Yahoo Hacked
webcache.googleusercontent.com
webcache.googleusercontent.com
Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock.
Three of our Sports API servers had malicious code executed on them this weekend by attackers looking for vulnerable Shellshock servers. These attackers had mutated their exploit, likely with the goal of bypassing IDS/IDP or WAF filters. This mutation happened to exactly fit a command injection bug in a monitoring script our Sports team was using at that moment to parse and debug their web logs.
Regardless of the cause our course of action remained the same: to isolate the servers at risk and protect our users' data. The affected API servers are used to provide live game streaming data to our Sports front-end and do not store user data. At this time we have found no evidence that the attackers compromised any other machines or that any user data was affected. This flaw was specific to a small number of machines and has been fixed, and we have added this pattern to our CI/CD code scanners to catch future issues.
As you can imagine this episode caused some confusion in our team, since the servers in question had been successfully patched (twice!!) immediately after the Bash issue became public. Once we ensured that the impacted servers were isolated from the network, we conducted a comprehensive trace of the attack code through our entire stack which revealed the root cause: not Shellshock. Let this be a lesson to defenders and attackers alike: just because exploit code works doesn’t mean it triggered the bug you expected!
I also want to address another issue: Yahoo takes external security reports seriously and we strive to respond immediately to credible tips. We monitor our Bug Bounty (bugbounty.yahoo.com) and security aliases (security@yahoo.com) 24x7, and our records show no attempt by this researcher to contact us using those means. Within an hour of our CEO being emailed directly we had isolated these systems and begun our investigation. We run one of the most successful Bug Bounty programs in the world and I hope everybody here will participate and help us keep our users safe.
We’re always looking for people who want to keep nearly a billion users safe at scale. paranoids-hiring@yahoo-inc.com
For example, way back in the day before ISS bought my company, somebody claimed their IDS was vulnerable to an IMAP evasion. They actually weren't, but that specific test triggered a wholly separate (and much worse) bug that made it look like it was evadable. I laughed and laughed.
Thank you
In contrast, if you've ever tried to responsibly disclose a vulnerability and gotten a threat from the legal department in response (still common practice in a lot of companies), a bug bounty program can be a very encouraging show of good faith.
Now, I have not seen too many people who would be doing it consistently for many years - simply because it gets tiresome. But it's the same thing for security consulting - at most consultancies, pentesters come and go.
I personally think that the opening created for those without the educational or economic opportunities available to developed world researchers is the best side effects of bug bounties.
Not knocking on you or anything, just more interested to know if all exploits have been patched against, more than the # of patches applied.
His team also recently poached Chris Rohlf, from his own company no less!, and Chris is probably one of the best vulnerability researchers working.
(I have no affiliation whatsoever with Yahoo and while I like Alex fine, we're not close friends. I'm pretty biased about Chris, though.)
This is more "vote of confidence" than your comment asked for; I'm just heading off a potentially unproductive thread at the pass. :)
However, genuine question - how does the laymen (like myself) rate infosec specialists? Imagine for a second I'm a senior exec at Target and IBN (IBM's fake arch-competitor) comes to me and says "no worries about security, we use 256-bit encryption, bank grade security, etc etc". Do I believe him?
I feel like infosec is a "I don't know what I don't know" industry and the consequences could be potentially dire.
As far as I can tell the best information provided by a certificate is that you should avoid applicants who brag about them (and for applicants, avoid employers who list them as job qualifications).
It gets better: you can't even depend on the large players generally getting it right. If a large organization makes a bad decision with their first infosec hire, it's not a self-correcting problem - the next hires will be cut from the same cloth, and unless something blows up, almost nobody will know.
The whole point of those audits is to show that, while every company of any importance will eventually have some sort of breach/break-in/hack, the company takes all reasonable steps to prevent it and mitigate the possible effects of such an event.
Infosec isn't a fool-proof thing. There's no way to prevent everything, and all you can do is keep on top of things and take steps to ensure you're doing everything you can to protect your systems.
You WILL get hacked eventually.
Now, I'm a bit stumped how any obvious variant of the CVE-2014-6271 or CVE-2014-6278 RCE payloads could lead to accidental code execution somewhere else, since they generally produce a parser-breaking syntax error when executed outside an env-encoded function definition. Also, because of an unusual fixed-string prefix required to carry out the attack, there is not a lot you can really do to avoid any half-baked IDS/IPS. Anyway, for the sake of my idle curiosity, I secretly hope that Alex shares the buggy line of code, even though that's unlikely =)
[1] http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficia...
This is no guarantee, of course, which is why the pen-test team that Chris Rohlf runs has to stay abreast of and continuously test the latest available exploits as well as the attempts that we see in our logs.
I won’t sit here and say that I think they are lying. To make such an accusation would only prove me to be a fool not having ammunition in the weapon before I fire it. I will, however, say that I believe – in my opinion – that this is a wordplay and a game of semantics. First off, there are several “shellshock” exploits. The term “shellshock” as the media has portrayed it is to execute the vulnerability or vulnerabilities recently discovered in bash by means of delivering the following payload: () { :; }; <commands>
When we look at this payload, what we are actually seeing is a function definition, not the execution of or calling of that function, with the regards to the following: () { :; };
The actual “arbitrary code” to be executed last past that point, where we’re no longer defining a function, but instead – giving instructions to be executed on the operating system via Bash. One could inevitable argue that taking the payload, and modifying it to look like: () { whatever; }; /bin/bash –c ‘id;uname –a’ could, or even could not, be identified as “shellshock” in the manner of which it was portrayed to be by the media. However, the fact still remains that this “payload” would cause the execution of the commands proceeding the {};
When we look at the other SIX (6) payloads that essentially accomplish the same exact thing: https://shellshocker.net – we see that modification of the “payload” does not stop the blatant fact that the same underlying results are achieved via the same exact vulnerable code in the Bash shell.
My response to Yahoo! : Please issue out the UNTAMPERED and UNMODIFIED apache logs, showing the payload delivered to your “sports API’s” - and other researchers, and potentially shareholders, determine what the underlying cause was. Furthermore, to state that this resulted in bypassing your “IDS/IDP” and “WAF filters” makes me wonder exactly what kind of IDS/IDP and WAF filtering you’re imploring. I’m willing to bet there were exact phrase match filters looking for what most sites have identified as the “Shellshock” vulnerability, I.e. “() { :; };” and preventing the scripts and/or bash from being executed once that string was identified. That could have been with something as simple as a wrapper for bash… And considering the IPS/IDS didn’t pick up on outbound IRC connections on port(s) 6660 and/or 6667, which NO internal server would have a reason to be connecting to, I can only say that your concept of IDS/IDP is seemingly inadequate in my professional opinion. So, once again, since the vulnerability has seemingly been “patched,” I urge you to release the details of the vulnerability in the script, and also explain why it is that the initial compromise appears to have been on a web-facing box with public access to it, and found amongst a botnet running a perl script that had self-spreading and searching capabilities based around the “shellshock” vulnerability? You are comparing apples and oranges, when in all actuality, you should be comparing “to-may-to” to “to-mah-toh."
Who do you think you are? lol.
Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks)
One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implications as a direct result of this behavior"
This is not the real issue here, the thing is their engineers think expired SSL cert is okay and no action being done. I told them you are now training your users to `feel` comfortable with browser warnings when they edit their Yahoo profile and risk your users in future's phishing attacks. I asked them why you are not using a self-signed cert if you think expired SSL cert is okay (of coz they didn't reply)
Util I raise this up in another hackernews' thread on their product's announcement and maybe this time it really made them feel embarrassing and finally they fixed it with a day.
The real problem here is actually not on the expired SSL cert, it is their mindset - you should treat every little reports seriously and it is your responsibility, because you are running one of the world's largest web sites.
How on earth do you manage that? Surely you have a process for monitoring and maintaining them?
Why wouldn't Yahoo set this up to email the group responsible or a ticketing email?
He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.
I knew what he meant...
short answer: yes, definitely.
For the user's data for each property (games, mail, etc) they have their own data stores, and those would have been compromised for sure.
This guy writes a lot of text but it takes him forever to get to the point.
He was actively exploiting it by sending himself reverse shells from the computers. He wrote code to collect and exploit the reverse shells. He wrote code to spider sites to try to find more exploitable hosts. Then he was logging and exploring the infrastructure and servers he penetrated.
If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under his real name.
He seems honest to a fault, loquacious to the point of legally endangering himself just to spread awareness of some horrible things he witnessed.
In my opinion, spinning his actions as anything other than heroic is itself an order of magnitude more malicious than what you're claiming, because it contributes to a false narrative in which the end goal is to completely destroy another human being's life when he was just trying to help.
But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offense to trespass regardless of whether you are trespassing with malicious intent. Certainly it is worse to break into a house intending to steal something than to walk into someone else's house out of curiosity, but neither is legal or, in my view, morally acceptable.
