<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 8083</title>
	<link>http://www.metafilter.com/8083//</link>
	<description>Comments on MetaFilter post Comments on 8083</description>
	<pubDate>Wed, 06 Jun 2001 00:21:38 -0800</pubDate>
	<lastBuildDate>Wed, 06 Jun 2001 00:21:38 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 8083</title>
		<link>http://www.metafilter.com/8083/</link>	
		<description>&lt;a href="http://www.metafilter.com/"&gt;EEEEEEEEEEEEK.&lt;/a&gt; Matt, hope you see this soon.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2001:site.8083</guid>
		<pubDate>Wed, 06 Jun 2001 00:17:43 -0800</pubDate>
		<dc:creator>cheaily</dc:creator>		<category>brokenlink</category>		<category>metafilter</category>		<category>hackers</category>
	</item>	<item>
		<title>By: cheaily</title>
		<link>http://www.metafilter.com/8083/#89678</link>	
		<description>in case you&apos;re wondering what i&apos;m on about: &lt;a href=&quot;http://dan.hyperstate.asn.au/mefihack.html&quot;&gt;mefi was hacked at approximately 12.15am PST&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89678</guid>
		<pubDate>Wed, 06 Jun 2001 00:21:38 -0800</pubDate>
		<dc:creator>cheaily</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/8083/#89679</link>	
		<description>Working on it with qJason for the past couple hours. I know exactly how they did it, what they did, and how they covered their tracks. I also know why it happened, which we&apos;re trying to fix now. 

The long story short is a stupid microsoft security patch installer is to blame for leaving the vulnerability open.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89679</guid>
		<pubDate>Wed, 06 Jun 2001 02:22:28 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: delfuego</title>
		<link>http://www.metafilter.com/8083/#89680</link>	
		<description>Figured out the problem with the hotfix installer, and patched the system about 20 minutes ago.

Should be ready to rock; we&apos;ll see about that.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89680</guid>
		<pubDate>Wed, 06 Jun 2001 03:49:51 -0800</pubDate>
		<dc:creator>delfuego</dc:creator>
	</item>	<item>
		<title>By: capt.crackpipe</title>
		<link>http://www.metafilter.com/8083/#89681</link>	
		<description>Wow, that was like a public service hack.

&quot;If you want more info on whats wrong with ur box Mr. Admin email me ... (yea we can still be friends ;p).&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89681</guid>
		<pubDate>Wed, 06 Jun 2001 04:03:26 -0800</pubDate>
		<dc:creator>capt.crackpipe</dc:creator>
	</item>	<item>
		<title>By: internook</title>
		<link>http://www.metafilter.com/8083/#89682</link>	
		<description>A public service hack is like a window salesman smashing your windows to show you the drafts in your house.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89682</guid>
		<pubDate>Wed, 06 Jun 2001 04:25:08 -0800</pubDate>
		<dc:creator>internook</dc:creator>
	</item>	<item>
		<title>By: TuxHeDoh</title>
		<link>http://www.metafilter.com/8083/#89688</link>	
		<description>&lt;quote&gt;... is like a window salesman smashing your windows....&lt;/quote&gt;
&lt;p&gt;Until I got to the end of the line, I swore you were talking about Windows - 95, NT, 2k.  Funny.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89688</guid>
		<pubDate>Wed, 06 Jun 2001 05:08:21 -0800</pubDate>
		<dc:creator>TuxHeDoh</dc:creator>
	</item>	<item>
		<title>By: m.polo</title>
		<link>http://www.metafilter.com/8083/#89690</link>	
		<description>&lt;i&gt;(yea we can still be friends ;p).&lt;/i&gt;

Hmm... With friends like &lt;i&gt;these&lt;/i&gt;, who needs...

Never mind.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89690</guid>
		<pubDate>Wed, 06 Jun 2001 05:17:11 -0800</pubDate>
		<dc:creator>m.polo</dc:creator>
	</item>	<item>
		<title>By: mecran01</title>
		<link>http://www.metafilter.com/8083/#89694</link>	
		<description>The self-righteousness of the cracker is reallly annoying.  And if they&apos;re going to break into machines, why not put up something funny or interesting? geesh.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89694</guid>
		<pubDate>Wed, 06 Jun 2001 05:30:37 -0800</pubDate>
		<dc:creator>mecran01</dc:creator>
	</item>	<item>
		<title>By: Irontom</title>
		<link>http://www.metafilter.com/8083/#89697</link>	
		<description>In light of the link that was posted earlier this week about the &lt;a href=&quot;http://www.metafilter.com/comments.mefi/8006&quot;&gt;GNC DDOS attacks&lt;/a&gt;, this is in fact a pretty mild attack.  

