Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.advocacy > #343721 > unrolled thread

Windows?

Started byMelzzzzz <mel@zzzzz.com>
First post2016-02-16 19:14 +0100
Last post2016-02-17 05:11 -0800
Articles 18 — 6 participants

Back to article view | Back to comp.os.linux.advocacy


Contents

  Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:14 +0100
    Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 13:42 -0500
      Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:54 +0100
        Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 14:19 -0500
          Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 20:52 +0100
            Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:23 -0500
        Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 12:44 +0000
    Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 20:05 +0000
      Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:34 -0500
        Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 21:05 +0000
          Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 16:42 -0500
            Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 22:13 +0000
              Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 19:41 -0500
                Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 00:49 +0000
                  Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 20:05 -0500
          Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 14:16 +0000
            Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 18:59 +0000
    Re: Windows? John Gohde <john.h.gohde@gmail.com> - 2016-02-17 05:11 -0800

#343721 — Windows?

FromMelzzzzz <mel@zzzzz.com>
Date2016-02-16 19:14 +0100
SubjectWindows?
Message-ID<20160216191422.48cb0e82@maxa-pc>
http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
"
Hackers have taken the computer system of the Hollywood Presbyterian
Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
"

[toc] | [next] | [standalone]


#343724

From"Ezekiel" <zeke@nosuchemail.com>
Date2016-02-16 13:42 -0500
Message-ID<n9vqdf$n7d$1@dont-email.me>
In reply to#343721
"Melzzzzz" <mel@zzzzz.com> wrote in message 
news:20160216191422.48cb0e82@maxa-pc...
> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> "
> Hackers have taken the computer system of the Hollywood Presbyterian
> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
> "

    "The administration has forbidden the use of other computers
    for fear that the harmful software could spread to more workstations."

Most likely Windows if it's workstations.

I could see local data being encrypted/taken-hostage but all the important 
stuff at a hospital should be on some backend DB running on a server. IT 
should constantly be backing up this data. If the servers weren't 
compromised (and they shouldn't have) then what does the $3.6M get them?

Did they get in by leaving USB drives in the parking lot?

There are always going to be places with terrible security practices. The 
hackers just need to find them.


[toc] | [prev] | [next] | [standalone]


#343729

FromMelzzzzz <mel@zzzzz.com>
Date2016-02-16 19:54 +0100
Message-ID<20160216195425.1b1906d8@maxa-pc>
In reply to#343724
On Tue, 16 Feb 2016 13:42:52 -0500
"Ezekiel" <zeke@nosuchemail.com> wrote:

> "Melzzzzz" <mel@zzzzz.com> wrote in message 
> news:20160216191422.48cb0e82@maxa-pc...
> > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> > "
> > Hackers have taken the computer system of the Hollywood Presbyterian
> > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
> > "  
> 
>     "The administration has forbidden the use of other computers
>     for fear that the harmful software could spread to more
> workstations."
> 
> Most likely Windows if it's workstations.
> 
> I could see local data being encrypted/taken-hostage but all the
> important stuff at a hospital should be on some backend DB running on
> a server. IT should constantly be backing up this data. If the
> servers weren't compromised (and they shouldn't have) then what does
> the $3.6M get them?

Problem is always one machine that keeps important password(s).
That goes like that. User plugs in usb key with game or
access some malware site, etc. When hacker gets passwords for access to
server, all is lost. No matter OS on the server.


> 
> Did they get in by leaving USB drives in the parking lot?

Probably.

> 
> There are always going to be places with terrible security practices.
> The hackers just need to find them.

Imagine computer security in hospital ;)

> 
> 
> 

[toc] | [prev] | [next] | [standalone]


#343730

From"Ezekiel" <zeke@nosuchemail.com>
Date2016-02-16 14:19 -0500
Message-ID<n9vshp$dd$1@dont-email.me>
In reply to#343729
"Melzzzzz" <mel@zzzzz.com> wrote in message 
news:20160216195425.1b1906d8@maxa-pc...
> On Tue, 16 Feb 2016 13:42:52 -0500
> "Ezekiel" <zeke@nosuchemail.com> wrote:
>
>> "Melzzzzz" <mel@zzzzz.com> wrote in message
>> news:20160216191422.48cb0e82@maxa-pc...
>> > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>> > "
>> > Hackers have taken the computer system of the Hollywood Presbyterian
>> > Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>> > "
>>
>>     "The administration has forbidden the use of other computers
>>     for fear that the harmful software could spread to more
>> workstations."
>>
>> Most likely Windows if it's workstations.
>>
>> I could see local data being encrypted/taken-hostage but all the
>> important stuff at a hospital should be on some backend DB running on
>> a server. IT should constantly be backing up this data. If the
>> servers weren't compromised (and they shouldn't have) then what does
>> the $3.6M get them?
>
> Problem is always one machine that keeps important password(s).
> That goes like that. User plugs in usb key with game or
> access some malware site, etc. When hacker gets passwords for access to
> server, all is lost. No matter OS on the server.

