[HN Gopher] Disposable Root Servers
       ___________________________________________________________________
        
       Disposable Root Servers
        
       Author : kxrm
       Score  : 312 points
       Date   : 2022-10-14 22:38 UTC (1 days ago)
        
 (HTM) web link (blog.thc.org)
 (TXT) w3m dump (blog.thc.org)
        
       | levkk wrote:
       | +--(rootsf-BrushFocus)-[~]       +-# finger       No one logged
       | on.
       | 
       | Where is everyone?
        
         | [deleted]
        
       | NoBreakfirst wrote:
       | I'm not sure to follow.
       | 
       | I don't see any TOS, at all.
       | 
       | Anybody can seed whatever and run Tor exit node ? ( not that it
       | would work well but still )
        
         | mccorrinall wrote:
         | When there are no tos defined, the tos is usually an implicit:
         | don't abuse and don't be an asshole
        
           | water-your-self wrote:
           | Certainly this won't be abused
        
         | [deleted]
        
         | tony-allan wrote:
         | "The Server only exists while you are logged in."
        
           | tony-allan wrote:
           | That's what their website says, however I had a play and
           | created a file and logged in and out and the file persisted
           | as did my ability to look at the /onion directory via Tor
           | after the ssh session was stopped.
        
             | geoffmcc wrote:
             | I read somewhere on their site or in GitHub that files in
             | the home directory are encrypted when you disconnect and
             | when you connect again the encrypted file is restored and
             | so you have files back. If you were to install a program
             | with apt however when you log in again that will be gone.
        
             | kxrm wrote:
             | It does shutdown when you log out, the only persisted data
             | in on /sec and /everyone
             | 
             | Your home directory is in /sec/root.
             | 
             | If you install tools outside of /sec/usr they will be reset
             | on your next visit. So if you want to install something
             | that survives a session log out you need to install to
             | /sec/usr
        
           | [deleted]
        
       | tony-allan wrote:
       | For me, this is a great testing and experimenting server with a
       | fresh environment every time I use it.
       | 
       | I often want test or observe something i'm doing from outside my
       | environment...                 lynx https://news.ycombinator.com
       | curl https://jsonplaceholder.typicode.com/todos/1
        
       | xyzzy123 wrote:
       | Smart way to get plausible deniability for your own grey zone
       | activities.
       | 
       | As a third party, of course absolutely experiment but don't rely
       | on there being no logs, lol.
        
         | bigiain wrote:
         | The weaselworded non answer to "is it safe" is obviously
         | technically true. Even if they've disclosed all activity and
         | logs and user ip addresses to law enforcement, which resulted
         | in hundreds of people going to jail, they went to jail for what
         | they did with this, not for "using it"...
         | 
         | It's a fun curiosity. But anyone relying on it to cover up
         | illegal activity should be very very careful. If what you're
         | doing can improve a cop's chance of promotion, you should
         | assume they'll take advantage of that. And for "lesser crimes",
         | you can bet that most things you want to do from there are
         | already on blocklists. You'll have as much chance of getting
         | your spam runs out of there as you do from any cheap vps or tor
         | exit...
        
       | tgsovlerkhgsel wrote:
       | > Your server will self-destruct on log out (and all data &
       | traces will get wiped).
       | 
       | This does not seem to be entirely accurate (and it would also be
       | very obnoxious, especially for use over Tor, if a dropped
       | connection meant starting from scratch). The servers do allow
       | reconnects, and data is preserved (presumably in encrypted form).
        
         | bdcravens wrote:
         | connection != session
        
           | ghostly_s wrote:
           | It does with ssh... maintaining a persistent session thru
           | reconnect requires a wrapper utility like mosh.
        
             | egberts1 wrote:
             | Or tmux.
        