On my own site, I would certainly prefer this kind of annoyance to some of the others that I have seen in the past.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89697</guid>
		<pubDate>Wed, 06 Jun 2001 05:37:09 -0800</pubDate>
		<dc:creator>Irontom</dc:creator>
	</item>	<item>
		<title>By: donkeymon</title>
		<link>http://www.metafilter.com/8083/#89700</link>	
		<description>I think that psychologically the cracker is riding the fence. They want the recognition of being Mr. Big-Time Cracker Guy, but they don&apos;t want to feel like a bad person and cry themselves to sleep at night, so instead of sending a nice email to Matt saying &quot;Hey, here is this huge hole&quot; or instead of trashing everything on the site, they go right down the middle and deface the site without really messing anything up. That is probably how I would do it too, I guess.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89700</guid>
		<pubDate>Wed, 06 Jun 2001 05:50:00 -0800</pubDate>
		<dc:creator>donkeymon</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/8083/#89710</link>	
		<description>  This guy isnt even a cracker, he&apos;s a defacer.  Its definately a mixed bag, these big egos have to write something and a simple email to the admin saying &apos;Check out Q248483 for the hotfix you need before its too late&apos;  doesn&apos;t do it for them.  Usually when that happens there&apos;s a public thank you and no one has to hide behind silly names like k0Ng&apos;daCrAk3R. I think its the fear of not getting a public thank you that drives &quot;nice defacers.&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89710</guid>
		<pubDate>Wed, 06 Jun 2001 06:25:54 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: ktheory</title>
		<link>http://www.metafilter.com/8083/#89713</link>	
		<description>This hacker sounds more like a punk script kiddie, try to get cred, than anything else.

He wasn&apos;t really being altruistic, because he could have simply emailed Matt about the problem.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89713</guid>
		<pubDate>Wed, 06 Jun 2001 06:30:52 -0800</pubDate>
		<dc:creator>ktheory</dc:creator>
	</item>	<item>
		<title>By: ktheory</title>
		<link>http://www.metafilter.com/8083/#89715</link>	
		<description>Umm, I agree will skallas.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89715</guid>
		<pubDate>Wed, 06 Jun 2001 06:31:47 -0800</pubDate>
		<dc:creator>ktheory</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/8083/#89716</link>	
		<description>Sorry about the double, but jumped the gun.

   I&apos;m sure this guy/gal, like lots of netizens out there want to legitimize the classical definiation of &apos;Hacker&apos; as opposed to Cracker, but they continue to act like a typical Cracker or scriptkid that more or less feeds the anti-Hacker rhetoric.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89716</guid>
		<pubDate>Wed, 06 Jun 2001 06:33:37 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: fleener</title>
		<link>http://www.metafilter.com/8083/#89720</link>	
		<description>Seems like a graffiti tagger putting his name on buildings instead of burning them down so as to inform us the building security sucks. OK, but, uhhh, we pretty much already know that. 

We operate everyday on an assumption that people will act in a civil manner. Storefronts like MetaFilter don&apos;t need ultratight security. They shouldn&apos;t need to hire a security guard to patrol their sidewalk to keep even taggers away. It&apos;s the banks and government offices that control sensitive information that we want being totally secure. MeFi doesn&apos;t even have credit card numbers on record, so what point is made in hacking us?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89720</guid>
		<pubDate>Wed, 06 Jun 2001 06:40:33 -0800</pubDate>
		<dc:creator>fleener</dc:creator>
	</item>	<item>
		<title>By: whuppy</title>
		<link>http://www.metafilter.com/8083/#89723</link>	
		<description>Time to switch to &lt;a href=&quot;www.openbsd.org&quot;&gt;OpenBSD&lt;/a&gt;!.
&lt;br&gt;
Okay, sorry, I&apos;ll go back to Slashdot now.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89723</guid>
		<pubDate>Wed, 06 Jun 2001 06:49:03 -0800</pubDate>
		<dc:creator>whuppy</dc:creator>
	</item>	<item>
		<title>By: whuppy</title>
		<link>http://www.metafilter.com/8083/#89725</link>	
		<description>Seriously, though:  What are the issues involved in migrating MeFi to a real operating system?  (ouch! okay, okay, I&apos;ll see you over in MetaTalk . . .)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89725</guid>
		<pubDate>Wed, 06 Jun 2001 06:52:33 -0800</pubDate>
		<dc:creator>whuppy</dc:creator>
	</item>	<item>
		<title>By: jpoulos</title>
		<link>http://www.metafilter.com/8083/#89727</link>	
		<description>&lt;i&gt;This hacker sounds more like a punk script kiddie&lt;/i&gt;

