TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Astalavista.com hacked, including details

171 点作者 gmazzola将近 16 年前

16 条评论

gmazzola将近 16 年前
Page as it appeared on June 5, 2009 12:15AM EDT: <a href="http://pastebin.com/f751e9f5b" rel="nofollow">http://pastebin.com/f751e9f5b</a><p>The post is a little low on details concerning the actual exploit used, but there's pretty massive carnage. Let's hope the admins have offsite backups.<p>For those who don't know of Astalavista, it was a popular website for "hackers" with relatively low-quality content. It started in 1994, and was one of the first search engines for computer security information. It hosted software exploits, and quickly degenerated into a forum for sharing software cracks, spyware, and virii.<p>Being a security-related website, you'd expect the owners to be a little more careful, which is why this is interesting.
评论 #642745 未加载
评论 #642763 未加载
评论 #642743 未加载
评论 #642804 未加载
评论 #642737 未加载
评论 #643684 未加载
评论 #642728 未加载
gojomo将近 16 年前
When a site is reported as 'hacked', am I alone in <i>not</i> wanting to visit it for a look-see? Aren't the same people who deface sites likely to try fresh browser compromises against rubberneckers?
评论 #643190 未加载
评论 #642877 未加载
jrnkntl将近 16 年前
This somewhat concludes the whole point of the hax0rs:<p>Quote: "plaintext passwords? yes, those so called "security professionals" who charge you $6.66 / month to register at their hack-proof portal, save your passwords in plaintext... brilliant!"
评论 #642829 未加载
dylanz将近 16 年前
I think scrolling down that was more suspenseful than any book I've ever read :)
评论 #642752 未加载
dmix将近 16 年前
Its the (other) hacker news this week on HN.
评论 #642694 未加载
Tom23将近 16 年前
From Digg: <a href="http://digg.com/security/astalavista_com_Hacked_2" rel="nofollow">http://digg.com/security/astalavista_com_Hacked_2</a><p><a href="http://romeo.copyandpaste.info" rel="nofollow">http://romeo.copyandpaste.info</a> gives an idea about anti-security movement...
xtxlog将近 16 年前
a bunch of people on efnet irc say that it was hacked by some guy named darkpontifex or some group called dikline or something. supposed to not be a litespeed vuln its actually an ntp daemon vuln just changed the name to confuse people.
Hexstream将近 16 年前
Read from line 1758 (at <a href="http://pastebin.com/f751e9f5b" rel="nofollow">http://pastebin.com/f751e9f5b</a>) and you'll see that those astalavista guys have no taste... Good riddance.
andr将近 16 年前
The hackers complain about Astalavista being targeted towards script kiddies. However, it looks like they used a prepackaged exploit, too.
评论 #643010 未加载
froo将近 16 年前
I saw some paypal details in there aswell, I'm wondering if astalavista used any of the same passwords to secure that account?
s3graham将近 16 年前
Heh 13.33.33.37.
评论 #642831 未加载
Tom23将近 16 年前
<a href="http://pastebin.com/m592e1f1c" rel="nofollow">http://pastebin.com/m592e1f1c</a>
ComputerGuru将近 16 年前
The site is back up now...
c00p3r将近 16 年前
2.6.18-128.1.10.el5 is the latest patchlevel of RHEL or CentOS kernels. It seems like their security officers are sleeping on their keyboards. Good news for so-called enterprise linux customers. amazon.com? =)<p>btw, this is merely good quality of system maintaince (of course, their backup system is very funny), but this is very usual way people uses linux and oss nowadays - no one cares to much, thanks to apt-get and yum and xen.<p>Linux is a mainstream now, nothing special, just stupid, plain activity. It was cool when they were migrated from 2.4 to 2.6 kernel, or even from 2.1 to 2.2 glibc. Today it lost all its coolness and romance.<p>Just imagine what happening in corporate sector, who hires cheap boys or guys from third-world, like me.
bdmac97将近 16 年前
That was painful to "watch" happen to them. Lesson learned. Do NOT f<i></i>* with hackers...
评论 #642756 未加载
gaius将近 16 年前
Who? If it was altavista.com this might be news...