               | sureglymop wrote:
               | Pretty sure that mosh uses ssh initially and then the
               | communication is over udp. Not sure if an ssh connection
               | is even maintained then. Tmux I guess you would run
               | locally and put in the background when you want to work
               | on something else. But then your ssh connection could
               | still drop or tmux could crash on your local machine.
        
         | tony-allan wrote:
         | I had a play and created a file and logged in and out and the
         | file persisted as did my ability to look at the /onion
         | directory via Tor after the ssh session was stopped.
        
           | tony-allan wrote:
           | The next morning, after being logged out overnight, I ssh'ed
           | into the server and it had been reset (and my saved files
           | removed).
           | 
           | Credentials still worked but a fresh instance.
        
       | ComputerGuru wrote:
       | This is already being severely abused; system load jumped to 9.xx
       | an hour ago and has stayed there.
        
         | ghostly_s wrote:
         | I don't see how it possibly could not be, seeing as they don't
         | seem to have even made any effort to curtail it.
        
       | floatinglotus wrote:
       | I have a hard time understanding the target market for this.
       | 
       | If you are so paranoid about your security and anonymity, why
       | would you take promises made by a third party at face value?
       | 
       | Why would you trust anyone or anything with an ounce of your
       | identity?
        
         | tgsovlerkhgsel wrote:
         | Most places require payment, which is hard to do anonymously.
         | 
         | Here, you don't have to take many promises at face value. You
         | do have to assume that everything you do on that server is
         | monitored if you don't trust it, but you can connect to it via
         | Tor and/or a VPN.
        
         | seba_dos1 wrote:
         | This is a cute toy for hackers, not something that provides
         | "security and anonymity".
        
           | kxrm wrote:
           | Agreed, I am not sure I understand the "how can you expect
           | this to be secure" argument. I paid nothing, and it's
           | sometimes fun to have a thing to play with that someone
           | created. I am not using this to proxy a hack into Bank of
           | America, nor am I storing my 20 page manifesto.
           | 
           | If you do such a thing through here, you deserve whatever
           | happens to you.
        
         | [deleted]
        
         | p4bl0 wrote:
         | I can totally see the market for this. Imagine being a young
         | person (let's say between 10 and 17), you read 2600 or
         | something like it, you cannot pay for a server, you do not have
         | your own Linux because the only family computer is running
         | Windows and you're not an administrator on it. This is free and
         | full of wonderful tools to try and explore.
        
           | MontyCarloHall wrote:
           | Seems like this situation would have been common 25 years
           | ago, but even poor families today have more than one computer
           | at home. Indeed, every family member probably owns a
           | smartphone, which is way more powerful than the "family
           | computers" of decades past, and a quite capable Linux box if
           | rooted and paired with a Bluetooth keyboard. If you're a
           | burgeoning hardware hacker, a Raspberry Pi is a few tens of
           | dollars and a more than capable machine for that purpose.
        
             | [deleted]
        
             | wongarsu wrote:
             | For a teenager in a poor family, spending $60 on an Orange
             | Pi (good luck finding a Raspberry Pi for cheaper) with
             | power supply and keyboard is a substantial investment (and
             | that assumes you can get an old monitor for free from
             | somewhere, your family PC is likely a $300 laptop after
             | all)
             | 
             | SSHing into a VPS from the family computer is definitely a
             | lower barrier to entry. You can get dirt-cheap VPS for
             | $3/month, but this free offer is even cheaper and comes
             | without the hassle of payment methods (no explaining to
             | your parents why you need to use their credit card for
             | this).
        
               | MichaelCollins wrote:
               | Is dumpster diving for computers still viable? All the
               | computers, monitors, etc I had when I was a teen were
               | free, scavenged from dumpsters in commercial parks. Maybe
               | this supply has dried up now that the pace of hardware
               | obsolescence has slowed.
        
             | p4bl0 wrote:
             | I'm sorry, it's sad, but that's just not how it works. Even
             | "a few tens of dollars" is too much for some people, much
             | more than you can imagine. I teach at university and every
             | year I have students who never had a personal computer and
             | are still not able to afford one. And mind that this in
             | France (not your typical third-world country) and that I
             | teach _computer science_ ...
        