&lt;a href=&quot;http://www.metafilter.com/comments.mefi/8006#88298&quot;&gt;DON&apos;T SAY &quot;SCRIPT KIDDIES&quot;!!!&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89727</guid>
		<pubDate>Wed, 06 Jun 2001 06:55:19 -0800</pubDate>
		<dc:creator>jpoulos</dc:creator>
	</item>	<item>
		<title>By: PWA_BadBoy</title>
		<link>http://www.metafilter.com/8083/#89732</link>	
		<description>What&apos;s wrong with &quot;script kiddies&quot;? That&apos;s exactly what they are. There&apos;s no m4d 5k1llz involved in hacking IIS servers. Just gotta know where to find the pre-written app that&apos;ll let you &quot;hack&quot; into the server. Plug in the IP and away you go. It&apos;s stupid really. Please give the hackers the respect they deserve and properly term these IIS &quot;hackers&quot; as &quot;script kiddies&quot;, ok?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89732</guid>
		<pubDate>Wed, 06 Jun 2001 07:00:12 -0800</pubDate>
		<dc:creator>PWA_BadBoy</dc:creator>
	</item>	<item>
		<title>By: ph00dz</title>
		<link>http://www.metafilter.com/8083/#89743</link>	
		<description>In defense of the script kiddies -- I recently got my hands on a really nice &quot;vulnerability testing script&quot; and I&apos;ve gotta say, it was almost impossible to keep myself from wandering around, defacing people&apos;s sites. (I didn&apos;t actually do that, but I did poke around in some places I probably shouldn&apos;t have)

You&apos;d be shocked at how many sites are still vulnerable to that big IIS bug that was announced recently...

I can imagine in the eyes of a 16-year old pimply faced kid, defacing sites would be a pretty exciting pastime.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89743</guid>
		<pubDate>Wed, 06 Jun 2001 07:16:57 -0800</pubDate>
		<dc:creator>ph00dz</dc:creator>
	</item>	<item>
		<title>By: darukaru</title>
		<link>http://www.metafilter.com/8083/#89744</link>	
		<description>up ur connection, foo, cause they will just keep comin at you</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89744</guid>
		<pubDate>Wed, 06 Jun 2001 07:17:00 -0800</pubDate>
		<dc:creator>darukaru</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/8083/#89746</link>	
		<description>&lt;I&gt;Storefronts like MetaFilter don&apos;t need ultratight security. &lt;/I&gt;

I hope you&apos;re not a system admin.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89746</guid>
		<pubDate>Wed, 06 Jun 2001 07:21:13 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: fleener</title>
		<link>http://www.metafilter.com/8083/#89751</link>	
		<description>Skallas, nope. I just draw a distinction between critical and non-critical web sites. OK, yes, tight security is needed everywhere in the sense that a low-priority site is likely hosted on a server along with high-priority sites, so the server needs tight security.  I guess I&apos;m asking, what purpose is served in disturbing MeFi when there are bigger sites that we will *really* care to know have lax security. When MeFi is hacked, people think &quot;Oh, that&apos;s an inconvenience, boy I wish those hackers would stop annoying us.&quot; If Amazon gets hacked, we think &quot;Oh shit, and they have my credit card number!&quot;  One has impact, the other is just annoying, in the eyes of average people.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89751</guid>
		<pubDate>Wed, 06 Jun 2001 07:30:40 -0800</pubDate>
		<dc:creator>fleener</dc:creator>
	</item>	<item>
		<title>By: lotsofno</title>
		<link>http://www.metafilter.com/8083/#89760</link>	
		<description>damn, everyone took the good allusions to the grc column...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89760</guid>
		<pubDate>Wed, 06 Jun 2001 07:39:06 -0800</pubDate>
		<dc:creator>lotsofno</dc:creator>
	</item>	<item>
		<title>By: jpoulos</title>
		<link>http://www.metafilter.com/8083/#89765</link>	
		<description>I should have added a :-) to my hysterical warning about the term SCRIPT KIDDIES. &lt;a href=&quot;http://www.metafilter.com/comments.mefi/8006&quot;&gt;Wicked hates that&lt;/a&gt;, and I bet SonicX does too. :-)

