Author Topic: F-List, or "likes: root compromise"  (Read 1026 times)

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 617
  • E-points: +44/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
F-List, or "likes: root compromise"
« on: February 05, 2011, 05:42:06 pm »
This came up on IRC a day or so ago. F-list is a big fetish list for furries to use to try and find typefuck partners.

<Meredith> awesome, the dude who fucked over f-list also stole a copy of the database which means all the passwords too
<Meredith> Eevee_: Seriously. The coder who fucked up f-list has now thrown a zip of the code up on megafile or whatever and now people are going "LOOK SEE HE'S TRUSTWORTHY, HE'S SHARING DAT CODE" all the while the guy is tweeting stuff like "HA HA NOW F-LIST WILL B DESTROYD"

<Meredith> Lanther: He CLAIMS he's not gonna release the database or do anything, but I really don't believe that
<Meredith> in a fit of pique he broke everything and rootkitted the main prod server, after all

< Zidonuke> Twitter: (@Zidonuke) Time for escalation! Preparing F-List Database for  release, and tcpdumps of unencrypted password exchanges, and htaccess, chat  server logs.
<+Bentley> Zidonuke: You don't get this "nobody cares" thing, do you? ;)

So, what we have here is some kind of microcosm of FA, except for the hacks are coming from inside the LAN. I don't really approve of someone who was originally trusted with root access to go in and thrash things around like this, but whatever.

F-list's front page says "If you can't login and you've changed your password since January 28th, try logging in using your old password. All passwords were recently reset to what they were on January 28th while recovering the database. Your characters and notes are not affected."

While this isn't quite the right response to "rogue insider goes around and fucks shit up", it's a lot better than FA's response to... much of anything. Also, the userbase apparently has the same dim, incurious attitude that most furries do when faced with this kind of issue. Oh well.
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt

rodox_video

  • ***
  • Posts: 496
  • E-points: +33/-8
  • HURF DURF DUH BLUH
    • View Profile
Re: F-List, or "likes: root compromise"
« Reply #1 on: February 06, 2011, 12:06:02 am »
Huh. I did not know about this. So who is this again, and why the fuck did he do it?
Zeriara is part of a series on Whores.

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 617
  • E-points: +44/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
Re: F-List, or "likes: root compromise"
« Reply #2 on: February 06, 2011, 12:36:20 am »
I dunno. I'm just curious as to the state of modern-day Linux rootkits.

Amazing, though. Did they actually restore, from a working backup, a copy of the site before it was compromised?
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt