Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Decide to 1337 hack the website, I shall just upload a file with my custom 0day html script [0]

...custom 0day html script...?

Who is this guy? Batman?

Can anybody explain how an html 0day might be able to pwn a php file uploader?

That sounds terrifying... but at least I can be somewhat reassured that nobody is going to waste that on my wordpress installation...

[0] https://web.archive.org/web/20180508063705/http://5.61.27.15...



He's joking mostly. He uploaded a webshell through the very poorly designed system that was in use. A webshell just runs whatever command it's given on a the machine its located and returns the results.

A nodejs based webshell is like 5 lines of code.

edit: imagine a URL like this: http://yourtarget.example.com/webshell?cmd=whoami

And that runs "whoami" on the target machine and returns the results.


Gotya...

So why would anyone assume that these are state sponsored hacker servers that were infiltrated then?



I suspect light sarcasm on the part of the perpetrator.


or maybe they wanted to see how much bullshit they could feed vice and still get printed


Probably this. I'm extremely left leaning but even I know vice is absolute dogshit. I used to work in the tar sands with my brother's, and once a year we have a tradition of watching the Vice tar sands "documentary" to laugh at how wildly inaccurate and ill-informed it is.


> I’m extremely left leaning but even I know vice is absolute dogshit.

Is Vice supposedly left leaning? Isn’t one of their founders an alt-right Proudboy?


Yes, but he is no longer with Vice due to “differences of opinion” with the direction of the company.


Who have since disowned Vice multiple times.


by "1337 hack" I concur, but "custom html 0day" sounds oddly specific imho.


Stylometric analysis is a thing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: