say, your email, and thus linking the box to you
As a third party, of course absolutely experiment but don't rely on there being no logs, lol.
It’s a fun curiosity. But anyone relying on it to cover up illegal activity should be very very careful. If what you’re doing can improve a cop’s chance of promotion, you should assume they’ll take advantage of that. And for “lesser crimes”, you can bet that most things you want to do from there are already on blocklists. You’ll have as much chance of getting your spam runs out of there as you do from any cheap vps or tor exit…
Deploy your own...
$ nmap -sn 10.11.0.0/24
Nmap done: 256 IP addresses (86 hosts up) scanned in 1.56 seconds
$ uname -srv
Linux 5.15.0-1011-aws #14-Ubuntu SMP Wed Jun 1 20:54:22 UTC 2022[1]: https://github.com/hackerschoice/segfault/blob/main/docker-c...
The page talks a big game about hating criminals, but these days if you don't put up a cookie banner RoboCop will shoot you in the dick. And if someone really isn't a criminal we've got a fix for that, too: Just ship them to a country where they are!
On the other hand maybe this post-HSA, post-Snowden world has made me jaded and the site really is just good clean fun.
Not sure if it covers your question though.
e.g. `ssh -v -D 30314 -q -C -N root@segfault.net`
This does not seem to be entirely accurate (and it would also be very obnoxious, especially for use over Tor, if a dropped connection meant starting from scratch). The servers do allow reconnects, and data is preserved (presumably in encrypted form).
Credentials still worked but a fresh instance.
So, uh... how do you (the creator of the service) know that, without doing some sort of data tracking?
For that matter, how do you know that someone's not grabbing 10,000 of these to run a botnet?
This server sits there as a perfect vehicle from which to break the law. It's like someone leaving a fleet of getaway cars and guns, with tips on which banks are loaded right now left on the drivers side seat, and delivering it to a poor neighborhood, where it is rational to accept higher risk for a higher reward.
There may be some who use it out of intellectual curiosity, and who are careful not to run afoul of any laws. LEOs will be of this type, I assume. I'm curious to know what is in that 8GB of tools that is included in every shell, for example. So for me the appeal would be a "safe" place to play with tools that I may have concern about even installing myself and what lists that adds me too. So in that sense its quite a good thing, it is freeing from risk of state involvement if your experiment/exploration goes wrong.
Presumably all serious hacking attempts originate from a remote process anyway, as only a very silly/young/foolish hacker would try certain tools from their actual home IP address and personal laptop. So one argument for this service is that it reduces the demand for (coerced) botnet nodes. If you squint your eyes it's a similar argument for providing clean needles and methodone to a community, no questions asked. No, it's ugly that people use, but it's even uglier that people use and reuse/share needles to avoid detection.
So while I agree it's probably a honeypot, there is also a sound argument for it to exist, legitimately, as a public service - a hacker's hamsterdam.
My point was — without tracking users, how do you ensure quality of service for this system, when someone could just generate 10k distinct SSH keys (= distinct "accounts" in this system) to run their botnet with, and so consume all your resources with purely their traffic? (Where "a botnet" here is just standing in as an example of a use-case that requires as many nodes as possible, rather than being satisfied with just one. Could be a distributed web scraper; could be a crypto-mining pool; etc.)
If you're not requiring some kind of user registration that does enough KYC to deduplicate registration attempts — and you're not tracking usage with fine-enough granularity to be able to surface + ban people who are "taking more than their fair share" — then this isn't going to be of benefit to the entire hacker community, but rather the whole thing is going to be gobbled up by the first person willing to write a script to do so.
It's like making a large donation to a community in a war-torn developing nation, where as soon as you leave, the whole thing gets extracted out into the coffers of the largest local warlord.
IMHO doing this model correctly would necessitate something closer to the "a real person's going to manually verify your sign-up" process of e.g. https://www.nearlyfreespeech.net/signup/signup.
For that claim to actually be true, the system has to be hermetically sealed against outside observation by any other than the user themselves. (Compare/contrast: the claims of a few VPN service providers, that their service is implemented effectively statelessly, in diskless + memory-constrained ASICs on network switches, such that there's no ability even in theory for the machine itself to keep metrics on which user accounts are responsible for which kinds of upstream traffic flows; such that a state actor who wanted to know that would be stuck either replacing the hardware [and so extracting the credential store out of the TPM of the original hardware] or MITMing both sides of the VPN box and doing traffic analysis to match flows.)
IMHO, it's probably very unlikely that the claim is true — but it's interesting and fun to try to threat-model a service that does try to make that guarantee.
Also, separately:
> In theory its relatively straightforward to develop a "1 human per process" heuristic for a service like this
You're forgetting that these accounts aren't strictly intended for use by humans, but rather scripting the system is an accepted (and encouraged!) use-case. Which means that you can't differentiate one user "botting" N accounts, running the same script (presumably bannable); from N users each "botting" their own single account by using the same popular open-source script (perfectly legitimate and protected!)
This, by the way, is the reason that most VPS providers outright ban the deployment of certain types of software, e.g. IRC bouncer bots: it's impossible to tell whether N deployments of such a bot are N users intentionally deploying the same open-source bot, or one user (with N stolen user credentials) deploying a botnet that uses IRC for command-and-control. So they just make the assumption that such deployments are always malicious, and refuse the business of anyone who has a non-malicious use-case for such deployments.
I don't think they're going that far (it doesn't come with a list of profitable organizations to hack.)
That’s exactly a thing the FBI would say.
They should name the service “honeypot.com”.
i assume this means the 'disposable root server' can send [whatever] encrypted data over the ssh tunnel to my machine (and my network if the machine is not properly segmented)?
if so, what should i do to protect it?
I don’t see any TOS, at all.
Anybody can seed whatever and run Tor exit node ? ( not that it would work well but still )
Your home directory is in /sec/root.
If you install tools outside of /sec/usr they will be reset on your next visit. So if you want to install something that survives a session log out you need to install to /sec/usr
Anyone got an ideas on how I can support the cause?
┌──(rootsf-BrushFocus)-[~]
└─# finger
No one logged on.
Where is everyone?Always stuck me as a clunky term, but it was where my head went first on reading the title here (then I thought DNS servers, but that did not compute so the first thought "won").
There’s a bunch of these comments. What would a disposable root DNS server mean? Stand up a DNS server and just claim authority for .?
You could do that here fine I imagine. You have root. Until you log out, of course.
If you can install stuff and listen on 53, you could make your own private DNS tree anywhere.
Now, managing delegations will get weird if you want to delegate outside of what you manage. I’m seeing a spiderweb of stub zones.