For some reason, when I hear that term, I think of the paperboys in &lt;a href=&quot;http://us.imdb.com/Title?0088794&quot;&gt;&lt;i&gt;Better Off Dead&lt;/i&gt;&lt;/a&gt;.

&quot;We want our two dollars......&quot;

&quot;We want our m4d 5k1llz....&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89765</guid>
		<pubDate>Wed, 06 Jun 2001 07:49:25 -0800</pubDate>
		<dc:creator>jpoulos</dc:creator>
	</item>	<item>
		<title>By: fooljay</title>
		<link>http://www.metafilter.com/8083/#89769</link>	
		<description>Actually Skallas, everyone needs tight security, even if there&apos;s nothing but the operating system on the server.  Why?  Because, if for no other reason, it provides a base of operations for unaccountable distributed denial of service attacks.  

For those who don&apos;t know what that means (or have never been on the receiving end of one, as I have), what usually happens is this:  Someone breaks into a bunch of unsecured (and hopefully underused) servers.  They plant a client on the machine, replace a few binaries with Trojans to give them easy access back in, and cover their tracks on their way out.

Once they have enough dummy servers around the internet, they can remotely launch a Denial of Service attack (usually in the form of massive repeated pinging) from so many different points that the administrators of the attacked site can&apos;t possibly shut out all of them at the router. 

Successful attacks will take out nearly any site.

By the way, Matt, I would be very very careful about continuing on without a full security survey.  Something about the message makes me think he&apos;s trying to lull you to sleep.  Are you sure that they didn&apos;t leave any back doors or trojans?  (One can&apos;t ever really be sure of this sort of thing, unless you&apos;re running something like Tripwire (on Unix) and running it correctly)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89769</guid>
		<pubDate>Wed, 06 Jun 2001 08:10:33 -0800</pubDate>
		<dc:creator>fooljay</dc:creator>
	</item>	<item>
		<title>By: fleener</title>
		<link>http://www.metafilter.com/8083/#89770</link>	
		<description>fooljay, are the people hacking web sites the same people doing Denial of Service attacks?  If yes, isn&apos;t that a vicious cycle? e.g., I deface your site to encourage you to get better security against hackers, while at the same time launching Denial of Service attacks against other people. Am I warning you about myself? Or is it being said that site taggers are the &quot;good guys&quot; and that they don&apos;t do denial of service attacks?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89770</guid>
		<pubDate>Wed, 06 Jun 2001 08:16:21 -0800</pubDate>
		<dc:creator>fleener</dc:creator>
	</item>	<item>
		<title>By: dhartung</title>
		<link>http://www.metafilter.com/8083/#89865</link>	
		<description>I don&apos;t generally believe that DDoSers are going to be the same range of personalities for the defacers. Defacers want credit, and are usually sort of hit-and-run. DDoSers have to keep their conquests secret, install backdoors, et cetera, and when they launch their attack it&apos;s usually somebody they have some kind of grudge against.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89865</guid>
		<pubDate>Wed, 06 Jun 2001 10:25:28 -0800</pubDate>
		<dc:creator>dhartung</dc:creator>
	</item>	<item>
		<title>By: sugarfish</title>
		<link>http://www.metafilter.com/8083/#89910</link>	
		<description>is there a mirror of this anywhere?  it sucks ass that it happened, but i wanna see!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89910</guid>
		<pubDate>Wed, 06 Jun 2001 10:53:05 -0800</pubDate>
		<dc:creator>sugarfish</dc:creator>
	</item>	<item>
		<title>By: bradlands</title>
		<link>http://www.metafilter.com/8083/#89927</link>	
		<description>&lt;A HREF=&quot;http://www.bradlands.com/art/elsewhere/1142/mefiHack.gif&quot;&gt;Screenshot here&lt;/A&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89927</guid>
		<pubDate>Wed, 06 Jun 2001 11:16:17 -0800</pubDate>
		<dc:creator>bradlands</dc:creator>
	</item>	<item>
		<title>By: barbelith</title>
		<link>http://www.metafilter.com/8083/#89940</link>	
		<description>I&apos;d be really interested in getting Matt&apos;s opinion on this...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89940</guid>
		<pubDate>Wed, 06 Jun 2001 11:40:58 -0800</pubDate>
		<dc:creator>barbelith</dc:creator>
	</item>	<item>
		<title>By: SpecialK</title>
		<link>http://www.metafilter.com/8083/#89947</link>	
		<description>Sugar, the link in the first comment is a mirror.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89947</guid>
		<pubDate>Wed, 06 Jun 2001 11:47:17 -0800</pubDate>
		<dc:creator>SpecialK</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/8083/#89960</link>	
		<description>there&apos;s a mirror in the first comment, and &lt;a href=&quot;/hacked.cfm&quot;&gt;I saved the page here&lt;/a&gt;.

