SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    HackedThat: Breaking in to a Hardened Server Via the Back Door
Date    Saturday August 27 2016, @06:07PM
Author    janrinok
Topic   
from the don't-go-through,-go-around dept.
https://soylentnews.org/article.pl?sid=16/08/27/1230220

ticho writes:

Earlier this summer, the team at Inversoft published a comprehensive and sophisticated guide to user data security. The guide spans from hardening servers from provisioning, up through the IP and SSH layers, and all the way to application-level techniques for password hashing, SQL injection protection, and intrusion detection. As proof that they stood behind their advice, the Inversoft team provisioned a pair of Linode hosts, a web server and database server, and gave them the hardening treatment. Inversoft offered up a fully-loaded MacBook to anyone who could break in, taunting all comers by naming the hardened web server hackthis.inversoft.com.

Game on.

Needless to say, they found a way in.

[...] After discovering an unpatched, unfirewalled Elasticsearch instance using nmap, we gained shell access on a utility server used for various functions at Inversoft. On there, we found API keys for Linode left behind by a human operator. Those keys allowed us to detach disks from running servers and attach them to servers we controlled, stealing sensitive user data (all to win a prize).


Original Submission

Links

  1. "ticho" - https://soylentnews.org/~ticho/
  2. "Game on" - http://polynome.co/infosec/inversoft/elasticsearch/linode/penetration-testing/2016/08/16/hack-that-inversoft.html
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=15536

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, HackedThat: Breaking in to a Hardened Server Via the Back Door on 2024-05-04 05:53:37