Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.advocacy > #343721 > unrolled thread
| Started by | Melzzzzz <mel@zzzzz.com> |
|---|---|
| First post | 2016-02-16 19:14 +0100 |
| Last post | 2016-02-17 05:11 -0800 |
| Articles | 18 — 6 participants |
Back to article view | Back to comp.os.linux.advocacy
Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:14 +0100
Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 13:42 -0500
Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:54 +0100
Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 14:19 -0500
Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 20:52 +0100
Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:23 -0500
Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 12:44 +0000
Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 20:05 +0000
Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:34 -0500
Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 21:05 +0000
Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 16:42 -0500
Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 22:13 +0000
Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 19:41 -0500
Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 00:49 +0000
Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 20:05 -0500
Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 14:16 +0000
Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 18:59 +0000
Re: Windows? John Gohde <john.h.gohde@gmail.com> - 2016-02-17 05:11 -0800
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-16 19:14 +0100 |
| Subject | Windows? |
| Message-ID | <20160216191422.48cb0e82@maxa-pc> |
http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm " Hackers have taken the computer system of the Hollywood Presbyterian Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. "
[toc] | [next] | [standalone]
| From | "Ezekiel" <zeke@nosuchemail.com> |
|---|---|
| Date | 2016-02-16 13:42 -0500 |
| Message-ID | <n9vqdf$n7d$1@dont-email.me> |
| In reply to | #343721 |
"Melzzzzz" <mel@zzzzz.com> wrote in message
news:20160216191422.48cb0e82@maxa-pc...
> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> "
> Hackers have taken the computer system of the Hollywood Presbyterian
> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
> "
"The administration has forbidden the use of other computers
for fear that the harmful software could spread to more workstations."
Most likely Windows if it's workstations.
I could see local data being encrypted/taken-hostage but all the important
stuff at a hospital should be on some backend DB running on a server. IT
should constantly be backing up this data. If the servers weren't
compromised (and they shouldn't have) then what does the $3.6M get them?
Did they get in by leaving USB drives in the parking lot?
There are always going to be places with terrible security practices. The
hackers just need to find them.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-16 19:54 +0100 |
| Message-ID | <20160216195425.1b1906d8@maxa-pc> |
| In reply to | #343724 |
On Tue, 16 Feb 2016 13:42:52 -0500 "Ezekiel" <zeke@nosuchemail.com> wrote: > "Melzzzzz" <mel@zzzzz.com> wrote in message > news:20160216191422.48cb0e82@maxa-pc... > > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm > > " > > Hackers have taken the computer system of the Hollywood Presbyterian > > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. > > " > > "The administration has forbidden the use of other computers > for fear that the harmful software could spread to more > workstations." > > Most likely Windows if it's workstations. > > I could see local data being encrypted/taken-hostage but all the > important stuff at a hospital should be on some backend DB running on > a server. IT should constantly be backing up this data. If the > servers weren't compromised (and they shouldn't have) then what does > the $3.6M get them? Problem is always one machine that keeps important password(s). That goes like that. User plugs in usb key with game or access some malware site, etc. When hacker gets passwords for access to server, all is lost. No matter OS on the server. > > Did they get in by leaving USB drives in the parking lot? Probably. > > There are always going to be places with terrible security practices. > The hackers just need to find them. Imagine computer security in hospital ;) > > >
[toc] | [prev] | [next] | [standalone]
| From | "Ezekiel" <zeke@nosuchemail.com> |
|---|---|
| Date | 2016-02-16 14:19 -0500 |
| Message-ID | <n9vshp$dd$1@dont-email.me> |
| In reply to | #343729 |