I was shocked and pissed at first, and did the immediate &quot;oh god, when was the last time I backed up the files and database?&quot; thought. Jason called me at about 12:30AM last night (I was in bed, reading Fast Food Nation) and we ended up researching it and IMing back and forth for a few hours. I actually emailed the kid and he emailed back almost immediately. We found in the logs what went on, and I remembered why this was possible in the first place.

&lt;b&gt;So here&apos;s a breakdown:&lt;/b&gt;
On May 14th, MS released &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS01-026.asp&quot;&gt;a patch&lt;/a&gt; for a particularly nasty IIS bug. You could, using only a URL and port 80, run command line arguments on any IIS site. I tried to install the patch the day it was released, but it wouldn&apos;t install. A few days later, I installed Service Pack 2, and figured I was ok.

It turns out service pack two included earlier IIS hotfixes, but not this May 14th one. I got an email yesterday from an admin in the UK saying that I was open to this sort of hacking and I should patch it up quick. So I tried to install it again, and again, got the error. &lt;a href=&quot;http://groups.google.com/groups?q=httpext.dll&amp;hl=en&amp;lr=&amp;safe=off&amp;rnum=3&amp;ic=1&amp;selm=3b012923.100691727%40172.1.40.24&quot;&gt;This is precisely what the error was&lt;/a&gt;.

So I still couldn&apos;t figure it out, and was going to contact Jason and ask his opinion of it eventually, but the hack happened last night, so we had to do it asap.

Jason figured out that the error occurred because I disabled WebDAV support. The person in the linked usenet post emailed me back, saying he got the error because he installed Microsoft&apos;s suggested access control list on the file. The WebDAV disabling was also in an earlier Microsoft IIS security bulletin, so I&apos;m a bit pissed at Microsoft for not doing the necessary quality control to spit out a better error than &quot;can&apos;t find the file httpext.dll&quot; (when the file exists exactly where the installer was looking for it). It would have been a lot nicer if the error was &quot;You need to enable WebDAV before installing&quot; or &quot;You need to update your ACLs on the file httpext.dll before installing.&quot;

So, the hacker/cracker/defacer seems to originate from a proxy server in Spain, cloaking their true location somewhat, and has visited MetaFilter a couple times. Last night the person used the exploit to transfer a single file to the server, called upload.asp. Though I don&apos;t use any ASP on MetaFilter.com, I left the parsing on for this site, so the uploaded file worked for them. They then used it to upload their new index file, and renamed the old one, then they removed the upload.asp and left. 

The &lt;a href=&quot;http://www.hushmail.com/terms/&quot;&gt;Hushmail TOS&lt;/a&gt; seems to outlaw use of its system for communicating with hacked site owners, so at worst I could probably get that email account cancelled, at best I could probably get the IP used to connect to Hushmail. Maybe the Spanish proxy server is a compromised box as well, who knows. I don&apos;t know if pursuing any of these avenues would help more than hurt me in the long run though.

So, after losing a few hours of sleep and finally getting the hotfixes installed, my opinion of Microsoft&apos;s QA department isn&apos;t very high.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89960</guid>
		<pubDate>Wed, 06 Jun 2001 12:02:51 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: CrayDrygu</title>
		<link>http://www.metafilter.com/8083/#89997</link>	
		<description>&lt;i&gt;&quot;Though I don&apos;t use any ASP on MetaFilter.com&quot;&lt;/i&gt;

Which reminds me, I&apos;ve always wondered what Mefi was written in.  I don&apos;t recognize the .cfm extention, and web searches on it (which I&apos;m usually good with) aren&apos;t turning up anything useful.

