If you’re trying to hack/deface a website, don’t submit a pull request
github.com
github.com
+ <script language="JavaScript1.2">
Are you sure, like, really really sure, you want JavaScript 1.2?
+var speed=1
please run jslint on your code before submitting a pull request
There are so many errors that JSLint gives up on this code at 39%.
+temp=document.body.scrollTop
You really shouldn't declare a variable without using var - can lead to all sorts of scoping problems.
Oh, good catch! You should submit a pull request to fix this
+<mass of span elements>
There's a couple of redundant span elements here, when you get time, you could optimise this
+ <p align="center" dir="rtl"> </p>
It's great that you've made sure that non-breaking space is read right to left, your readers would have been screwed otherwise.
+ $bind_port_p="IyEvdXN...<base64 encoded string>";
It's going to be hard to comment on these Base64 encoded C and Perl programs in their current form.
That daemon() function call is going to cause problems on a whole bunch of non-Linux architectures. Solaris doesn't have it for example.
You should definitely consider supporting IPv6, you can't just assume IPv4 connectivity...
You're also missing a return at the end of main().
+$auth_pass = "fe3f6d96a1ee06bc5415a5c05540c7a8";1911990 is not a good password. Your birthday?
Let's hope you didn't use that for your email account, lovestory8976@yahoo.com
can you use a sha512 hash, instead? it's more secure.
+
Hmm the HTML isnt compliant. Please rebase from master, squash the previous commit and resubmit.
Thanks for your invaluable future contributions
http://docs.oracle.com/cd/E19082-01/819-2243/6n4i098sj/index.htmlIf there was ever an opportunity for a disruptive simple startup idea it would be to replicate what skitch did before evernote bought it and broke the original use case.
Then I found these this week:
Skitch to S3 upload (through webdav) — http://brad.me/skitchs3
Skitch to CloudApp upload — http://brad.me/skitchcloud
If you are a CloudApp user (http://getcloudapp.com/) the second one is super slick. Pretty much duplicates the old Skitch functionality and returns a short URL that you can use to post. You can also use a custom domain with CloudApp if you use the paid service.
Totally made Skitch useful again.
You can change one setting and it will copy the direct link to the image into your clipboard - Perfect! That's exactly what I want it to do. :)
Thanks again, you made my day!
Puush, Greenshot, ShareX, HyperDesktop, Snag.gy, as well as some smaller apps written by users.
Maybe one will be useful for people sad about Skitch!
Skitch supports FTP-upload, so if they turn off sharing in the future you can just switch to your own webspace.
No need to mess with lesser tools (or the evernote-garbage) while Skitch still works!
i wish there is a plugin or kernel extension that modified skitch so that you could upload it to say dropbox. The other method is to point skitch to the local machine and use dropbox to sync, but i think you lose the clipboard thingy.
May be i will just switch to monosnap. But it looks so ugly compared to skitch!
I'm definitely sticking with skitch as long as it works and until a suitable replacement appears.
Edit: un-checking "show inline notes" helps.
Edit 2: So if I understand correctly, OP tried to hack into a website... by submitting code to github. I was confused at first because that would have been (very) wrong way to "hack", but as it turns out, that is indeed true. And rest is about the code he/she used. It seems to be auto generated in some wysiwyg html editor that uses old html.
> can you please add semicolons to the end of these lines + @douglascrockford
With Githubs ease of merging and automatted testing by Travis, it's easy to forget that changes may be actively malicious and not just buggy.
Spending months building trust while creating a giant trail of information that can be used to find you and then really pissing off the open-source community seems like a bad plan for someone that is attempting to quietly gain root. Might work if one project is attempting to discredit another project (think closed source vendor trying to steal clients who use opensourced github projects).
I'm not saying someone wont do it, I suspect it has been done a few times, but it is a dumb way to break into computers and far more work/risk than downloading metasploit and using a public exploit.
You don't need to provide much information to get a github account, so the risk is not very much elevated.
1. Unless you are extremely lucky, you have to gain someones trust by posting fixes that do not contain backdoors. This leaves a trail in terms of: coding style, word usage, editor settings (tabs vs spaces), and ip records/timestamps in github. It's not much but it is additional unnecessary exposure.