You'd expect that passwords to the production server and the password to the 
production database would be better protected. Most likely the person who 
has these passwords wasn't the one infected. A employee at some workstation 
shouldn't be able to access any resources like this.


>> Did they get in by leaving USB drives in the parking lot?
>
> Probably.

It's worked before.


>> There are always going to be places with terrible security practices.
>> The hackers just need to find them.
>
> Imagine computer security in hospital ;)
>

The problem is that if you're really good at IT then you're not going to 
work at a hospital. The tech company across the street will hire you for 
more money.

Lots of insurance companies, financials, manufacturing, etc use our product. 
We deal with different IT departments all the time. Most have decent people 
working there but others can be bad. These are the database people we deal 
with but there's bad security people out there too.







[toc] | [prev] | [next] | [standalone]


#343738

FromMelzzzzz <mel@zzzzz.com>
Date2016-02-16 20:52 +0100
Message-ID<20160216205246.01a7a7d2@maxa-pc>
In reply to#343730
On Tue, 16 Feb 2016 14:19:17 -0500
"Ezekiel" <zeke@nosuchemail.com> wrote:

> "Melzzzzz" <mel@zzzzz.com> wrote in message 
> news:20160216195425.1b1906d8@maxa-pc...
> > On Tue, 16 Feb 2016 13:42:52 -0500
> > "Ezekiel" <zeke@nosuchemail.com> wrote:
> >  
> >> "Melzzzzz" <mel@zzzzz.com> wrote in message
> >> news:20160216191422.48cb0e82@maxa-pc...  
> >> > http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> >> > "
> >> > Hackers have taken the computer system of the Hollywood
> >> > Presbyterian Medical Center hostage, demanding 9,000 Bitcoin or
> >> > $3.6 million. "  
> >>
> >>     "The administration has forbidden the use of other computers
> >>     for fear that the harmful software could spread to more
> >> workstations."
> >>
> >> Most likely Windows if it's workstations.
> >>
> >> I could see local data being encrypted/taken-hostage but all the
> >> important stuff at a hospital should be on some backend DB running
> >> on a server. IT should constantly be backing up this data. If the
> >> servers weren't compromised (and they shouldn't have) then what
> >> does the $3.6M get them?  
> >
> > Problem is always one machine that keeps important password(s).
> > That goes like that. User plugs in usb key with game or
> > access some malware site, etc. When hacker gets passwords for
> > access to server, all is lost. No matter OS on the server.  
> 
> You'd expect that passwords to the production server and the password
> to the production database would be better protected.

Yep. But obviously that was not the case.

 Most likely the
> person who has these passwords wasn't the one infected. A employee at
> some workstation shouldn't be able to access any resources like this.

I disagree. They overtook whole system, so it seems. That can't be done
without having access to critical accounts.

[toc] | [prev] | [next] | [standalone]


#343745

From"Ezekiel" <zeke@nosuchemail.com>
Date2016-02-16 15:23 -0500
Message-ID<na00a3$gc2$1@dont-email.me>
In reply to#343738
"Melzzzzz" <mel@zzzzz.com> wrote in message 
news:20160216205246.01a7a7d2@maxa-pc...
> On Tue, 16 Feb 2016 14:19:17 -0500
> "Ezekiel" <zeke@nosuchemail.com> wrote:
>
>>
>> You'd expect that passwords to the production server and the password
>> to the production database would be better protected.
>
> Yep. But obviously that was not the case.

Evidently this wasn't the case. I agree. But some guy working in the 
blood-lab or front desk isn't supposed to get this type of access. Something 
wasn't right.


> Most likely the
>> person who has these passwords wasn't the one infected. A employee at
>> some workstation shouldn't be able to access any resources like this.
>
> I disagree. They overtook whole system, so it seems. That can't be done
> without having access to critical accounts.
>

It sounds like you do agree. They did overtake the whole system.

    "some workstation shouldn't be able
    to access any resources like this."