So I say: good for him for making these breaches known, but he definitely should not have been in there poking around in the first place.
In the case of physical property the most common remedies for trespassing are either an injunction prohibiting future trespassing on the same property or a modest fine (e.g. $100). Applying the same penalties to the equivalent behavior in the computer context would be completely reasonable, but that empirically isn't what happens, because the CFAA is defective.
This gets us into complicated territory, though. There are very few people who have ever actually been sentenced to the maximum CFAA penalty. (I'm actually aware of none.) The actual punishments actually imposed are often, I think, fairly reasonable.
Of course, there are plenty who have been threatened with the huge maximum by federal prosecutors, but this is no different from any other crime. Of course federal prosecutors will menace defendants with the maximum possible penalty. They want to extract a guilty plea, and it would also be dangerous for them to claim that any shorter penalty than the maximum applied, since they do no actually control sentencing. (Imagine the controversy if the U.S. Attorney told a defendant that he was only realistically looking at 6 months but the judge gave him 2 years.) It's the defense attorney's role to make sure that her client has a realistic understanding of the likely punishment, not the government's.
What's really needed is a replacement for CFAA (and, for that matter, most other criminal statutes) with more carefully graded maximum sentences, but I've never heard a realistic proposal about how such a law would work.
That said, it was a well-written article by an obviously talented hacker, though I did find the simile about the infant with a genital wart to be unsettling.
Winzip.com has been hacked as well. Do not trust their binaries.
Either this will be headline news tomorrow, or it will be suppressed in its entirety. The OP will probably go to prison, unfortunately, as they will not differentiate between this and black hat intrusion - the case will be judged by someone who saw his nephew using a computer, once, and they will go after him, because they know who he is, and will not have any joy identifying the actual intruders, and this will just go further to demonstrate that the spy agency dragnets are as useful as a chocolate teapot in preventing and acting against actual crime.
I hope he contacted a great defence attorney and the ACLU at the same time as Yahoo and the FBI.
People just get into using something and simply never stop. Then there's the comfort barrier to switching (e.g. I know how to use WinZip but 7Zip is new and unfamiliar).
CCleaner is still popular with low level tech support types, which is quite ironic as it damages the Windows Registry on later versions of the OS. There is also built in tools (Disk Cleaner, Recycling Bin maximum size, auto-Defrag/Trim, etc) which accomplish most of the same things.
Teachers use Real Player. Several nationalities (Russia?) use ICQ.
AOL Instant Messenger (AIM) was popular but full of ads and didn't offer many features. MSN Messenger (later "Live Messenger" ".Net Messenger Service") didn't exist yet (1999) and while Windows had something called Netmeeting it was simply terrible.
ICQ technically came around before AIM, being released in 1996 Vs. 1997 but AIM hit the ground running as AOL hooked up their massive (then) subscriber base. So while AIM was a more popular service, ICQ became popular with a certain more savvy class of user (e.g. tech' nerds, who wanted more functionality, and something NOT tied to their email address).
ICQ offered that. Less ads, more features, and slightly anonymous (ICQ numbers). ICQ sucks by todays' standards, but in 1996-1999 it was really competing with AIM. There's also Yahoo! Messenger that came out in 1998 which was fairly popular (particularly as an "AIM replacement").
ICQ just somehow remained popular in certain parts of the world for the same reason Facebook isn't going away: It reached a critical mass, now "everyone" is using it which means "everyone" has to continue using it...
Note there was a strong anti-AOL sentiment throughout the 90's.
What's your idea of a better alternative?
Back when I worked help desk, the most common reason for a completely FUBAR and need a re-install was that the user ran CCleaner on it.
That doesn't mean CCleaner's behavior is correct, but it's probably a situation the developers haven't been able to test against. For what it's worth, I've run CCleaner's registry cleaner on dozens of machines and never had a problem of any type, and I still use CCleaner sometimes because it's a simple way to clean the temp/junk files left by many common applications with one button click.
I always feel a little nervous when I run the registry cleaner, and while I haven't noticed any problems, I also haven't noticed a meaningful improvement after running it either. I should probably stop doing it just for that reason.
So reading between the lines, you're saying that CCleaner is a bad idea simply because they cannot possibly understand the registry well enough to make the changes that they're making.
We agree completely.
Honestly if people want to use CCleaner to do jump lists, file history, and caches (although that last one is misguided) then I'm all for it. There's very little chance anything will break with those (it is hard to screw up!).