"Melzzzzz" <mel@zzzzz.com> wrote in message news:20160216195425.1b1906d8@maxa-pc... > On Tue, 16 Feb 2016 13:42:52 -0500 > "Ezekiel" <zeke@nosuchemail.com> wrote: > >> "Melzzzzz" <mel@zzzzz.com> wrote in message >> news:20160216191422.48cb0e82@maxa-pc... >> > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >> > " >> > Hackers have taken the computer system of the Hollywood Presbyterian >> > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >> > " >> >> "The administration has forbidden the use of other computers >> for fear that the harmful software could spread to more >> workstations." >> >> Most likely Windows if it's workstations. >> >> I could see local data being encrypted/taken-hostage but all the >> important stuff at a hospital should be on some backend DB running on >> a server. IT should constantly be backing up this data. If the >> servers weren't compromised (and they shouldn't have) then what does >> the $3.6M get them? > > Problem is always one machine that keeps important password(s). > That goes like that. User plugs in usb key with game or > access some malware site, etc. When hacker gets passwords for access to > server, all is lost. No matter OS on the server. You'd expect that passwords to the production server and the password to the production database would be better protected. Most likely the person who has these passwords wasn't the one infected. A employee at some workstation shouldn't be able to access any resources like this. >> Did they get in by leaving USB drives in the parking lot? > > Probably. It's worked before. >> There are always going to be places with terrible security practices. >> The hackers just need to find them. > > Imagine computer security in hospital ;) > The problem is that if you're really good at IT then you're not going to work at a hospital. The tech company across the street will hire you for more money. Lots of insurance companies, financials, manufacturing, etc use our product. We deal with different IT departments all the time. Most have decent people working there but others can be bad. These are the database people we deal with but there's bad security people out there too.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-16 20:52 +0100 |
| Message-ID | <20160216205246.01a7a7d2@maxa-pc> |
| In reply to | #343730 |
On Tue, 16 Feb 2016 14:19:17 -0500 "Ezekiel" <zeke@nosuchemail.com> wrote: > "Melzzzzz" <mel@zzzzz.com> wrote in message > news:20160216195425.1b1906d8@maxa-pc... > > On Tue, 16 Feb 2016 13:42:52 -0500 > > "Ezekiel" <zeke@nosuchemail.com> wrote: > > > >> "Melzzzzz" <mel@zzzzz.com> wrote in message > >> news:20160216191422.48cb0e82@maxa-pc... > >> > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm > >> > " > >> > Hackers have taken the computer system of the Hollywood > >> > Presbyterian Medical Center hostage, demanding 9,000 Bitcoin or > >> > $3.6 million. " > >> > >> "The administration has forbidden the use of other computers > >> for fear that the harmful software could spread to more > >> workstations." > >> > >> Most likely Windows if it's workstations. > >> > >> I could see local data being encrypted/taken-hostage but all the > >> important stuff at a hospital should be on some backend DB running > >> on a server. IT should constantly be backing up this data. If the > >> servers weren't compromised (and they shouldn't have) then what > >> does the $3.6M get them? > > > > Problem is always one machine that keeps important password(s). > > That goes like that. User plugs in usb key with game or > > access some malware site, etc. When hacker gets passwords for > > access to server, all is lost. No matter OS on the server. > > You'd expect that passwords to the production server and the password > to the production database would be better protected. Yep. But obviously that was not the case. Most likely the > person who has these passwords wasn't the one infected. A employee at > some workstation shouldn't be able to access any resources like this. I disagree. They overtook whole system, so it seems. That can't be done without having access to critical accounts.
[toc] | [prev] | [next] | [standalone]
| From | "Ezekiel" <zeke@nosuchemail.com> |
|---|---|
| Date | 2016-02-16 15:23 -0500 |
| Message-ID | <na00a3$gc2$1@dont-email.me> |
| In reply to | #343738 |
"Melzzzzz" <mel@zzzzz.com> wrote in message
news:20160216205246.01a7a7d2@maxa-pc...
> On Tue, 16 Feb 2016 14:19:17 -0500
> "Ezekiel" <zeke@nosuchemail.com> wrote:
>
>>
>> You'd expect that passwords to the production server and the password
>> to the production database would be better protected.
>
> Yep. But obviously that was not the case.
Evidently this wasn't the case. I agree. But some guy working in the
blood-lab or front desk isn't supposed to get this type of access. Something
wasn't right.
> Most likely the
>> person who has these passwords wasn't the one infected. A employee at
>> some workstation shouldn't be able to access any resources like this.
>
> I disagree. They overtook whole system, so it seems. That can't be done
> without having access to critical accounts.
>
It sounds like you do agree. They did overtake the whole system.
"some workstation shouldn't be able
to access any resources like this."
When they shouldn't be able but they did have root access then something was
wrong. This is a server/db that has patient medical records, personal
information, billing records, etc. This needs to be locked down so that
malware and rogue employees can't get anywhere near this stuff.