             | withinboredom wrote:
             | A pi is not simply "a few tens of dollars" as you also need
             | to buy a power supply, monitor/tv, keyboard, mouse, etc
        
               | MontyCarloHall wrote:
               | Those can also be had for tens of dollars. But my general
               | point was not about the Pi; it was that even poor teens
               | likely already have access to their own Linux-capable
               | machine.
        
             | baud147258 wrote:
             | you don't really need another computer, just a bootable USB
             | key with a Linux OS can be enough
        
         | surfsvammel wrote:
         | I might use this just for convenience if I need to test
         | something away from my home network.
        
           | nix23 wrote:
           | Exactly, if i want to test my pf firewall with "triggers"
           | then this is one way, test my IDS etc, and with installed
           | Kali everything is possible ;) just perfect!
           | 
           | Big Thanks to the Creators!!
        
         | imhoguy wrote:
         | `nmap` or pentesting from dedicated hosting or your home fiber
         | may lead to permban from your service provider. Here you can
         | experiment without much consequences.
        
       | cercatrova wrote:
       | You could use Firecracker VMs instead right?
        
       | userbinator wrote:
       | From the name I thought it would be something to do with DNS,
       | since that's the first thing that comes to mind when I see the
       | phrase "Root Servers".
        
         | usr1106 wrote:
         | A virtual root server is a cloud server giving you full access,
         | root in Linux. As opposed to some web page hosting thing. I
         | think has been mainstream for more than 10 years. DNS root
         | servers just work, nobody talks about them. Well, unless there
         | were a major incident some day.
        
           | runlaszlorun wrote:
           | aren't we talking about root servers here?
           | 
           | or just me...
        
             | [deleted]
        
         | LinuxBender wrote:
         | I've always known this as "root shell" vs. "root servers". I
         | too automatically think root DNS servers. I would love to
         | control the root servers.
        
       | dudeinjapan wrote:
       | "Well," said Pooh, "what I like best," and then he had to stop
       | and think. Because although Eating Honey was a very good thing to
       | do, there was a moment just before you began to eat it which was
       | better than when you were, but he didn't know what it was
       | called." - A. A. Milne
        
         | totetsu wrote:
         | Pooh was into Edge computing?
        
           | sva_ wrote:
           | I think he's into building the ultimate surveillance state
           | nowadays.
        
             | 867-5309 wrote:
             | full of honeypot IoT cams
        
       | joshxyz wrote:
       | interesting, anyone know if there's a docker image available of
       | that os with preinstalled hacking stuffs?
        
         | Veve wrote:
         | Yes there is: https://github.com/hackerschoice/segfault
        
       | hezag wrote:
       | About the creators: THC (The Hackers Choice) is a well known
       | hacker group active since 1995. One of their most famous project
       | is Hydra[0].                 > "We research and publish tools and
       | academic papers to expose fishy IT security that just isn't
       | secure. We also develop and publish tools to help the IT Security
       | movement."[1]
       | 
       | 0. https://en.wikipedia.org/wiki/Hydra_%28software%29
       | 
       | 1. https://www.thc.org/
        
         | noduerme wrote:
         | Not to piss in the honeypot here, but is there any assurance
         | this collective hasn't been co-opted in the last 25 years?
        
           | MichaelCollins wrote:
           | How could there possibly be assurance of that? People who get
           | coerced and turned into being informants don't go around
           | advertising it to everybody else.
           | 
           | Absolutely not, no assurance whatsoever.
        