2. Since the code is publicly available on github it stands a much better chance of discovered later. If you own a server, do you business and change the logs, you have a very very low chance of someone discovering the intrusion after the fact.
3. If someone discovers the backdoor they can setup a honey pot. They might even allow the change to be merged and then wait for you to connect, although this is unlikely. An attacker is potentially forfeiting the element of surprise.
4. Gaining access to a remote server is trivially easy (just use a publicly available exploit before it is patched on your target server), especially if it is a webapp, especially if you have access to the code.
I'm not saying there isn't someone out there that thinks this is great attack method. I'm just saying that an attacker that uses this method is either doing it because they think it is funny or a stupid attacker (there is not shortage of stupid attackers).
So yes, owning a server might be easier in some respects, but owning a project might own you a server you'd never get access to - a machine that runs behind a firewall e.g.
I say similar because it was not a trusted contributor going rogue but someone actually hacking the public CVS repo.
Long story short. The FBI put on its payroll a well paid crypto analyst trusted with commit access to the OpenBSD code. Years after that, somebody claims that the analyst has put on the FBI payroll to implant an hidden weakness in the crypto code. Audit follows; nothing found in the code. FUD still remains.
See what happened when oh-my-zsh got careless in testing pull requests: https://github.com/robbyrussell/oh-my-zsh/pull/1395/files#L1... everyone who got the update (tons of people, as it's self-updating) had their $HOME screwed up, basically breaking the entire shell.
Point being that trust only goes so far here: proper code reviews are what stop these problems.
Copyright 2000, 2001, 2003, 2005 E\/17 |-|4><0|2z Software Foundation, Inc.
This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY, COMPLETE DESTRUCTION OF IMPORTANT DATA or FITNESS FOR A PARTICULAR PURPOSE (eg. sending thousands of Viagra spams to people accross the world).
Basic Installation
Before attempting to compile this virus make sure you have the correct version of glibc installed, and that your firewall rules are set to ‘allow everything’.
1. Put the attachment into the appropriate directory eg. /usr/src.
2. Type ‘tar xvzf evilmalware.tar.gz’ to extract the source files for this virus.
3. ‘cd’ to the directory containing the virus' source code and type ‘./configure’ to configure the virus for your system. If you're using ‘csh’ on an old version of System V, you might need to type ‘sh ./configure’ instead to prevent ‘csh’ from trying to execute ‘configure’ itself.
4. Type ‘make’ to compile the package. You may need to be logged in as root to do this.
5. Optionally, type ‘make check_payable’ to run any self-tests that come with the virus, and send a large donation to an unnumbered Swiss bank account.
6. Type ‘make install’ to install the virus and any spyware, trojans pornography, penis enlargement adverts and DDoS attacks that come with it.
7. You may now configure your preferred malware behaviour in /etc/evilmalware.conf.
SEE ALSO evilmalware(1), evilmalware.conf(5), please_delete_all_my_files(1)
/tinfoil
"If there is no check on the freedom of your words, then let your hearts be open to the freedom of our actions"
"The war continues until the last Zionist remains on the beloved land of Palestine"
cough Shouldn't that be until there are no more Zionists in Palestine? Are they proposing to kill all Zionists until there is just one of them left, and then say "you're the last one here, you can stay".
بسم الله رب المجاهدين والشهداء ،،~ In the name of God, lord of martyrs and Moujahidin[no idea how to translate that]
إن الرساله المراد توصيلها لكم .. The message that you are intended to receive is...
إن صواريخ المقاومه قد وصلت إلى تل أبيب والقدس الغربيه المحتله وإلى جميع التجمعات الإستيطانيه القريبه من قطاع غزه .. وإن طائراتكم التي تحلق في سماء قطاع غزه لن تحلق بعد اليوم . وألياتكم التي تتحرك على طول الخط الفاصل هيه تحت مرمى ضربات المجاهدين وسُفنكم الحربيه قُبالة شواطيء غزه أصبحت تحت الإستهداف The resistance[Hezbollah]'s rockets have reached Tel Aviv and the occupied West Jerusalem and to all colonies[or colonial compounds/groupings? not sure] in the Gaza district... And your planes that fly in Gaza's airspace will not fly after today. And your tanks[or armoured vehicles] that patrol the dividing line are within reach of the moujahidin and your warships facing the beaches of Gaza are now being targeted.