[toc] | [prev] | [next] | [standalone]
| From | Desk Rabbit <me@example.com> |
|---|---|
| Date | 2016-02-17 12:44 +0000 |
| Message-ID | <na1ppa$hu$2@deskrabbit.motzarella.org> |
| In reply to | #343729 |
On 16/02/2016 18:54, Melzzzzz wrote: > On Tue, 16 Feb 2016 13:42:52 -0500 > "Ezekiel" <zeke@nosuchemail.com> wrote: > >> "Melzzzzz" <mel@zzzzz.com> wrote in message >> news:20160216191422.48cb0e82@maxa-pc... >>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >>> " >>> Hackers have taken the computer system of the Hollywood Presbyterian >>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >>> " >> >> "The administration has forbidden the use of other computers >> for fear that the harmful software could spread to more >> workstations." >> >> Most likely Windows if it's workstations. >> >> I could see local data being encrypted/taken-hostage but all the >> important stuff at a hospital should be on some backend DB running on >> a server. IT should constantly be backing up this data. If the >> servers weren't compromised (and they shouldn't have) then what does >> the $3.6M get them? > > Problem is always one machine that keeps important password(s). > That goes like that. User plugs in usb key with game or > access some malware site, etc. When hacker gets passwords for access to > server, all is lost. No matter OS on the server. > > >> >> Did they get in by leaving USB drives in the parking lot? > > Probably. Wouldn't work on any site we manage. USB is locked out except for a few and each stick/drive is scanned before being used. It's a little more difficult at a print shop we support where customers bring in sticks with work on them to be printed but the AV we use scans the stick before allowing access, never had a problem. This ransomware is usually from links in emails. A good AV on the email system and managed DNS like Umbrella stops that in its tracks. And yes in the early days of ransomware we had a couple of customers hit but by using shadow copies (A Windows server technology enabled by default unlike Linux Server) all the files were replaced within an hour and no damage was done, no business lost and no ransom paid.
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-02-16 20:05 +0000 |
| Message-ID | <hgjdi30.jfie03@rooftop.invalid> |
| In reply to | #343721 |
Melzzzzz <mel@zzzzz.com> wrote: > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm > " > Hackers have taken the computer system of the Hollywood Presbyterian > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. > " Content-Length: 311 Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0
[toc] | [prev] | [next] | [standalone]
| From | "Ezekiel" <zeke@nosuchemail.com> |
|---|---|
| Date | 2016-02-16 15:34 -0500 |
| Message-ID | <na00ua$iqi$1@dont-email.me> |
| In reply to | #343743 |
"owl" <owl@rooftop.invalid> wrote in message news:hgjdi30.jfie03@rooftop.invalid... > Melzzzzz <mel@zzzzz.com> wrote: >> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >> " >> Hackers have taken the computer system of the Hollywood Presbyterian >> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >> " > > Content-Length: 311 > Content-Type: text/html; charset=us-ascii > Server: Microsoft-HTTPAPI/2.0 > What's that, their webserver? Netcraft says the server is Mongrel running on Linux hosted by SoftLayer Technologies. If they're stupid enough to host *any* web server on the same machine as their backend patient data then they were asking for trouble. It's like putting a Windows server next to a fuel tank aboard a cruise ship.
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-02-16 21:05 +0000 |
| Message-ID | <thjdw03ra.safe@rooftop.invalid> |
| In reply to | #343747 |
Ezekiel <zeke@nosuchemail.com> wrote: > > "owl" <owl@rooftop.invalid> wrote in message > news:hgjdi30.jfie03@rooftop.invalid... >> Melzzzzz <mel@zzzzz.com> wrote: >>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >>> " >>> Hackers have taken the computer system of the Hollywood Presbyterian >>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >>> " >> >> Content-Length: 311 >> Content-Type: text/html; charset=us-ascii >> Server: Microsoft-HTTPAPI/2.0 >> > > What's that, their webserver? > Yeah. > Netcraft says the server is Mongrel running on Linux hosted by SoftLayer > Technologies. > Where does it say that? If I go to netcraft, it says IIS/8.5 Is this not them? http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com > If they're stupid enough to host *any* web server on the same machine as > their backend patient data then they were asking for trouble. > Not necessarily the same machine, but it reveals a reliance on Microsoft technology. When the web server is IIS, I would guess that the backend is SQL Server. There is a patient portal on the website, so internal data can at least be touched via the web site. > It's like putting a Windows server next to a fuel tank aboard a cruise ship. > LOL!