       | Havoc wrote:
       | I hope it thrives. Not super optimistic given how even CI compute
       | gets abused for crypto mining...but hopeful
        
       | tony-allan wrote:
       | The Hacker's Choice -- Disposable Root Servers
       | 
       | https://www.thc.org/segfault/
       | 
       | Deploy your own...
       | 
       | https://github.com/hackerschoice/segfault
        
       | cyanydeez wrote:
       | Sounds like a public honeypot
        
         | tony-allan wrote:
         | You should always assume that for a service such as this and
         | proceed accordingly.
        
         | sally_glance wrote:
         | Here's hoping that this is deliberately obvious but also not
         | deliberately irresponsible...
        
         | [deleted]
        
       | IncRnd wrote:
       | From the article:                 Is it safe?       Nobody ever
       | got arrested for choosing segfault.net.
       | 
       | Take a close look at how that question isn't answered. It's best
       | not to do any work on these, where you need to trust the
       | platform. You might even get blamed for people's actions on their
       | box next to you.
       | 
       | Not much remains outside of this being a honeypot or for
       | criminals.
        
         | tony-allan wrote:
         | Of course, with no further information you should not use it
         | for real data production work but I'm fine with that
         | limitation.
        
           | IncRnd wrote:
           | The other part is that you may be liable for how others use
           | these boxes, just by your logging into one. It's not only
           | whether you use one at work.
        
             | MacsHeadroom wrote:
             | How is anyone going to know you, specifically, briefly
             | logged into an ephemeral VM over Tor?
        
               | IncRnd wrote:
               | I'll treat that as an idle question on the technical
               | aspects, not a question about how to evade law
               | enforcement.
               | 
               | There are people on this page talking about logging into
               | other services from there, so I think you can see one
               | very easy way.
               | 
               | If you use a service that says they don't track anything,
               | delete the machine upon logout, and so forth, who do you
               | think will use that box?
        
               | MacsHeadroom wrote:
               | I will; to perform port scanning and other
               | reconnaissance, to scrape data, and more. Nothing
               | connected to my identity in any way.
        
               | antonvs wrote:
               | I can't see the easy way you mentioned - could you
               | explain?
               | 
               | I agree that a target of interest could be located to
               | this service, but to correlate activity of two users
               | would seem to require detailed logs from the provider -
               | the logs they claim not to keep.
               | 
               | Also, by visiting a bank, there's a chance you could end
               | up being mistaken for a bank robber; or by jogging
               | through a neighborhood, there's a chance you could be
               | mistaken for a thief; etc. We don't usually give much
               | thought to these possibilities, although they do
               | sometimes happen. Is there any reason to treat this
               | differently?
        
               | woojoo666 wrote:
               | > There are people on this page talking about logging
               | into other services from there, so I think you can see
               | one very easy way.
               | 
               | I assume they are talking about logging into, say, your
               | email, and thus linking the box to you
        
               | jokethrowaway wrote:
               | It's like visiting a bank wearing a balaclava
               | 
               | Sure, it's perfectly reasonable from a privacy
               | perspective but it raises questions: I don't run around
               | showing my passport to everyone (except for my
               | authoritarian government) and yet I drive around with an
               | id that the authorities can link to my identity.
               | 
               | Don't get me wrong, I'm all for removing layers of
               | surveillance, but I will still assume tor users on my
               | website are either trying to hack it or have something to
               | hide from their government.
        
               | tenebrisalietum wrote:
               | A 100% valid non-clandestine use of Tor is to enable you
               | to receive incoming traffic without needing to port
               | forward or mess with firewall settings.
        
         | stavros wrote:
         | > It's best not to do any work on these, where you need to
         | trust the platform.
         | 
         | I don't mean to be snarky, but I don't think the target
         | audience for these servers trusts them one bit, and the
         | operators know this.
        
         | bcook wrote:
         | > Take a close look at how that question isn't answered.
         | 
         | I think that's the joke. I prefer this non-answer over a long-
         | winded bullshit answer that ultimately means nothing.
        
         | pvitz wrote:
         | This is a pun on the phrase "Nobody ever got fired for choosing
         | IBM". Don't read too much into it...
        
