Eon8
Friday, June 30th, 2006Yet another social engineering prank. I predict its not for a game or a movie, but just a simple social engineering prank. Update: I was right!
Yet another social engineering prank. I predict its not for a game or a movie, but just a simple social engineering prank. Update: I was right!
Theodore Ts’o presents: The ext4 Filesystem
Google officially announces Google Checkout
Well, I had an interesting conversation with someone on IRC a few minutes ago, discussing my earlier article on possible future monitors. Basically, to sum up his argument, he said that HDMI is the future because a few companies are already adopting it as an alternative to DVI.
The reasons I think that’s wrong is because both DVI and HDMI are pretty much technological dead ends;
On the other hand, DisplayPort fixes most of these limitations;
So, taking all of this into account, due to it’s technologically superior and cheaper to implement design, plus far stronger copy protection to ease the fears of people like George Lucas, I feel that DisplayPort is the future of display technology.
[1]: The only hardware that actually supports dual-link DVI are workstation class video cards, ie, really expensive ones. Cards that support the use of two plugs to make a dual-link connection don’t allow more than one monitor plugged in due to only having two DVI plugs to begin with. In addition, some cards allow really strange things, like using the analog part of a DVI plug and the digital part of a DVI plug to allow two monitors; this is a really stupid idea.
[2]: A hack does exist that allows 16-bit per channel data to be displayed on two single-link DVI connections, putting the least significant 8 bits on the second connection, but this is both not standardized (and very few devices support it) and not able to display resolutions that require a dual-link connection.
So, it seems, Rob got a beat down not unlike what what the US military did to Nagisaki on August 6, 1945. Lots of collateral damage, lots of /kills, and lots of people running for cover and/or leaving the network.
The attack was perpetrated by user named Jmax, who is a member of Bantown. For those that have never heard of Bantown, think of them as the GNAA on steroids.
So, Jmax somehow acquired the ircd.conf from one of the volunteer servers (presumably the admin of that machine sent it to him), which contains the password hashes for all the oper accounts, including Rob’s.
Now, a one-way hash produced by MD5 is quite useless. You can get the password out of it, but it requires a lot of CPU power to do, as you have to guess every possible combination that fits the hash.
One of the Bantown members claims they have access to a giant Cray machine deep in a research facility somewhere that has 2048 CPUs, in addition to a few racks of dual Opteron machines. If this is true or not, I don’t know… but it does explain how they cracked it so quickly.
So, getting on with the show, Jmax cracks the hash, and notices one gigantic security flaw in Rob’s oper account… mainly that it uses levin@* as the hostmask. For those that don’t get hostmasks. Now, normally, this should be levin@*.isp.he.connects.to.com, so at least Jmax would have to compromise a computer that matched that hostmask.
Jmax logs into lilo’s oper accounts, and then proceeds to /squit and otherwise delink the entire network, /kill half the network, and set new topics for a bunch of big channels. He also delinked services and/or compromised hundreds of nickserv and chanserv passwords. (Which reminds me, its time to change your passwords, everyone.)
What Jmax did is basically legal according to Federal law. Will the FBI go after him? No. Jmax, Freenode, and Rob are all small fries. There was no money lost, there was no actual damage done, and stuff was fixed within a few hours.
Now, does this mean I condone such actions? No. What Jmax did was still wrong, yet unfortunately legal. Does this mean I still want to see changes in how Freenode is operated? Yes. Does this mean I still think Rob should drop Spinhome, and actually earn his pay from PDPC? Yes.