عليكم الإن الإختيار بين أمرين لا ثالث لهما You now have to choose between two options, you do not have a third.
( إما الرحيل عن فلسطين , أو أن تموتو على أيدي المقاومه ) Either you leave Palestine or you die at the hands of the Resistance[Hezbollah]
وسنوفر لكم خدماتنا السريعه بإرسالكم للموت بطيئأً .. We will be quick in giving you a slow death[you can just imagine that guy chuckling to himself as he came up with this pun]
هذا ونتمنى لكم النار منعمين فيها بإذن الله We wish you [something I don't know how to translate about fire and hell] god willing.
--
I'm Lebanese, so I've met quite a few Hezbollah/Amal people, I tend to sympathise more with the Palestinans than the Israelis in general, but shit like this makes me feel sad and unsure if I want to laugh or cry at the guy who wrote it. That is, if they were being serious and this not just a troll.
Protip: if your trying to hack/deface a website, dont submit a pull request WITH YOUR EMAIL AND PASSWORD!
The pull request included the code that does the hashing:-
if( empty( $auth_pass ) || ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) )
$_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
else
printLogin();
So any salt [was hash] used would have to be present in the code too.Given that such a simple password (8 digits) could be brute forced in seconds on an average PC, even with a salt, it doesn't really matter whether it was salted or not.
A password of "p*l12nJ9£l ~98as2389bvkqsopfq£3oef2[olpe]wog!wei^og(8ni" would take an unrealistic amount of time to brute force, even if unsalted, and it's beyond the scope of any precomputed rainbow tables for similar reasons.
Anyway, it's only a concern if he uses the same password elsewhere.
Since rainbow tables look up a password via its hashed value, I believe you could find something else that has a hash collision -- for all we know, it has the same hash as 'ponies'.
The sheer size of the keyspace (2^128) means that rainbow tables can only ever exist for a subset of the keyspace.
1M machines running for a year each capable of doing 20M MD5 hashes a second will still only cover 1/539514153540300709th of the MD5 keyspace.
But, yes, salting would prevent the use of rainbow tables completely.
Hash type: MD5, Hash: 6df23dc03f9b54cc38a0fc1483df6e21
Device #0: [RV870] 850.00 Mhz 1600 SP
Device #1: [RV870] 850.00 Mhz 1600 SP
CURPWD: @uX5G DONE: 22.30% ETA: 1m 34s CURSPD: 6436.3M=3217.8M+3218.6M
http://www.golubev.com/hashgpu.htmPretty disturbing stuff, to say the least. Combined with the english text about the Zionists leaving Palestine, I just wanted to shed some light on the intention of the defacement.
But if I ever need a jury of my peers to audit my coding style to see how good it is, now I know what to do - a pretend-attempted-defacement is bound to be more effective than finding some place on the net to ask 'Is this proper idiomatic javascript?'.
[0] https://github.com/maxymax/WordPress/commit/2fa93590c7881fab...
Please report? https://github.com/ahmedalex
P.S. If you're not a jerk and would love to help with the new CoderDojo.com site, let me know rebecca (at) coderdojo.com
Or how did he think that he can pull this thing off? is there a "10 ways to hack a website" where a git pull is one of them?
The fact that there is a code snipped a tutorial on "How to Create a Website With Notepad" and the whole thing seems like it came out from an old WYSIWYG editor, the thing obviously was made by a script kiddie. script kiddies uses git now? wow
Here's last year's winner: https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/commi...
https://github.com/Incognito/CoderDojo-Kata/commit/d6c4163ab...
After you ask them, they then criticize your choice of spraypaint ("Krylon? Really? Not using Rustoleum, even though this is clearly for outside application?"), testing that your egg is actually of proper dimension and size, and then sighing in annoyance upon finding out that your toilet paper isn't quilted.
PROTIP. better than calling someone a sheep.
Suddenly all the smart comments feel a lot less fun
[1] http://www.alternet.org/speakeasy/tikkundaily/israeli-minist...