When they shouldn't be able but they did have root access then something was 
wrong. This is a server/db that has patient medical records, personal 
information, billing records, etc. This needs to be locked down so that 
malware and rogue employees can't get anywhere near this stuff.



[toc] | [prev] | [next] | [standalone]


#343804

FromDesk Rabbit <me@example.com>
Date2016-02-17 12:44 +0000
Message-ID<na1ppa$hu$2@deskrabbit.motzarella.org>
In reply to#343729
On 16/02/2016 18:54, Melzzzzz wrote:
> On Tue, 16 Feb 2016 13:42:52 -0500
> "Ezekiel" <zeke@nosuchemail.com> wrote:
>
>> "Melzzzzz" <mel@zzzzz.com> wrote in message
>> news:20160216191422.48cb0e82@maxa-pc...
>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>> "
>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>> "
>>
>>      "The administration has forbidden the use of other computers
>>      for fear that the harmful software could spread to more
>> workstations."
>>
>> Most likely Windows if it's workstations.
>>
>> I could see local data being encrypted/taken-hostage but all the
>> important stuff at a hospital should be on some backend DB running on
>> a server. IT should constantly be backing up this data. If the
>> servers weren't compromised (and they shouldn't have) then what does
>> the $3.6M get them?
>
> Problem is always one machine that keeps important password(s).
> That goes like that. User plugs in usb key with game or
> access some malware site, etc. When hacker gets passwords for access to
> server, all is lost. No matter OS on the server.
>
>
>>
>> Did they get in by leaving USB drives in the parking lot?
>
> Probably.

Wouldn't work on any site we manage. USB is locked out except for a few 
and each stick/drive is scanned before being used.

It's a little more difficult at a print shop we support where customers 
bring in sticks with work on them to be printed but the AV we use scans 
the stick before allowing access, never had a problem.

This ransomware is usually from links in emails. A good AV on the email 
system and managed DNS like Umbrella stops that in its tracks.

And yes in the early days of ransomware we had a couple of customers hit 
but by using shadow copies (A Windows server technology enabled by 
default unlike Linux Server) all the files were replaced within an hour 
and no damage was done, no business lost and no ransom paid.

[toc] | [prev] | [next] | [standalone]


#343743

Fromowl <owl@rooftop.invalid>
Date2016-02-16 20:05 +0000
Message-ID<hgjdi30.jfie03@rooftop.invalid>
In reply to#343721
Melzzzzz <mel@zzzzz.com> wrote:
> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> "
> Hackers have taken the computer system of the Hollywood Presbyterian
> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
> "

Content-Length: 311
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0

[toc] | [prev] | [next] | [standalone]


#343747

From"Ezekiel" <zeke@nosuchemail.com>
Date2016-02-16 15:34 -0500
Message-ID<na00ua$iqi$1@dont-email.me>
In reply to#343743
"owl" <owl@rooftop.invalid> wrote in message 
news:hgjdi30.jfie03@rooftop.invalid...
> Melzzzzz <mel@zzzzz.com> wrote:
>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>> "
>> Hackers have taken the computer system of the Hollywood Presbyterian
>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>> "
>
> Content-Length: 311
> Content-Type: text/html; charset=us-ascii
> Server: Microsoft-HTTPAPI/2.0
>

What's that, their webserver?

Netcraft says the server is Mongrel running on Linux hosted by SoftLayer 
Technologies.

If they're stupid enough to host *any* web server on the same machine as 
their backend patient data then they were asking for trouble.

It's like putting a Windows server next to a fuel tank aboard a cruise ship.



[toc] | [prev] | [next] | [standalone]


#343749

Fromowl <owl@rooftop.invalid>
Date2016-02-16 21:05 +0000
Message-ID<thjdw03ra.safe@rooftop.invalid>
In reply to#343747
Ezekiel <zeke@nosuchemail.com> wrote:
> 
> "owl" <owl@rooftop.invalid> wrote in message 
> news:hgjdi30.jfie03@rooftop.invalid...
>> Melzzzzz <mel@zzzzz.com> wrote:
>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>> "
>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>> "
>>
>> Content-Length: 311
>> Content-Type: text/html; charset=us-ascii
>> Server: Microsoft-HTTPAPI/2.0
>>
> 
> What's that, their webserver?
> 

Yeah.

> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer 
> Technologies.
> 

Where does it say that?  If I go to netcraft, it says IIS/8.5
Is this not them?
http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com

> If they're stupid enough to host *any* web server on the same machine as 
> their backend patient data then they were asking for trouble.
> 

Not necessarily the same machine, but it reveals a reliance on Microsoft
technology.  When the web server is IIS, I would guess that the backend
is SQL Server.  There is a patient portal on the website, so internal
data can at least be touched via the web site.


> It's like putting a Windows server next to a fuel tank aboard a cruise ship.
> 
 
LOL!
 
 

[toc] | [prev] | [next] | [standalone]


#343753

From"Ezekiel" <zeke@nosuchemail.com>
Date2016-02-16 16:42 -0500
Message-ID<na04uf$31a$1@dont-email.me>
In reply to#343749
"owl" <owl@rooftop.invalid> wrote in message 
news:thjdw03ra.safe@rooftop.invalid...
> Ezekiel <zeke@nosuchemail.com> wrote:
>>
>> "owl" <owl@rooftop.invalid> wrote in message
>> news:hgjdi30.jfie03@rooftop.invalid...
>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>> "
>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>> "
>>>
>>> Content-Length: 311
>>> Content-Type: text/html; charset=us-ascii
>>> Server: Microsoft-HTTPAPI/2.0
>>>
>>
>> What's that, their webserver?
>>
>
> Yeah.
>
>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>> Technologies.
>>
>
> Where does it say that?  If I go to netcraft, it says IIS/8.5
> Is this not them?
> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>

That is what your link says. The one I used is:
   http://toolbar.netcraft.com/site_report?url=hollywoodpresbyterian.com



>> If they're stupid enough to host *any* web server on the same machine as
>> their backend patient data then they were asking for trouble.
>>
>
> Not necessarily the same machine, but it reveals a reliance on Microsoft
> technology.  When the web server is IIS, I would guess that the backend
> is SQL Server.  There is a patient portal on the website, so internal
> data can at least be touched via the web site.

I'm not convinced about the reliance on MS technology. Companies are pretty 
hetro these days with what they use. Connecting a web page to a database 
isn't any more difficult with Oracle or Teradata.

The web page would never access the db directly anyway. It would go through 
a middle-layer that manages all this stuff. The web page isn't running stuff 
like "select * from patients where patient_id = ${url.id}

The middle-layer is what connects to the db. They're not a big hospital (430 
beds) and they bought all the finance, hospital and patient management 
software from some 3rd party.

They can buy and use whatever software they need. But IT and security is 
probably being done in-house.

>> It's like putting a Windows server next to a fuel tank aboard a cruise 
>> ship.
>>
>
> LOL!
>

I got a kick from the videos of the cruise ship that left NJ and took 4,500 
passengers into a huge storm. I'm curious what the thought process is for 
someone to think that sending a ship into a huge storm is a good idea. Have 
schedules taken over common sense?


[toc] | [prev] | [next] | [standalone]


#343756

Fromowl <owl@rooftop.invalid>
Date2016-02-16 22:13 +0000
Message-ID<ghjcmbnjd83.jai@rooftop.invalid>
In reply to#343753
Ezekiel <zeke@nosuchemail.com> wrote:
> 
> "owl" <owl@rooftop.invalid> wrote in message 
> news:thjdw03ra.safe@rooftop.invalid...
>> Ezekiel <zeke@nosuchemail.com> wrote:
>>>
>>> "owl" <owl@rooftop.invalid> wrote in message
>>> news:hgjdi30.jfie03@rooftop.invalid...
>>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>>> "
>>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>>> "
>>>>
>>>> Content-Length: 311
>>>> Content-Type: text/html; charset=us-ascii
>>>> Server: Microsoft-HTTPAPI/2.0
>>>>
>>>
>>> What's that, their webserver?
>>>
>>
>> Yeah.
>>
>>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>>> Technologies.
>>>
>>
>> Where does it say that?  If I go to netcraft, it says IIS/8.5
>> Is this not them?
>> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>>
> 
> That is what your link says. The one I used is:
>    http://toolbar.netcraft.com/site_report?url=hollywoodpresbyterian.com
> 

Whenever I connect to either it comes up 184.175.96.210 which is
the IIS one.  The linux one listed is 74.86.205.60.