[toc] | [prev] | [next] | [standalone]
| From | "Ezekiel" <zeke@nosuchemail.com> |
|---|---|
| Date | 2016-02-16 16:42 -0500 |
| Message-ID | <na04uf$31a$1@dont-email.me> |
| In reply to | #343749 |
"owl" <owl@rooftop.invalid> wrote in message
news:thjdw03ra.safe@rooftop.invalid...
> Ezekiel <zeke@nosuchemail.com> wrote:
>>
>> "owl" <owl@rooftop.invalid> wrote in message
>> news:hgjdi30.jfie03@rooftop.invalid...
>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>> "
>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>> "
>>>
>>> Content-Length: 311
>>> Content-Type: text/html; charset=us-ascii
>>> Server: Microsoft-HTTPAPI/2.0
>>>
>>
>> What's that, their webserver?
>>
>
> Yeah.
>
>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>> Technologies.
>>
>
> Where does it say that? If I go to netcraft, it says IIS/8.5
> Is this not them?
> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>
That is what your link says. The one I used is:
http://toolbar.netcraft.com/site_report?url=hollywoodpresbyterian.com
>> If they're stupid enough to host *any* web server on the same machine as
>> their backend patient data then they were asking for trouble.
>>
>
> Not necessarily the same machine, but it reveals a reliance on Microsoft
> technology. When the web server is IIS, I would guess that the backend
> is SQL Server. There is a patient portal on the website, so internal
> data can at least be touched via the web site.
I'm not convinced about the reliance on MS technology. Companies are pretty
hetro these days with what they use. Connecting a web page to a database
isn't any more difficult with Oracle or Teradata.
The web page would never access the db directly anyway. It would go through
a middle-layer that manages all this stuff. The web page isn't running stuff
like "select * from patients where patient_id = ${url.id}
The middle-layer is what connects to the db. They're not a big hospital (430
beds) and they bought all the finance, hospital and patient management
software from some 3rd party.
They can buy and use whatever software they need. But IT and security is
probably being done in-house.
>> It's like putting a Windows server next to a fuel tank aboard a cruise
>> ship.
>>
>
> LOL!
>
I got a kick from the videos of the cruise ship that left NJ and took 4,500
passengers into a huge storm. I'm curious what the thought process is for
someone to think that sending a ship into a huge storm is a good idea. Have
schedules taken over common sense?
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-02-16 22:13 +0000 |
| Message-ID | <ghjcmbnjd83.jai@rooftop.invalid> |
| In reply to | #343753 |
Ezekiel <zeke@nosuchemail.com> wrote:
>
> "owl" <owl@rooftop.invalid> wrote in message
> news:thjdw03ra.safe@rooftop.invalid...
>> Ezekiel <zeke@nosuchemail.com> wrote:
>>>
>>> "owl" <owl@rooftop.invalid> wrote in message
>>> news:hgjdi30.jfie03@rooftop.invalid...
>>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>>> "
>>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>>> "
>>>>
>>>> Content-Length: 311
>>>> Content-Type: text/html; charset=us-ascii
>>>> Server: Microsoft-HTTPAPI/2.0
>>>>
>>>
>>> What's that, their webserver?
>>>
>>
>> Yeah.
>>
>>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>>> Technologies.
>>>
>>
>> Where does it say that? If I go to netcraft, it says IIS/8.5
>> Is this not them?
>> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>>
>
> That is what your link says. The one I used is:
> http://toolbar.netcraft.com/site_report?url=hollywoodpresbyterian.com
>
Whenever I connect to either it comes up 184.175.96.210 which is
the IIS one. The linux one listed is 74.86.205.60.
>
>
>>> If they're stupid enough to host *any* web server on the same machine as
>>> their backend patient data then they were asking for trouble.
>>>
>>
>> Not necessarily the same machine, but it reveals a reliance on Microsoft
>> technology. When the web server is IIS, I would guess that the backend
>> is SQL Server. There is a patient portal on the website, so internal
>> data can at least be touched via the web site.