&lt;i&gt;&quot;my opinion of Microsoft&apos;s QA department isn&apos;t very high&quot;&lt;/i&gt;

Took you this long? ;)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-89997</guid>
		<pubDate>Wed, 06 Jun 2001 12:48:45 -0800</pubDate>
		<dc:creator>CrayDrygu</dc:creator>
	</item>	<item>
		<title>By: igloo</title>
		<link>http://www.metafilter.com/8083/#90001</link>	
		<description>.cfm is Cold Fusion</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90001</guid>
		<pubDate>Wed, 06 Jun 2001 12:56:56 -0800</pubDate>
		<dc:creator>igloo</dc:creator>
	</item>	<item>
		<title>By: jpoulos</title>
		<link>http://www.metafilter.com/8083/#90032</link>	
		<description>&lt;i&gt;. I don&apos;t know if pursuing any of these avenues would help more than hurt me in the long run though.&lt;/i&gt;?

Matt, bro, you&apos;ve got the MeFi Mob&#8482; on your side. :-)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90032</guid>
		<pubDate>Wed, 06 Jun 2001 13:29:47 -0800</pubDate>
		<dc:creator>jpoulos</dc:creator>
	</item>	<item>
		<title>By: benbrown</title>
		<link>http://www.metafilter.com/8083/#90088</link>	
		<description>Matt, you should contact the admin of the proxy server in Spain to warn him that his box may be compromised.  You should also contact Hushmail if only to tell them that someone may be using their service for illegal purposes.

If your machine was in Virginia, you could have the dude arrested.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90088</guid>
		<pubDate>Wed, 06 Jun 2001 14:55:37 -0800</pubDate>
		<dc:creator>benbrown</dc:creator>
	</item>	<item>
		<title>By: kindall</title>
		<link>http://www.metafilter.com/8083/#90109</link>	
		<description>&lt;I&gt;.cfm is Cold Fusion&lt;/I&gt;

Which has always bugged me to no end, because I couldn&apos;t figure out what the hell the &quot;m&quot; stood for. And also because CFM is the Code Fragment Manager on the Mac.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90109</guid>
		<pubDate>Wed, 06 Jun 2001 15:38:13 -0800</pubDate>
		<dc:creator>kindall</dc:creator>
	</item>	<item>
		<title>By: rodii</title>
		<link>http://www.metafilter.com/8083/#90112</link>	
		<description>It was originally called Cold Fusiom.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90112</guid>
		<pubDate>Wed, 06 Jun 2001 15:40:28 -0800</pubDate>
		<dc:creator>rodii</dc:creator>
	</item>	<item>
		<title>By: bradlands</title>
		<link>http://www.metafilter.com/8083/#90149</link>	
		<description>&lt;EM&gt;If your machine was in Virginia, you could have the dude arrested.&lt;/EM&gt;

Jason! Time to call FedEx again!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90149</guid>
		<pubDate>Wed, 06 Jun 2001 16:30:28 -0800</pubDate>
		<dc:creator>bradlands</dc:creator>
	</item>	<item>
		<title>By: tomorama</title>
		<link>http://www.metafilter.com/8083/#90156</link>	
		<description>&lt;i&gt;Which has always bugged me to no end, because I couldn&apos;t figure out what the hell the &quot;m&quot; stood for&lt;/i&gt;

I&apos;ve always assumed &lt;b&gt;C&lt;/b&gt;old &lt;b&gt;F&lt;/b&gt;usion &lt;b&gt;M&lt;/b&gt;arkup</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90156</guid>
		<pubDate>Wed, 06 Jun 2001 16:46:54 -0800</pubDate>
		<dc:creator>tomorama</dc:creator>
	</item>	<item>
		<title>By: Awol</title>
		<link>http://www.metafilter.com/8083/#90158</link>	
		<description>I always assumed the &quot;m&quot; stood for mark-up.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90158</guid>
		<pubDate>Wed, 06 Jun 2001 16:51:25 -0800</pubDate>
		<dc:creator>Awol</dc:creator>
	</item>	<item>
		<title>By: jpoulos</title>
		<link>http://www.metafilter.com/8083/#90183</link>	
		<description>&lt;i&gt;I always assumed the &quot;m&quot; stood for mark-up.&lt;/i&gt;