> 
> 
>>> If they're stupid enough to host *any* web server on the same machine as
>>> their backend patient data then they were asking for trouble.
>>>
>>
>> Not necessarily the same machine, but it reveals a reliance on Microsoft
>> technology.  When the web server is IIS, I would guess that the backend
>> is SQL Server.  There is a patient portal on the website, so internal
>> data can at least be touched via the web site.
> 
> I'm not convinced about the reliance on MS technology. Companies are pretty 
> hetro these days with what they use. Connecting a web page to a database 
> isn't any more difficult with Oracle or Teradata.
> 

Yeah, but it's probably Windows though.

> The web page would never access the db directly anyway. It would go through 
> a middle-layer that manages all this stuff. The web page isn't running stuff 
> like "select * from patients where patient_id = ${url.id}
> 
> The middle-layer is what connects to the db. They're not a big hospital (430 
> beds) and they bought all the finance, hospital and patient management 
> software from some 3rd party.
> 
> They can buy and use whatever software they need. But IT and security is 
> probably being done in-house.
> 
>>> It's like putting a Windows server next to a fuel tank aboard a cruise 
>>> ship.
>>>
>>
>> LOL!
>>
> 
> I got a kick from the videos of the cruise ship that left NJ and took 4,500 
> passengers into a huge storm. I'm curious what the thought process is for 
> someone to think that sending a ship into a huge storm is a good idea. Have 
> schedules taken over common sense?
> 

MS Anthem of the Seas.
LOL  MS strikes again.
 
https://en.wikipedia.org/wiki/MS_Anthem_of_the_Seas

http://newjersey.news12.com/news/storm-battered-cruise-ship-sets-sail-1.11468047?pts=629669
<quote>
The ship suffered damage during a major winter storm off the coast of
North Carolina last week and lost half of its propulsion system.
</quote>

"Lost its propulsion system"

That's what happened to that Navy cruiser running on NT back in the day.
"Captain, I divided by zero."
"Shit, call a tug boat."

[toc] | [prev] | [next] | [standalone]


#343768

FromDFS <nospam@dfs.com>
Date2016-02-16 19:41 -0500
Message-ID<na0ffb$8ob$5@dont-email.me>
In reply to#343756
On 2/16/2016 5:13 PM, owl wrote:

> That's what happened to that Navy cruiser running on NT back in the day.
> "Captain, I divided by zero."
> "Shit, call a tug boat."


That's just a lame fantasy concocted by Linux idiots.

[toc] | [prev] | [next] | [standalone]


#343770

Fromowl <owl@rooftop.invalid>
Date2016-02-17 00:49 +0000
Message-ID<fhuf003.aa@rooftop.invalid>
In reply to#343768
DFS <nospam@dfs.com> wrote:
> On 2/16/2016 5:13 PM, owl wrote:
> 
>> That's what happened to that Navy cruiser running on NT back in the day.
>> "Captain, I divided by zero."
>> "Shit, call a tug boat."
> 
> 
> That's just a lame fantasy concocted by Linux idiots.
> 

Funny, I read it an article in Scientific American.
 

[toc] | [prev] | [next] | [standalone]


#343774

FromDFS <nospam@dfs.com>
Date2016-02-16 20:05 -0500
Message-ID<na0gr5$ca3$2@dont-email.me>
In reply to#343770
On 2/16/2016 7:49 PM, owl wrote:
> DFS <nospam@dfs.com> wrote:
>> On 2/16/2016 5:13 PM, owl wrote:
>>
>>> That's what happened to that Navy cruiser running on NT back in the day.
>>> "Captain, I divided by zero."
>>> "Shit, call a tug boat."
>>
>>
>> That's just a lame fantasy concocted by Linux idiots.
>>
>
> Funny, I read it an article in Scientific American.


I didn't know SA published bald-faced lies by Linux idiots.

Their standards are slipping.

[toc] | [prev] | [next] | [standalone]


#343812

FromDesk Rabbit <me@example.com>
Date2016-02-17 14:16 +0000
Message-ID<na1v5v$mdo$1@deskrabbit.motzarella.org>
In reply to#343749
On 16/02/2016 21:05, owl wrote:
> Ezekiel <zeke@nosuchemail.com> wrote:
>>
>> "owl" <owl@rooftop.invalid> wrote in message
>> news:hgjdi30.jfie03@rooftop.invalid...
>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>> "
>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>> "
>>>
>>> Content-Length: 311
>>> Content-Type: text/html; charset=us-ascii
>>> Server: Microsoft-HTTPAPI/2.0
>>>
>>
>> What's that, their webserver?
>>
>
> Yeah.
>
>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>> Technologies.
>>
>
> Where does it say that?  If I go to netcraft, it says IIS/8.5
> Is this not them?
> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>
>> If they're stupid enough to host *any* web server on the same machine as
>> their backend patient data then they were asking for trouble.
>>
>
> Not necessarily the same machine, but it reveals a reliance on Microsoft
> technology.  When the web server is IIS, I would guess that the backend
> is SQL Server.  There is a patient portal on the website, so internal
> data can at least be touched via the web site.
>
>
>> It's like putting a Windows server next to a fuel tank aboard a cruise ship.
>>
>
> LOL!
>
>
>

