9 ms·
Page as it appeared on June 5, 2009 12:15AM EDT: http://pastebin.com/f751e9f5b http://pastebin.com/f751e9f5b The post is a little low on details concerning the
by gmazzola 17y ago
Page as it appeared on June 5, 2009 12:15AM EDT:
http://pastebin.com/f751e9f5b http://pastebin.com/f751e9f5b
The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups.
For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer security information. It hosted software exploits, and quickly degenerated into a forum for sharing software cracks, spyware, and virii.
Being a security-related website, you'd expect the owners to be a little more careful, which is why this is interesting.
- noodle 17y agohell, i tend to find any reasonably detailed description of the process of exploiting something to be pretty interesting. gives a fairly good idea of how to not make the same mistakes, if applicable.
- andreyf 17y agoYeah, considering how last-decade astalavista.com is, I wouldn't be surprised if now is the most pageviews they've gotten in awhile ;)
- asnyder 17y agoBrutal indeed. Not only did they expose all aspects of astalavista, they actually trashed and dropped everything. As bad as astalavista is, is it right to reciprocate and trash their server? It seems as if the hacker sunk to their level. Are there legal ramifications to something like this?
- enneff 17y ago"Are there legal ramifications to something like this?" Uh, yeah, of course. Good luck catching them, though.
- Timothee 17y agoI'm thinking I was not the only one reading the title as altavista.com and I was really shocked. Thanks for the background info on the site.
- bdmac97 17y agoI definitely read "altavista" at first too having never heard of astalavista until now.
- danijel 17y agoWhy do you think they called it like that? It was founded in early 90's and altavista was "the" thing. I remember going there and learning about trojans, debuggers and disassembly as a kid.
- enneff 17y agoThey did have off-site backups, which the hacker found and erased. One strategy that I employ to mitigate this is to have my backup service connect to the production server, rather than the other way around. That way if your production services are compromised, your backups remain untouched (on a machine that's running no services, behind a firewall, etc, and for all intents invisible).
- sev 17y agoDefinitely a much better method of handling backups. Completely agreed.
- obanite 17y agoWhat's the point in offsite backups (for security reasons) if they're connected over network connections?
- notaddicted 17y agoPhysical security, i.e. protection against fires floods and comets, etc.
- jlcheng 17y agoI thought the typical definition of offsite backup also means data is backed up to a media like tape and stored in a different location. How is your offsite backup implemented? Is the data stored on a network drive, or backed up to tape?
- enneff 17y agoMy understanding is that an offsite backup is, as the name implies, a backup that is stored at a geographically separate location to your production site. I have a few servers deployed at various locations around the world, and I have a machine here at home that performs rsnapshot daily backups of their files. I then make bi-monthly backups of those backups, and store them in a saftey deposit box at a bank. This means that if my servers go down, I can restore them to within a day. If my house burns down, I still have my data to within two-weeks.
- iheartmemcache 17y agoIt looks like they first buffer overflowed Litespeed to spawn a shell (which was ironically running as a user 'apache'). The http headers that are being returned from Astalavista are consistent with this theory (in addition to the obvious output of the first binary run). Apparently Litespeed has a pretty dodgy security record after doing a cursory search. Far more interesting was the root escalation exploit. 2.6.18 is a relatively recent kernel, and I haven't heard of exploits publically disclosing something of that caliber. Has anyone seen anything on securityfocus/bugtraq/milw0rm etc regarding this?
- duskwuff 17y agoThere's a nasty bug in the vmsplice() syscall in anything from 2.6.17 to 2.6.24.1. Exploits have been public since early 2008. http://www.milw0rm.com/exploits/5092 http://www.milw0rm.com/exploits/5092 http://www.milw0rm.com/exploits/5093 http://www.milw0rm.com/exploits/5093
- bdr 17y agoOne of the files on their server is an exploit for that vulnerability. If they know about it, I would guess they aren't vulnerable, but who knows.
- duskwuff 17y agoGood point. The kernel version in the transcript looks like the version I've got on a CentOS machine, so it's probably patched. Interestingly, the strings ("r00tr00t", "Executing shell") from the local-root tool they're using don't appear anywhere online, suggesting that it's something private and potentially unknown.
- oscardelben 17y agomaybe it's just not indexed.
- 17y ago
- Confusion 17y agoOfftopic, but please, don't use 'virii'. The correct plural is 'viruses'. 'Virii' is wrong for two reaons: 1) The Latin plural of word ending in -us is not -ii. -i at best. 2) 'Virus' doesn't have a Latin plural, because its meaning is like (in the sense of not having a plural) 'sand': it already denotes a multitude.
- sev 17y agoWhy is it that the plural of "radius" is "radii" but the plural of "virus" is not "viri"? I don't see "virus" as inherently denoting a multitude in the dictionary. Just curious.
- __david__ 17y agoAnd furthermore "sands" is still perfectly legitimate, even though "sand" may be inherently plural (the "sands" of time, different "sands" of the world).
- thomaspaine 17y agoVirus is Latin for poison. It's a mass noun because it denotes something uncountable (not in the strict mathematical sense, but in the how the hell do you count poison sense). As far as I know, there is no Latin plural form for virus. Second declension singular nominative nouns end in 'us' and their plural form end in 'i', but fourth declension singular nominative nouns also end in 'us', but their plural form still end in 'us'. Also, like in every language, there are funky exceptions to these rules, like second declension singular nominative nouns which are neuter rather than masculine, but still end in 'us' rather than the normal 'um'. Moral of the story, don't assume that the plural of word ending in 'us' is 'i'. It's also been about 8 years since I've taken Latin, so take that into consideration before someone goes all Life of Brian on me.
- DrJokepu 17y agoBecause with [radi]us the stem is "radi" but with [vir]us the stem is "vir". These words are from the same type (second declension) they both receive an -i affix in plural, hence radi + i = radii, vir + i = viri. Latin being Latin there are an awful number of exceptions but this is a somewhat general rule. Put it like this: Grammatically speaking, the plural of virus is viri. Putting it into plural might or might not makes sense. Personally, I don't think that using plural for collections in Latin is a very big sin given that this is very common in classical Latin texts. One example of this can be found in the famous introduction of Aeneid (I.1 "Arma virumque cano...") lines 31-32, where Virgil is using the plural form of the word "sea" (mare, plural: maria) "multosque per annos / errabant acti fatis __maria__ omnia circum" - "for a number of years, driven by fate, wandering around on the seas"
- takeda 17y agoyou're mistaking astalavista.box.sk with astalavista.com. astalavista.com stole their name to ride on their popularity.