Path: csiph.com!usenet.pasdenom.info!aioe.org!news.stack.nl!newsfeed.xs4all.nl!newsfeed1.news.xs4all.nl!xs4all!post.news.xs4all.nl!not-for-mail Return-Path: X-Original-To: python-list@python.org Delivered-To: python-list@mail.python.org X-Spam-Status: OK 0.052 X-Spam-Evidence: '*H*': 0.90; '*S*': 0.00; 'encoding': 0.05; 'utf-8': 0.07; 'lawrence': 0.09; 'cc:addr:python-list': 0.11; 'python': 0.11; 'i\xe2\x80\x99m': 0.16; 'lawsuit': 0.16; 'mad,': 0.16; 'password,': 0.16; 'posting,': 0.16; 'ssh': 0.16; 'unlikely': 0.16; 'with?': 0.16; 'hire': 0.16; 'language': 0.16; 'wrote:': 0.18; '>>>': 0.22; 'appears': 0.22; 'cc:addr:python.org': 0.22; 'looks': 0.24; 'cc:2**0': 0.24; 'cc:no real name:2**0': 0.24; "i've": 0.25; 'source': 0.25; 'script': 0.25; 'long,': 0.26; 'somewhere': 0.26; 'header:In-Reply-To:1': 0.27; 'wondering': 0.29; 'chris': 0.29; '(c)': 0.29; 'message-id:@mail.gmail.com': 0.30; 'url:mailman': 0.30; 'code': 0.31; 'option.': 0.31; 'question:': 0.31; 'file': 0.32; 'this.': 0.32; 'url:python': 0.33; 'running': 0.33; 'not.': 0.33; 'sense': 0.34; 'something': 0.35; 'but': 0.35; 'received:google.com': 0.35; 'doubt': 0.36; 'in.': 0.36; 'url:listinfo': 0.36; 'doing': 0.36; "i'll": 0.36; 'url:org': 0.36; 'server': 0.38; 'pm,': 0.38; 'does': 0.39; 'url:mail': 0.40; 'how': 0.40; 'even': 0.60; 'logged': 0.60; 'most': 0.60; 'hope': 0.61; 'from:charset:utf-8': 0.61; 'skip:\xe2 10': 0.65; 'to:addr:gmail.com': 0.65; 'due': 0.66; 'account?': 0.68; '8bit%:92': 0.71; '8bit%:43': 0.74; 'saw': 0.77; 'can:': 0.84; 'greek': 0.84; 'it\xe2\x80\x99s': 0.84; 'locked': 0.84; 'me!': 0.84; 'url:tk': 0.95; '2013': 0.98 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=MtQtq/kozuCJ0da0dB4KyWtH3yu0/0W8+uP2oxmCcyo=; b=vqWM6OmQCRZaJe9xqeQq2ZR+BoihwT45lyCud99P6zwCqLG1Y2VG/xR5lB6ZZOmbBZ XIVmxW/sYqAVZNSaZd8zqCUc0aHwpQj/kZ6KQpAoq9vaE0BLbgrQg6aWkq2Ycb1mWy+y giLCGYGcoa2MgNl/m2kkADRviu1WQoB9/qagIECY69gXq2d/N0rcuYnaFmfGnYVhidLD hjJ+UmEroaE0REBX85DWqKCszZg3fMSYtBAyQUnoz9zrvODDbUnSjS0zKi5DXXsBEdXB hq0EO8cOEH9KLds0MEUjNXOQ9novhCI6fmz1DcstMo/lSpy8amBHIqsISMCpTP0bM8HU Tq3A== MIME-Version: 1.0 X-Received: by 10.50.23.46 with SMTP id j14mr18025545igf.41.1380634077524; Tue, 01 Oct 2013 06:27:57 -0700 (PDT) In-Reply-To: References: Date: Tue, 1 Oct 2013 15:27:57 +0200 Subject: Re: JUST GOT HACKED From: =?UTF-8?B?Q2hyaXMg4oCcS3dwb2xza2HigJ0gV2Fycmljaw==?= To: =?UTF-8?B?zp3Or866zr/Pgg==?= Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Cc: python-list@python.org X-BeenThere: python-list@python.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: General discussion list for the Python programming language List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Newsgroups: comp.lang.python Message-ID: Lines: 69 NNTP-Posting-Host: 2001:888:2000:d::a6 X-Trace: 1380634080 news.xs4all.nl 15952 [2001:888:2000:d::a6]:54478 X-Complaints-To: abuse@xs4all.nl Xref: csiph.com comp.lang.python:55197 On Tue, Oct 1, 2013 at 3:15 PM, =CE=9D=CE=AF=CE=BA=CE=BF=CF=82 wrote: > =CE=A3=CF=84=CE=B9=CF=82 1/10/2013 4:06 =CE=BC=CE=BC, =CE=BF/=CE=B7 Mark = Lawrence =CE=AD=CE=B3=CF=81=CE=B1=CF=88=CE=B5: >> >> On 01/10/2013 10:58, =CE=9D=CE=AF=CE=BA=CE=BF=CF=82 wrote: >>> >>> Just logged in via FTP to my server and i saw an uploade file named >>> "Warnign html" >>> >>> Contents were: >>> >>> WARNING >>> >>> I am incompetent. Do not hire me! >>> >>> Question: >>> >>> WHO AND MOST IMPORTNTANLY HOW DID HE MANAGED TO UPLOAD THIS FILE ON MY >>> ACCOUNT? >>> >>> PLEASE ANSWER ME, I WONT GET MAD, BUT THIS IS AN IMPORTANT SECURITY RIS= K. >>> >>> SOMEONES MUST HAVE ACCESS TO MY ACCOUNT, DOES THE SOURCE CODE OF MY MAI= N >>> PYTHON SCRIPT APPEARS SOMEPLACE AGAIN?!?! >> >> >> Would you please stop posting, I've almost burst my stomach laughing at >> this. You definetely have a ready made career writing comedy. > > > Okey smartass, > > Try to do it again, if you be successfull again i'll even congratulate yo= u > myself. > > -- > https://mail.python.org/mailman/listinfo/python-list It looks like you are accusing someone of doing something without any proof whatsoever. Would you like help with the fallout of the lawsuit that I hope Mark might (should!) come up with? Speaking of =E2=80=9Ctry again=E2=80=9D, I doubt it would be hard=E2=80=A6 = As long as a FTP daemon is running somewhere (and you clearly do not know better); or even you have a SSH daemon and you do not know better, an attacker can: a) wait for you to publish your password yet again; b) get you to download an exploit/keylogger/whatever; c) brute-force. Well, considering it=E2=80=99s unlikely you actually have a long-as-shit password, (c) is the best option. Unless your password is very long, in which case is not. I=E2=80=99m also wondering what language your password is in. If you actua= lly used a Greek phrase, how long will it take you to get locked out due to encoding bullshit? --=20 Chris =E2=80=9CKwpolska=E2=80=9D Warrick PGP: 5EAAEA16 stop html mail | always bottom-post | only UTF-8 makes sense