That web server is on 184.175.96.210, try running nmap against that for 
a shocker! In short it's a case of Firewall? What's a Firewall??

A telnet to port 25 184.175.96.210 reveals
Connected to 184.175.96.210.
Escape character is '^]'.
220 vps.citilinks.com

Hmm, looks like a Virtual Private Server probably hosted in a data 
centre (The Netblock assignment also suggests this). The domain of 
course takes you to this bunch of muppets http://citilinks.com/ who 
appear to be responsible for it.

And this just makes me want to weep:
  ftp 184.175.96.210
Connected to 184.175.96.210 (184.175.96.210).
220 Microsoft FTP Service
Name (184.175.96.210:root):


[toc] | [prev] | [next] | [standalone]


#343822

Fromowl <owl@rooftop.invalid>
Date2016-02-17 18:59 +0000
Message-ID<ghjdus93a.ar3@rooftop.invalid>
In reply to#343812
Desk Rabbit <me@example.com> wrote:
> On 16/02/2016 21:05, owl wrote:
>> Ezekiel <zeke@nosuchemail.com> wrote:
>>>
>>> "owl" <owl@rooftop.invalid> wrote in message
>>> news:hgjdi30.jfie03@rooftop.invalid...
>>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>>>> "
>>>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>>>> "
>>>>
>>>> Content-Length: 311
>>>> Content-Type: text/html; charset=us-ascii
>>>> Server: Microsoft-HTTPAPI/2.0
>>>>
>>>
>>> What's that, their webserver?
>>>
>>
>> Yeah.
>>
>>> Netcraft says the server is Mongrel running on Linux hosted by SoftLayer
>>> Technologies.
>>>
>>
>> Where does it say that?  If I go to netcraft, it says IIS/8.5
>> Is this not them?
>> http://toolbar.netcraft.com/site_report?url=http://www.hollywoodpresbyterian.com
>>
>>> If they're stupid enough to host *any* web server on the same machine as
>>> their backend patient data then they were asking for trouble.
>>>
>>
>> Not necessarily the same machine, but it reveals a reliance on Microsoft
>> technology.  When the web server is IIS, I would guess that the backend
>> is SQL Server.  There is a patient portal on the website, so internal
>> data can at least be touched via the web site.
>>
>>
>>> It's like putting a Windows server next to a fuel tank aboard a cruise ship.
>>>
>>
>> LOL!
>>
>>
>>
> 
> That web server is on 184.175.96.210, try running nmap against that for 
> a shocker! In short it's a case of Firewall? What's a Firewall??
> 
> A telnet to port 25 184.175.96.210 reveals
> Connected to 184.175.96.210.
> Escape character is '^]'.
> 220 vps.citilinks.com
> 
> Hmm, looks like a Virtual Private Server probably hosted in a data 
> centre (The Netblock assignment also suggests this). The domain of 
> course takes you to this bunch of muppets http://citilinks.com/ who 
> appear to be responsible for it.
> 
> And this just makes me want to weep:
>  ftp 184.175.96.210
> Connected to 184.175.96.210 (184.175.96.210).
> 220 Microsoft FTP Service
> Name (184.175.96.210:root):
> 

lol I'll let you probe the system that's under investigation. :)
What else is open?

[toc] | [prev] | [next] | [standalone]


#343809

FromJohn Gohde <john.h.gohde@gmail.com>
Date2016-02-17 05:11 -0800
Message-ID<ee43facc-2eea-4b3d-826f-880a4a9c41dc@googlegroups.com>
In reply to#343721
On Tuesday, February 16, 2016 at 1:14:24 PM UTC-5, Melzzzzz wrote:
> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
> "
> Hackers have taken the computer system of the Hollywood Presbyterian
> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
> "


Sounds like it is a good opportunity for the Brain Farts on COLA to prove their worth and earn a big paycheck.
 

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.advocacy


csiph-web