           | IncRnd wrote:
           | That's the thing. You might just end up with Big Blue coming
           | after you.
        
       | lpgauth wrote:
       | Pretty cool, useful if you need a SOCKS proxy to access blocked
       | services.
       | 
       | e.g. `ssh -v -D 30314 -q -C -N root@segfault.net`
        
       | tux wrote:
       | Interesting project thank you THC.
        
       | tomschwiha wrote:
       | Could you keep them permanently online if you circularly create
       | another server, that logs back into the first server? Just
       | wondering
        
       | derefr wrote:
       | > It shall be used for good purposes only.
       | 
       | So, uh... how do you (the creator of the service) know that,
       | without doing some sort of data tracking?
       | 
       | For that matter, how do you know that someone's not grabbing
       | 10,000 of these to run a botnet?
        
         | javajosh wrote:
         | "Good purpose" is ambiguous. Even if you start with a
         | "reasonableness standard" that is something like a "test
         | particle" that is white, male, raised in Minnesota to vaguely
         | Christian parents born in the 80's watched Sponge Bob
         | squarepants, it's less ambiguous. It means respecting the law,
         | including ones you don't agree with. Including the laws that
         | you think it would be good to break.
         | 
         | This server sits there as a perfect vehicle from which to break
         | the law. It's like someone leaving a fleet of getaway cars and
         | guns, with tips on which banks are loaded right now left on the
         | drivers side seat, and delivering it to a poor neighborhood,
         | where it is rational to accept higher risk for a higher reward.
         | 
         | There may be some who use it out of intellectual curiosity, and
         | who are careful not to run afoul of any laws. LEOs will be of
         | this type, I assume. I'm curious to know what is in that 8GB of
         | tools that is included in every shell, for example. So for me
         | the appeal would be a "safe" place to play with tools that I
         | may have concern about even installing myself and what lists
         | that adds me too. So in that sense its quite a good thing, it
         | is freeing from risk of state involvement if your
         | experiment/exploration goes wrong.
         | 
         | Presumably all serious hacking attempts originate from a remote
         | process anyway, as only a very silly/young/foolish hacker would
         | try certain tools from their actual home IP address and
         | personal laptop. So one argument for this service is that it
         | reduces the demand for (coerced) botnet nodes. If you squint
         | your eyes it's a similar argument for providing clean needles
         | and methodone to a community, no questions asked. No, it's ugly
         | that people use, but it's even uglier that people use and
         | reuse/share needles to avoid detection.
         | 
         | So while I agree it's probably a honeypot, there is also a
         | sound argument for it to exist, legitimately, as a public
         | service - a hacker's hamsterdam.
        
           | MichaelCollins wrote:
           | > _with tips on which banks are loaded right now left on the
           | drivers side seat_
           | 
           | I don't think they're going that far (it doesn't come with a
           | list of profitable organizations to hack.)
        
           | derefr wrote:
           | That wasn't really my point. It's clear from the feature-set
           | what people are intended to use the service for.
           | 
           | My point was -- without tracking users, how do you _ensure
           | quality of service_ for this system, when someone could just
           | generate 10k distinct SSH keys (= distinct  "accounts" in
           | this system) to run their botnet with, and so consume all
           | your resources with purely their traffic? (Where "a botnet"
           | here is just standing in as an example of a use-case that
           | requires as many nodes as possible, rather than being
           | satisfied with just one. Could be a distributed web scraper;
           | could be a crypto-mining pool; etc.)
           | 
           | If you're not requiring some kind of user registration that
           | does enough KYC to deduplicate registration attempts -- _and_
           | you 're not tracking usage with fine-enough granularity to be
           | able to surface + ban people who are "taking more than their
           | fair share" -- then this isn't going to be of benefit to the
           | entire hacker community, but rather the whole thing is going
           | to be gobbled up by the first person willing to write a
           | script to do so.
           | 
           | It's like making a large donation to a community in a war-
           | torn developing nation, where as soon as you leave, the whole
           | thing gets extracted out into the coffers of the largest
           | local warlord.
           | 
           | IMHO doing this model _correctly_ would necessitate something
           | closer to the  "a real person's going to manually verify your
           | sign-up" process of e.g.
           | https://www.nearlyfreespeech.net/signup/signup.
        
             | javajosh wrote:
             | Oh, well by misunderstanding your point I stumbled on what
             | is, IMHO, a more interesting point. In theory its
             | relatively straightforward to develop a "1 human per
             | process" heuristic for a service like this, especially if
             | you reserve the right to observe and interact with users at
             | any time (which this service certainly does).
        
               | derefr wrote:
               | Doing any interactive external observation would put a
               | lie to the claim that "all data & traces will get wiped"
               | -- since there would then be "traces" (in the sense of
               | "trace evidence" -- https://en.wikipedia.org/wiki/Locard%
               | 27s_exchange_principle) left on the sysadmin-observer's
               | workstation, that would have to be wiped in turn. (And
               | which are unlikely to be, because the sysadmin is likely
               | also the developer, and a DevOps workstation is usually
               | persistent.)
               | 
               | For that claim to actually be _true_ , the system has to
               | be hermetically sealed against outside observation by any
               | other than the user themselves. (Compare/contrast: the
               | claims of a few VPN service providers, that their service
               | is implemented effectively statelessly, in diskless +
               | memory-constrained ASICs on network switches, such that
               | there's no ability _even in theory_ for the machine
               | itself to keep metrics on which user accounts are
               | responsible for which kinds of upstream traffic flows;
               | such that a state actor who wanted to know that would be
               | stuck either replacing the hardware [and so extracting
               | the credential store out of the TPM of the original
               | hardware] or MITMing both sides of the VPN box and doing
               | traffic analysis to match flows.)
               | 
               | IMHO, it's probably very _unlikely_ that the claim is
               | true -- but it 's interesting and fun to try to threat-
               | model a service that _does_ try to make that guarantee.
               | 
               | Also, separately:
               | 
               | > In theory its relatively straightforward to develop a
               | "1 human per process" heuristic for a service like this
               | 
               | You're forgetting that these accounts aren't strictly
               | intended for use by humans, but rather scripting the
               | system is an accepted (and encouraged!) use-case. Which
               | means that you can't differentiate one user "botting" N
               | accounts, running the same script (presumably bannable);
               | from N users each "botting" their own single account by
               | using the same popular open-source script (perfectly
               | legitimate and protected!)
               | 
               | This, by the way, is the reason that most VPS providers
               | outright ban the deployment of certain types of software,
               | e.g. IRC bouncer bots: it's impossible to tell whether N
               | deployments of such a bot are N users intentionally
               | deploying the same open-source bot, or one user (with N
               | stolen user credentials) deploying a botnet that uses IRC
               | for command-and-control. So they just make the assumption
               | that such deployments are always malicious, and refuse
               | the business of anyone who has a non-malicious use-case
               | for such deployments.
        
         | MichaelCollins wrote:
         | Read that as a command or request, not a prediction.
        
       | guessmyname wrote:
       | I got excited for a moment reading the title thinking it was
       | referring to (disposable) DNS Root Servers, since that is the
       | only context in which I have heard about _"root servers"_ before.
        
         | silisili wrote:
         | Same. I'm guessing they're German, that's the only other times
         | I've seen the term 'root server' used this way.
        
           | justsomehnguy wrote:
           | > Since 1995 we have had 3 of our members arrested (0
           | convicted), we have had visits by the BKA (Germany's FBI) and
           | BND (Germany's NSA), we were blackmailed by the British GCHQ
           | and harassed and intimidated by many others
        
           | antonvs wrote:
           | I didn't realize that was a German thing - anyone who's done
           | much renting of bare metal servers is likely to have
           | encountered the term, but that seems to be because some of
           | the biggest global providers of those services are German,
           | like Hetzner and 1&1/Ionos.
        