I just warn against the registry cleaner primarily, and just feel like with Disk Cleaner and Windows' automatic cleaning that has been integrated for a while you could live without using CCleaner (unless you still have a Windows 9x box).
It sounds more like, "the software vendor is doing incorrect or incomplete things with the registry and CCleaner cannot possibly know that."
As a long-time Windows software developer, I've been stunned at how sloppy desktop programs and installers are, even today. People ignore Microsoft guidelines, somehow get the software to the "works for me" stage, and deploy it.
CCleaner's registry cleaner is the main issue (aside from the fact it makes computers literally slower by clearing every single cache it can find). Some of the issues it has caused:
- Registry damage: Windows 8 store was damaged/corrupted by a previous version (you had to run DISM to repair it), Windows uninstaller corruption (this impacted Mcafee anti-virus around 2009, the uninstaller would become unusable), deletes preferences for unconnected devices (USB sticks, external drives, network drives, etc) so if you have any software installed externally the drive letter may shift and the software will break, deletes unmounted but valid COM objects, and so on...
- Damage: http://features.en.softonic.com/the-dangers-of-using-ccleane....
- Article: https://bitsum.com/regcleanerfacts.php
- Wikipedia: https://en.wikipedia.org/wiki/Registry_cleaner
- Microsoft support article ("serious issues can occur when you modify the registry incorrectly using these types of utilities"): https://support2.microsoft.com/kb/2563254
- Microsoft Article: http://windows.microsoft.com/en-us/windows/are-registry-clea...
Everyone is saying the same thing. Registry Cleaning is unnecessary, won't improve performance, and really only offers you a chance of doing damage. Registry cleaning hasn't been important since XP, and XP shipped over ten years ago.
Everyone else CCleaner does is either stupid (clearing caches) or duplicated of internal functionality (IE cache clearing, Recycling Bin emptying, etc). Plus Disk Cleanup isn't a new addition to Windows.
Well, shit. I've been using the registry cleaner for years now on Windows 7. I've always liked that it seems to clear certain cruft from my system (unused file extensions, crap left behind by uninstalled programs, etc.), as I have a certain need for digital tidiness. I'm now considering abandoning the feature after these posts.
Thanks for the explanations!
Then again, I used WinRAR up until probably 2010 or so, whenever ninite made it easier to install 7zip.
A sort of related oddity is how often I see OpenOffice on the desktops in doctors offices - usually alongside Microst Office icons. I have no idea what they would use it for.
CCleaner has two main use-cases: a performance tool (allegedly) and a privacy tool.
You assume that CCleaner is popular because people think that it boosts performance. This was never my use-case and anyone that I've seen actually uses it as a privacy tool, i.e., to clean up browser history, delete caches, wipe free space, etc., to not expose what they've been looking at, searching for, and downloading.
With respect to privacy, if I see someone using CCleaner, I recommend that they switch over to BleachBit[1] which is open source and which even Bruce Schneier swears by. I used both simultaneously for awhile on my Windows systems and found that BleachBit found many more privacy-sensitive files to erase than CCleaner.
Alternatively just encrypt the VM[1].
Alternatively again just run a Linux "Live OS" from a DVD and pull the power to "wipe."
Alternatively ad-infinitum make a Windows To Go Thumb Drive and smash it with a brick when you're done.
[0] http://technet.microsoft.com/en-us/library/cc720381(v=WS.10)...
[1] http://www.virtualizationadmin.com/kbase/VirtualizationTips/...
ICQ was popular here way more than in the rest of the world, but it got displaced by Facebook Messenger (and to some smaller extent Google Talk/Hangout/what's the name now).
I have no idea about Russia or Israel, where it was too popular.
I mean - all I want to do is to quickly setup a playlist out of a bunch of directories and eventually do searches in it, which is incredibly common at a party when you quickly assemble playlists from multiple sources. Other media players are completely retarded.
Telling the FBI you broke into a server to see if you could, and that you found that someone else had also broken in before you is just plain stupid.
The CFAA in the US might apply, section a.2.c bit is pretty broad: information from any protected computer). The wikipedia article is full of interesting bits and bobs: http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Though whether or not a DA would be bothered with investigating and building a case is a different story (probably not, unless there were lots of complaints and/or "serious" complaints).
I strongly doubt anyone, even at the FBI, is tasked with finding hackers independent of any complaints.
Weev got 3.5 years and also did nothing malicious with the data he found: http://www.wired.com/2013/03/att-hacker-gets-3-years/
Not that it says anything about whether he'll be in legal trouble. Laws are crazy.
