HNHacker News
TopNewBestAskShowJobs

ElliotSpeck

-40 karma · joined March 20, 2011

submissionscomments
ElliotSpeck··on Phpfog "Down for maintenance"
Interesting. Link bookmarked for when it's not midnight, I'll definitely take a read through that. It'd be nice to have a guideline of sorts, I guess.
ElliotSpeck··on Phpfog "Down for maintenance"
Yes, I can explain that.

The links are dead. They were the links to the original uploads for the others to look at. The link was leaked to Andrew somehow. By looking at times, I'm very sure that the files were deleted from there before they were posted by Andrew.

I don't know and don't want to find out how he obtained those links. We're all a big group of people, but the links were never shared by me to him. He's a rash and irresponsible person as you can tell from that tweet.

ElliotSpeck··on Phpfog "Down for maintenance"
No.

I 'think' what I did was a relatively good thing. I never claimed it was, nor would I use that sort of thing as a defence. Everything that I have a say in is under control of phpFog now, and no data was lost. Anything further is completely out of my hands, I can only do so much.

ElliotSpeck··on Phpfog "Down for maintenance"
I never claimed what I did was a good thing.
ElliotSpeck··on Phpfog "Down for maintenance"
I didn't have to at all, correct. But like you said, one doesn't have to wipe the box or redirect everything to goatse, however if you give many people the ability, there will be 10% who will do it. In perspective, me posting on the Twitter account (which was easily remedied, and like I said control was willingly relinquished) wasn't much of a bad thing.
ElliotSpeck··on Phpfog "Down for maintenance"
The website was allegedly posted before I obtained the engine code, however it then went on the site after I gave a copy of the engine code to someone in order to analyze and look for further exploits.

To clarify, I had no intention of hosting the files for public access and never did so. Any links to my site were immediately dead as they were only used so that a copy of the source could be obtained to analyze. The files were destroyed from the server after.

ElliotSpeck··on Phpfog "Down for maintenance"
Would you rather that I hadn't, and instead just wiped the box?

How about I changed every DNS record for every domain to something like goatse.cx?

In perspective, it's not a dick move at all. I'm not academically subnormal, I wouldn't do stupid things with a public Twitter account excluding make it noted that it's temporarily under someone else's control. What's more, I willingly relinquished control of it back to Lucas about an hour later.

ElliotSpeck··on Phpfog "Down for maintenance"
Hey guys,

I'm Elliot Speck, one of the guys (let's be realistic, the main guy) behind the phpFog hack, I guess the record needs to be set straight about exactly what went down.

phpfogsucks.com isn't mine, I never contributed directly to it and any work credited by me is assumed by the creator and owner of that site.

My work was slightly different, I was proving that the system was horribly exploitable. Throughout the process I burnt into the box, gained root access, and took a screenshot. I also gained access to the phpFog Twitter account and posted a bit. I didn't damage any files, and when I finally came into contact with Lucas, I explained my methodology directly and gave him a few security pointers for immediate causes for concern. As a result, the project is now on standby as they fix up the issues that were made apparent by my break-in.

I don't consider what I did to be a bad thing. It's better me break in and make the fact I did public, than someone break in silently and wipe the box, losing hundreds of hours of both the team's and clients' time. That is below any moral standard I could possibly even consider upholding.

What I did not do:

-Damage or otherwise alter any of the system files

-Damage, alter or view any client files

-Post or otherwise make public the methodology behind my access

-Post or otherwise make public the engine code for phpFog, this was done by someone else who I showed the code to in order to investigate further potential security holes before I alerted the phpFog team.

I'm posting here to clear the air, but if you have any questions you can contact me on Twitter: @ElliotSpeck.