         | salmo wrote:
         | A "root server" was a pre-cloud term for a rented server you
         | had root on vs a mortal user account. The latter was typically
         | for hosting a canned LAMP. Basically your own VM or physical
         | instead of a user on a shared machine or a limited-use VM.
         | 
         | There's a bunch of these comments. What would a disposable root
         | DNS server mean? Stand up a DNS server and just claim authority
         | for .?
         | 
         | You could do that here fine I imagine. You have root. Until you
         | log out, of course.
         | 
         | If you can install stuff and listen on 53, you could make your
         | own private DNS tree anywhere.
         | 
         | Now, managing delegations will get weird if you want to
         | delegate outside of what you manage. I'm seeing a spiderweb of
         | stub zones.
        
         | kiwijamo wrote:
         | That was my thought too. I wondered why one would need
         | disposable DNS Root Servers!
        
         | [deleted]
        
         | khanhquole wrote:
         | Yeah, that's what I thought too
        
         | dspillett wrote:
         | I've seen the term used to mean dedicated servers or VMs, by
         | European hosting companies. Possibly all German companies
         | though that might not be a solid memory, but it does seem quite
         | localised. I assume it is to differentiate between hosted
         | servers where you have an account, multiple accounts, or a
         | reseller account, but not full admin (root level) access.
         | 
         | Always stuck me as a clunky term, but it was where my head went
         | first on reading the title here (then I thought DNS servers,
         | but that did not compute so the first thought "won").
        
       | gertruded wrote:
       | Was wondering what the limits are on this service - turns out
       | they quite sensibly restrict the number of shells allowed per
       | source IP address. This script shows it starts refusing new SSH
       | sessions after a few connections back to itself:
       | #!/usr/bin/expect                  set timeout -1         spawn
       | torsocks ssh root@segfault.net         while (true) {
       | expect " password:"             send "segfault\n"
       | expect "\[~]"             send "gsocket -s NzdlMWQxNGQM ssh
       | root@segfault.net\n"             expect "t\])? "             send
       | "yes\n"         }
       | 
       | Eventually starts showing this in response:
       | [ERROR]         --> You (172.22.0.21) have to many servers
       | running         --> Read
       | https://www.thc.org/segfault/youcheapfuck         --> Contact us
       | on Telegram: https://t.me/thorg         Connection to 127.31.33.7
       | closed.
       | 
       | Also their Tor hidden service currently seems to be inaccessible.
       | Perhaps there's a hard limit on the number of connections via
       | that route, given that one can't restrict per any individual
       | source due to the design of Tor.
        
         | imhoguy wrote:
         | Over 20 years with Linux and I didn't `expect` to learn
         | something new in the shell today. Thanks!
        
       | sva_ wrote:
       | Interesting project.                 $ nmap -sn 10.11.0.0/24
       | Nmap done: 256 IP addresses (86 hosts up) scanned in 1.56 seconds
       | $ uname -srv       Linux 5.15.0-1011-aws #14-Ubuntu SMP Wed Jun 1
       | 20:54:22 UTC 2022
        
       | prmoustache wrote:
       | What does "root server" even means? The only context where I saw
       | servers being mentionned as root is in the domain name system.
       | These aren't.
        
         | [deleted]
        
         | [deleted]
        
         | MontyCarloHall wrote:
         | It means you have root access.
        
         | [deleted]
        
       | gz5 wrote:
       | > Reverse Port Forwards (forget ngrok. This is free & better).
       | 
       | i assume this means the 'disposable root server' can send
       | [whatever] encrypted data over the ssh tunnel to my machine (and
       | my network if the machine is not properly segmented)?
       | 
       | if so, what should i do to protect it?
        