>
> I'm not convinced about the reliance on MS technology. Companies are pretty
> hetro these days with what they use. Connecting a web page to a database
> isn't any more difficult with Oracle or Teradata.
>
Yeah, but it's probably Windows though.
> The web page would never access the db directly anyway. It would go through
> a middle-layer that manages all this stuff. The web page isn't running stuff
> like "select * from patients where patient_id = ${url.id}
>
> The middle-layer is what connects to the db. They're not a big hospital (430
> beds) and they bought all the finance, hospital and patient management
> software from some 3rd party.
>
> They can buy and use whatever software they need. But IT and security is
> probably being done in-house.
>
>>> It's like putting a Windows server next to a fuel tank aboard a cruise
>>> ship.
>>>
>>
>> LOL!
>>
>
> I got a kick from the videos of the cruise ship that left NJ and took 4,500
> passengers into a huge storm. I'm curious what the thought process is for
> someone to think that sending a ship into a huge storm is a good idea. Have
> schedules taken over common sense?
>
MS Anthem of the Seas.
LOL MS strikes again.
https://en.wikipedia.org/wiki/MS_Anthem_of_the_Seas
http://newjersey.news12.com/news/storm-battered-cruise-ship-sets-sail-1.11468047?pts=629669
<quote>
The ship suffered damage during a major winter storm off the coast of
North Carolina last week and lost half of its propulsion system.
</quote>
"Lost its propulsion system"
That's what happened to that Navy cruiser running on NT back in the day.
"Captain, I divided by zero."
"Shit, call a tug boat."
[toc] | [prev] | [next] | [standalone]
| From | DFS <nospam@dfs.com> |
|---|---|
| Date | 2016-02-16 19:41 -0500 |
| Message-ID | <na0ffb$8ob$5@dont-email.me> |
| In reply to | #343756 |
On 2/16/2016 5:13 PM, owl wrote: > That's what happened to that Navy cruiser running on NT back in the day. > "Captain, I divided by zero." > "Shit, call a tug boat." That's just a lame fantasy concocted by Linux idiots.
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-02-17 00:49 +0000 |
| Message-ID | <fhuf003.aa@rooftop.invalid> |
| In reply to | #343768 |
DFS <nospam@dfs.com> wrote: > On 2/16/2016 5:13 PM, owl wrote: > >> That's what happened to that Navy cruiser running on NT back in the day. >> "Captain, I divided by zero." >> "Shit, call a tug boat." > > > That's just a lame fantasy concocted by Linux idiots. > Funny, I read it an article in Scientific American.
[toc] | [prev] | [next] | [standalone]
| From | DFS <nospam@dfs.com> |
|---|---|
| Date | 2016-02-16 20:05 -0500 |
| Message-ID | <na0gr5$ca3$2@dont-email.me> |
| In reply to | #343770 |
On 2/16/2016 7:49 PM, owl wrote: > DFS <nospam@dfs.com> wrote: >> On 2/16/2016 5:13 PM, owl wrote: >> >>> That's what happened to that Navy cruiser running on NT back in the day. >>> "Captain, I divided by zero." >>> "Shit, call a tug boat." >> >> >> That's just a lame fantasy concocted by Linux idiots. >> > > Funny, I read it an article in Scientific American. I didn't know SA published bald-faced lies by Linux idiots. Their standards are slipping.