Right. Techincally, it&apos;s known as Cold Fusion Markup Language, CFML (vs. HTML). You&apos;ll note that web pages can have the extension .htm</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90183</guid>
		<pubDate>Wed, 06 Jun 2001 17:21:04 -0800</pubDate>
		<dc:creator>jpoulos</dc:creator>
	</item>	<item>
		<title>By: jpoulos</title>
		<link>http://www.metafilter.com/8083/#90184</link>	
		<description>&lt;i&gt;You should also contact Hushmail if only to tell them that someone may be using their service for illegal purposes.&lt;/i&gt;

I&apos;m sure they&apos;d be &lt;i&gt;shocked&lt;/i&gt; to hear that.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90184</guid>
		<pubDate>Wed, 06 Jun 2001 17:22:06 -0800</pubDate>
		<dc:creator>jpoulos</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/8083/#90190</link>	
		<description>I did contact hushmail and this is what they had to say (they don&apos;t keep track of IP access? yeah right):
&lt;blockquote&gt;From: postmaster@hushmail.com
Date: Wed, 6 Jun 2001 16:11:03 -0800 (PDT)
To: matt@haughey.com
Subject: Re: HushMail.com Contact Form Submittal

Hello,

Unfortunately we don&apos;t log IP addresses against account activity, so we don&apos;t have any way of providing this information.  If you would like to get what info we do have, then please contact you local police department, as we require a hard-copy court issued subpeona.  You might try checking with your upstream provider and seeing if they have any IP logs that might be of help.  We will disable this account if you send us a copy of the e-mail with the headers. 

All the best,
TeamHush.&lt;/blockquote&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90190</guid>
		<pubDate>Wed, 06 Jun 2001 17:33:08 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: fooljay</title>
		<link>http://www.metafilter.com/8083/#90223</link>	
		<description>&lt;i&gt;fooljay, are the people hacking web sites the same people doing Denial of Service attacks?&lt;/i&gt;

I think in most cases, no.

However, I happen to have run across one individual in the past who was a serious (dark-)grey-hat hacker.  He would break into sites through various exploits, then plant his trojans.  Apparently he was very very good at covering his tracks to avoid detection by detection systems (usually because they were poorly configured).  To dissuade the sysadmins from doubting their IDSs, he would create new tracks mimicking a scr*pt k*ddie and deface the page giving a &quot;shout out to his peeps&quot;, who were invaribly imaginary.

While it seems like a lot of work, apparently the thrill of breaking into other systems wasn&apos;t enough for him, so his new game became nothing more than how long he could have access to the compromised systems.

&lt;i&gt;Or is it being said that site taggers are the &quot;good guys&quot; and that they don&apos;t do denial of service attacks?&lt;/i&gt;

I don&apos;t believe that there&apos;s a clear line or overlap, but either way, a &lt;b&gt;true&lt;/b&gt; white-hat does not deface.  He informs the sysadmin of the vulnerable site.  At most, he gains access to the system, reads a file from the filesystem (for proof of intrusion) and then logs the hell out.

I am not a hacker.  Just a hack...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90223</guid>
		<pubDate>Wed, 06 Jun 2001 19:41:02 -0800</pubDate>
		<dc:creator>fooljay</dc:creator>
	</item>	<item>
		<title>By: lagado</title>
		<link>http://www.metafilter.com/8083/#90243</link>	
		<description>I would be very wary of the system now. Just because the hack appeared harmless doesn&apos;t mean it actually was. As fooljay implied it&apos;s hard to know what you&apos;re up against here. This airchair personality profiling going on about black hats and white hats is not really helping. 

This exploit is the same one used by the PoisonBox worm (mentioned here a few weeks back) and it&apos;s big enough to drive a truck through. It allows any one to execute any code on the Windows command line. The biggest security hole of all however is the Windows NT operating system itself. It&apos;s just too big and complex to ever really be secure.

I love the way Microsoft requires you to have WebDAV enabled in order to install the security patch. WebDAV is potentially another security hole and probably should be off.