         | Tepix wrote:
         | You can configure it (or not) the way you want it. It is not a
         | security issue by itself.
        
         | [deleted]
        
       | runlaszlorun wrote:
       | I've got a few beefy servers that are under fixed fee contracts
       | and are underutilized at the moment.
       | 
       | Anyone got an ideas on how I can support the cause?
        
       | imhoguy wrote:
       | If anyone worries it honeypot... well, you can self-host:
       | https://github.com/hackerschoice/segfault
        
       | efitz wrote:
       | Hahaha "free h4x0r servers with no logs" hahaha
       | 
       | That's exactly a thing the FBI would say.
       | 
       | They should name the service "honeypot.com".
        
         | antonvs wrote:
         | If I'm doing something the FBI won't care about, then it's just
         | a free resource. Woohoo
        
       | ComputerGuru wrote:
       | They've either been compromised or severely borked in an attempt
       | to fight abuse. The entire? image is now read-only, or at least
       | /tmp and the home directory both are. Their login script fails
       | and errors out about read-only filesystems and you can't do
       | anything useful with the machine without some extra hacking.
        
       | gnarbarian wrote:
       | honeypot
        
       | jetbalsa wrote:
       | Oh... these are inside a docker container... that sounds ripe for
       | a kernel privesc -- Also its not /real/ root :V
        
         | woodruffw wrote:
         | It looks like they bind the Docker socket into the guest
         | _controller_ [1], but maybe not the guest itself. But yeah:
         | unrestricted container root plus _any_ capabilities means that
         | they 're only one low-effort bug away from a container escape.
         | 
         | [1]:
         | https://github.com/hackerschoice/segfault/blob/main/docker-c...
        
           | coderintherye wrote:
           | Given how valuable 0-day container escape exploits are and
           | how knowledgeable the people are who host this, it would seem
           | to make sense economically to host this for free with the
           | explicit hope that someone does in fact escape and pwn the
           | box, assuming they can log enough to determine the method of
           | exploit and be able to reproduce it.
        
             | bigiain wrote:
             | Paranoid me wonders if this is run by law enforcement,
             | who've made the segfault.net owners/admins "an offer that
             | can't refuse"?
        
               | pinebox wrote:
               | That was my first thought. Shut down voluntarily in 2019
               | for no particular reason after 22 years? Mysteriously
               | back and even better? Doesn't pass the smell test.
               | 
               | The page talks a big game about hating criminals, but
               | these days if you don't put up a cookie banner RoboCop
               | will shoot you in the dick. And if someone _really_ isn
               | 't a criminal we've got a fix for that, too: Just ship
               | them to a country where they are!
               | 
               | On the other hand maybe this post-HSA, post-Snowden world
               | has made me jaded and the site really is just good clean
               | fun.
        
         | normaler wrote:
         | Better term would be disposable root shell. I am interested in
         | the networking part of it. How that is achieved.
        
           | kxrm wrote:
           | GitHub repo https://github.com/hackerschoice/segfault
           | 
           | Not sure if it covers your question though.
        
       | jedisct1 wrote:
       | Too bad all the DNS traffic just goes to Cloudflare instead of
       | using their own resolvers.
        
       | 1vuio0pswjnm7 wrote:
       | At first from the title I thought this was about DNS root
       | servers. Oh well. It got me thinking.
        
       | rexreed wrote:
       | What are the CPU bandwidth and storage limits?
        
         | imhoguy wrote:
         | Just "Enforcing Memory Limit to 64MB for the free service." on
         | telegram. Looks like they got HN hug of death.
        
           | dd_fan wrote:
        
       | chaz6 wrote:
       | This is a great development. Sadly there is no support for IPv6.
       | Hopefully that will come soon.
        
       | ctb_ wrote:
       | Own your own root, run it on your own machine or hardware.
        
       ___________________________________________________________________
       (page generated 2022-10-15 23:01 UTC)