[toc] | [prev] | [next] | [standalone]
| From | Desk Rabbit <me@example.com> |
|---|---|
| Date | 2016-02-17 14:16 +0000 |
| Message-ID | <na1v5v$mdo$1@deskrabbit.motzarella.org> |
| In reply to | #343749 |
On 16/02/2016 21:05, owl wrote: > Ezekiel <zeke@nosuchemail.com> wrote: >> >> "owl" <owl@rooftop.invalid> wrote in message >> news:hgjdi30.jfie03@rooftop.invalid... >>> Melzzzzz <mel@zzzzz.com> wrote: >>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >>>> " >>>> Hackers have taken the computer system of the Hollywood Presbyterian >>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >>>> " >>> >>> Content-Length: 311 >>> Content-Type: text/html; charset=us-ascii >>> Server: Microsoft-HTTPAPI/2.0 >>> >> >> What's that, their webserver? >> > > Yeah. > >> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer >> Technologies. >> > > Where does it say that? If I go to netcraft, it says IIS/8.5 > Is this not them? > http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com > >> If they're stupid enough to host *any* web server on the same machine as >> their backend patient data then they were asking for trouble. >> > > Not necessarily the same machine, but it reveals a reliance on Microsoft > technology. When the web server is IIS, I would guess that the backend > is SQL Server. There is a patient portal on the website, so internal > data can at least be touched via the web site. > > >> It's like putting a Windows server next to a fuel tank aboard a cruise ship. >> > > LOL! > > > That web server is on 184.175.96.210, try running nmap against that for a shocker! In short it's a case of Firewall? What's a Firewall?? A telnet to port 25 184.175.96.210 reveals Connected to 184.175.96.210. Escape character is '^]'. 220 vps.citilinks.com Hmm, looks like a Virtual Private Server probably hosted in a data centre (The Netblock assignment also suggests this). The domain of course takes you to this bunch of muppets http://citilinks.com/ who appear to be responsible for it. And this just makes me want to weep: ftp 184.175.96.210 Connected to 184.175.96.210 (184.175.96.210). 220 Microsoft FTP Service Name (184.175.96.210:root):
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-02-17 18:59 +0000 |
| Message-ID | <ghjdus93a.ar3@rooftop.invalid> |
| In reply to | #343812 |
Desk Rabbit <me@example.com> wrote: > On 16/02/2016 21:05, owl wrote: >> Ezekiel <zeke@nosuchemail.com> wrote: >>> >>> "owl" <owl@rooftop.invalid> wrote in message >>> news:hgjdi30.jfie03@rooftop.invalid... >>>> Melzzzzz <mel@zzzzz.com> wrote: >>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm >>>>> " >>>>> Hackers have taken the computer system of the Hollywood Presbyterian >>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. >>>>> " >>>> >>>> Content-Length: 311 >>>> Content-Type: text/html; charset=us-ascii >>>> Server: Microsoft-HTTPAPI/2.0 >>>> >>> >>> What's that, their webserver? >>> >> >> Yeah. >> >>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer >>> Technologies. >>> >> >> Where does it say that? If I go to netcraft, it says IIS/8.5 >> Is this not them? >> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com >> >>> If they're stupid enough to host *any* web server on the same machine as >>> their backend patient data then they were asking for trouble. >>> >> >> Not necessarily the same machine, but it reveals a reliance on Microsoft >> technology. When the web server is IIS, I would guess that the backend >> is SQL Server. There is a patient portal on the website, so internal >> data can at least be touched via the web site. >> >> >>> It's like putting a Windows server next to a fuel tank aboard a cruise ship. >>> >> >> LOL! >> >> >> > > That web server is on 184.175.96.210, try running nmap against that for > a shocker! In short it's a case of Firewall? What's a Firewall?? > > A telnet to port 25 184.175.96.210 reveals > Connected to 184.175.96.210. > Escape character is '^]'. > 220 vps.citilinks.com > > Hmm, looks like a Virtual Private Server probably hosted in a data > centre (The Netblock assignment also suggests this). The domain of > course takes you to this bunch of muppets http://citilinks.com/ who > appear to be responsible for it. > > And this just makes me want to weep: > ftp 184.175.96.210 > Connected to 184.175.96.210 (184.175.96.210). > 220 Microsoft FTP Service > Name (184.175.96.210:root): > lol I'll let you probe the system that's under investigation. :) What else is open?
[toc] | [prev] | [next] | [standalone]
| From | John Gohde <john.h.gohde@gmail.com> |
|---|---|
| Date | 2016-02-17 05:11 -0800 |
| Message-ID | <ee43facc-2eea-4b3d-826f-880a4a9c41dc@googlegroups.com> |
| In reply to | #343721 |
On Tuesday, February 16, 2016 at 1:14:24 PM UTC-5, Melzzzzz wrote: > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm > " > Hackers have taken the computer system of the Hollywood Presbyterian > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million. > " Sounds like it is a good opportunity for the Brain Farts on COLA to prove their worth and earn a big paycheck.
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.advocacy
csiph-web