Trust Microsoft, I mean don&apos;t!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90243</guid>
		<pubDate>Wed, 06 Jun 2001 20:43:00 -0800</pubDate>
		<dc:creator>lagado</dc:creator>
	</item>	<item>
		<title>By: fooljay</title>
		<link>http://www.metafilter.com/8083/#90246</link>	
		<description>&lt;i&gt;big and complex&lt;/i&gt;

You misspelled &quot;closed source&quot;...  ;)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90246</guid>
		<pubDate>Wed, 06 Jun 2001 21:04:33 -0800</pubDate>
		<dc:creator>fooljay</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/8083/#90260</link>	
		<description>I&apos;ve done a full security check through the OS, looked for trojans listening on different ports, sniffed for backdoor programs, ran Steve Gibson&apos;s little security checker and everything seems clean. WebDAV is back off, and all the latest patches are on the box.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90260</guid>
		<pubDate>Wed, 06 Jun 2001 21:50:07 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: fooljay</title>
		<link>http://www.metafilter.com/8083/#90289</link>	
		<description>Nice job, Matt...  Now aren&apos;t you glad it happened when you had plenty of time on your hands?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90289</guid>
		<pubDate>Thu, 07 Jun 2001 01:42:51 -0800</pubDate>
		<dc:creator>fooljay</dc:creator>
	</item>	<item>
		<title>By: kindall</title>
		<link>http://www.metafilter.com/8083/#90388</link>	
		<description>&lt;I&gt;I always assumed the &quot;m&quot; stood for mark-up.&lt;/I&gt; ... &lt;I&gt;You&apos;ll note that web pages can have the extension .htm&lt;/I&gt;

Naming your HTML files &quot;*.htm&quot; is like asking yourself, &quot;What would Jesus?&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90388</guid>
		<pubDate>Thu, 07 Jun 2001 08:05:50 -0800</pubDate>
		<dc:creator>kindall</dc:creator>
	</item>	<item>
		<title>By: Dn</title>
		<link>http://www.metafilter.com/8083/#90409</link>	
		<description>well, not really.. it&apos;s actually allowing dos based browsers that can only handle a three-letter ext on files to still browse!!..hehe..</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90409</guid>
		<pubDate>Thu, 07 Jun 2001 08:27:39 -0800</pubDate>
		<dc:creator>Dn</dc:creator>
	</item>	<item>
		<title>By: CrayDrygu</title>
		<link>http://www.metafilter.com/8083/#90654</link>	
		<description>&lt;i&gt;&quot;it&apos;s actually allowing dos based browsers...&quot;&lt;/i&gt;

No it&apos;s not.  The URL is completely independant of that.  Anyone who&apos;s used Windows 3.1 for web surfing (as I have) should know that, since .html and other assorted 4-letter extentions work just fine.

In fact, your browser doesn&apos;t care one bit what the file extention on the other end is, since the way your browser determines what kind of data to expect is sent in the MIME type.  I could configure my server to return &quot;text/plain&quot; for all &quot;.mov&quot; files, and name my text files *.mov, and only broken browsers would try to show them in QuickTime.

The main reason for allowing .htm is because, Back in The Day, people would write websites using OSes that only supported three-letter extentions.  It&apos;s kinda hard to develop a website where pages end in &quot;.html&quot; when your OS doesn&apos;t support it.  Sure, you could rename them on the server, but it would break all your links.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-90654</guid>
		<pubDate>Thu, 07 Jun 2001 13:02:13 -0800</pubDate>
		<dc:creator>CrayDrygu</dc:creator>
	</item>	<item>
		<title>By: wackybrit</title>
		<link>http://www.metafilter.com/8083/#91061</link>	
		<description>Simply e-mailing Matt might not have been an option.

I don&apos;t know about Matt, but there are many webmasters who are -not interested- in holes in their system. However, when their home page is suddenly changed, they suddenly become very enthusiastic to solve the problem.

I know, because it happened to me. I had a well known forum script running on my site and I knew there was a patch I could get to fix a hole in it.. but I didn&apos;t bother until a week after someone actually hacked it.

Some of us are so busy, that we can&apos;t help but be apathetic until something really happens.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.8083-91061</guid>
		<pubDate>Fri, 08 Jun 2001 08:43:05 -0800</pubDate>
		<dc:creator>wackybrit</dc:creator>
	</item>
	</channel>
</rss>