He did not break there to make himself rich or to cause any trouble for the server owner; quite the contrary.
> they will not differentiate between this and black hat intrusion
Should they? This reads like textbook unauthorized access to a computer system,
> A quick `ps aux` on the box yielded...
This isn't just poking at web servers to see what secrets they freely reveal, this is trespass.
On one hand, there are the vandals, or outright criminals, who are using and abusing my property for their gain to my detriment.
On the other hand, there's a passerby who knows about the criminals in the area, knows no one else is looking for them, and trespasses my property because the trail led him onto it.
Now that guy willingly alerts me to the criminals, offers an explanation of what he did on my property and how he found the criminals -- what should my response be?
I know that technically he broke the law, and there are those who want to see anyone and everyone pay for their deeds, but in this situation, wouldn't a reasonable person possibly consider tracking down the criminals first before crying "trespassing!"
With that said I'm sympathetic to this guy's intent. If I were Yahoo or the FBI and he can prove that innocuous access is all he was doing, let's just say I wouldn't go out of my way to throw the book at him.
Because (going back to IRL analogies again), the authorities writ large have the authority to do an exigent search of my home if there's probable cause of a disaster of some sort going on, but local and Federal LE don't exactly have the same right to go around pwning the entire Internet to look for sites that have already been rooted, so in a sense leaving this issue to the authorities is simply leaving it to no one except the criminals, which is also unsatisfactory.
If the right answer to widespread problems like these is supposed to be law enforcement "patrolling the Internet" in some fashion, then we'd need to have way different legal authorities to allow for that. Until then I'm not sure that "only the criminals can search for burning buildings on the Internet" is really the most pragmatic answer.
In any event we obviously can't rely on each and every single important web site's system administration teams. If even Yahoo can be caught, who can you trust?
yeah right, they'll fix your KDE 2 install on freebsd in a jiffy as well
Until then I'm not sure that "only the criminals can search for burning buildings on the Internet" is really the most pragmatic answer.
It's not a pragmatic answer, it's a matter of fact. NSCIA are busy collecting phone calls and developing backdoors. I'd be careful calling anyone criminal.
I wish there were stronger free-to-roam laws. I don't think anybody has the right to tell another person they can't traverse land so long as they don't enter any structures, do any damage, take anything, disturb any wildlife, etc.
Edit: I thought this was an accurate analogy, but I'm assuming the downvoter either disagreed or felt I phrased this as a sarcastic attack rather than an analogy. If it incorrectly came across as the former, that would be my fault, but I don't know if that's what caused the downvote, so an explanatory comment would be appreciated.
I didn't express a stance either way on whether he should be prosecuted for a more minor offense or not, in the analogy's case trespassing. (There are obviously both pros and cons in the precedent set by prosecuting people for revealing their own minor crime on account of reporting a terrible one.)
Plus, using 'murder' and 'family' and 'dead' etc. are too dramatic and personal and unnecessary to convey your point about internet security.
If you're not intending this metaphorically, I must disagree. Trespass is a fairly limited act involving a physical presence. Sending and receiving packets with another host that is configured to do that is really not anything like physically inhabiting a place.
All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI.
They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available.
Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd.
I wonder if they still have them.
There might have been a better way to implement it but with a company the size of Yahoo! I think they'd have the resources to maintain/patch such critical flaws. So the idea of a home-grown (really it's more of a patched version of apache / php than anything else) isn't entirely crazy.
Just looks like this one slipped through the cracks.
Everything is dangerous in the hands of idiots. The technology is almost entirely irrelevant to the discussion.
Citation needed.
I've been a serious Perl programmer since the 90s who has written public facing code at at least a half-dozen companies in the last decade. I've seen all kinds of combinations of things like mod_perl, fastcgi and Plack, but not once CGI.
I don't doubt that there are still some toy websites that run old CGI programs written in Perl. But I haven't seen them in the wild. And that niche has been replaced by PHP.
It's interesting, but in itself is not that exciting in my opinion.
First, read this. Note the date. http://www.crime-research.org/library/grcdos.pdf
I read that shortly after it was originally published. And I thought to myself: COOL!
I was seventeen. I had a spare Windows 95c (or was it 98se?) box laying around, and some experience with inctrl5, a linux box which could operate as a router, and some basic knowledge of tcpdump(1). Importantly, I could also script the behavior of an IRC client.
At the time I was a channel operator in a relatively popular IRC channel on EFnet... "Don't ask to ask!" :) Users would come in and request assistance with malware all the time, so I was already roughly familiar with the mechanisms of infection and CnC.
This is a long story that I must cut short: I ended up in the same CnC room as Gibson did. Not the same type--the same one. I met some of the people in the story. :D
[0] http://www.net.t-labs.tu-berlin.de/teaching/ws0910/IS_semina...
[0] It probably is not really advisable to do even 'helpful' actions such as that, but when you are young you do careless things.
The trick I used was to go on some xdcc network, change nickname to one similar to the bots and just wait. Sooner or later one of the botnet owners tried to authenticate and soon after I would exit with a ping-timeout.
Then you could just log into one of them, get a list of processes and download the one with a random name. It was pretty easy and you could get your hands on a few thousand bots in a weekend.
Oh the joy of running "!uninstall" while the owners was in the chatroom...
Fk Yahoo, they deserve what's happening to them.
I am doubtful that FBI would share their plans and/or actions with OP.
> I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough.
> This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have deemed as an improper response, or lack thereof ...
Seems pretty straight forward: hackers have already downloaded all the personal data out of these organizations and are probably using it in ways harmful to the general public already. This guy is forgoing his probable bug bounty payouts as this is, as he says, a really serious issue.
Thank you to him!
> I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.
Might be the important part of the quote you missed.
He reached out, and didn't have any luck. Companies truly need to learn how to deal with these breaches in a way that re-invites the public trust
And the feds are standing at his front door in 3 .. 2 .. 1.
"Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.
It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme."
[1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new...
EDIT: The quote previously included "Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise." but I moved it here as it caused confusion regarding which issue the article was referencing.
http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the...
(and HN discussion: https://news.ycombinator.com/item?id=6488897)
Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.
Facebook has paid $12,500 for one (http://techcrunch.com/2013/09/02/security-researcher-discove...)
Google will pay up to $20,000 for one (http://www.google.com/about/appsecurity/reward-program/#rewa...)
Forbes even posted an article a couple years ago on the market of zero day exploits and listed prices someone could get for zero day exploits with prices in the tens/hundreds of thousands. (http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...) It should be noted that they state in this article that the groups that will buy these exploits for these prices are generally western governments.
I identified that a few major sites were actually compromised using the vulnerability - Yahoo! being one in
particular. Tripod/Lycos and WinZip.com were also compromised. Yahoo! reached out and gave me a response, albeit a very
weak one, only after the FBI, media and CEO Marissa Mayers was contacted... WinZip patched their boxes and didn't
bother responding or notifying me that they got it done.
And, amusingly, an apology for his rambling:Please do excuse the scattered nature of the email sent to Marissa Mayers @ Yahoo! - there were other correspondences that are currently being kept private, and at the time that I wrote that one, I had been awake for roughly 48 hours and was fueled on caffeine and nicotine.
Which makes his signature line pretty interesting. :)
> A fool learns only from himself. A wise man will learn from the fool.
So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK.
Of course, IANAL.
But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't good enough. Why isn't it?
Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen. If the company being contacted does not personally know the person contacting them, it is not altogether unreasonable to treat the person with great suspicion.
That said, people that do have a public reputation for white-hat work probably deserve to get a pass. This of course raises the question of how you go about getting a whitehat reputation, because most whitehats get their rep by doing the same things the blackhats do, without the profit motive.
There was one time when I used a CnC channel to issue uninstall commands against a couple hundred bots. That was only after trying to contact a user or two to suggest that they uninstall the malware themselves... Those conversations went SO poorly! :)
Anyway, the only way to find a user's contact information via a piece of malware like that is arguably an invasion of privacy... Which brings us full circle.
Could we establish a metric for Good Samaritanism? Could we design a metric that is restrictive enough to prevent misuse but inclusive enough to allow unrequested, benevolent cleaning and patching?
Which provides a perfectly reasonable way to distinguish the white hat from the black hat. The black hat is the one making fraudulent charges to stolen credit cards, or selling social security numbers, etc.
Well no, not really. After all, the blackhat isn't telling you that they're also busy selling your data to someone. And even if you are aware that the data is being sold, the blackhat can claim that it must be another intruder using the same flaw, and geez, you really should fix that!
Doesn't that make a lot more sense than charging anyone who cuts across your lawn with grand theft just because someone engaged in grand theft might cut across your lawn?
All I know is that I've never had this problem on competing services.
futuresouth.us got Hacker News'd this morning.
[1]: http://webcache.googleusercontent.com/search?q=cache:http://...