[HN Gopher] Disposable Root Servers
___________________________________________________________________
Disposable Root Servers
Author : kxrm
Score : 312 points
Date : 2022-10-14 22:38 UTC (1 days ago)
(HTM) web link (blog.thc.org)
(TXT) w3m dump (blog.thc.org)
| levkk wrote:
| +--(rootsf-BrushFocus)-[~] +-# finger No one logged
| on.
|
| Where is everyone?
| [deleted]
| NoBreakfirst wrote:
| I'm not sure to follow.
|
| I don't see any TOS, at all.
|
| Anybody can seed whatever and run Tor exit node ? ( not that it
| would work well but still )
| mccorrinall wrote:
| When there are no tos defined, the tos is usually an implicit:
| don't abuse and don't be an asshole
| water-your-self wrote:
| Certainly this won't be abused
| [deleted]
| tony-allan wrote:
| "The Server only exists while you are logged in."
| tony-allan wrote:
| That's what their website says, however I had a play and
| created a file and logged in and out and the file persisted
| as did my ability to look at the /onion directory via Tor
| after the ssh session was stopped.
| geoffmcc wrote:
| I read somewhere on their site or in GitHub that files in
| the home directory are encrypted when you disconnect and
| when you connect again the encrypted file is restored and
| so you have files back. If you were to install a program
| with apt however when you log in again that will be gone.
| kxrm wrote:
| It does shutdown when you log out, the only persisted data
| in on /sec and /everyone
|
| Your home directory is in /sec/root.
|
| If you install tools outside of /sec/usr they will be reset
| on your next visit. So if you want to install something
| that survives a session log out you need to install to
| /sec/usr
| [deleted]
| tony-allan wrote:
| For me, this is a great testing and experimenting server with a
| fresh environment every time I use it.
|
| I often want test or observe something i'm doing from outside my
| environment... lynx https://news.ycombinator.com
| curl https://jsonplaceholder.typicode.com/todos/1
| xyzzy123 wrote:
| Smart way to get plausible deniability for your own grey zone
| activities.
|
| As a third party, of course absolutely experiment but don't rely
| on there being no logs, lol.
| bigiain wrote:
| The weaselworded non answer to "is it safe" is obviously
| technically true. Even if they've disclosed all activity and
| logs and user ip addresses to law enforcement, which resulted
| in hundreds of people going to jail, they went to jail for what
| they did with this, not for "using it"...
|
| It's a fun curiosity. But anyone relying on it to cover up
| illegal activity should be very very careful. If what you're
| doing can improve a cop's chance of promotion, you should
| assume they'll take advantage of that. And for "lesser crimes",
| you can bet that most things you want to do from there are
| already on blocklists. You'll have as much chance of getting
| your spam runs out of there as you do from any cheap vps or tor
| exit...
| tgsovlerkhgsel wrote:
| > Your server will self-destruct on log out (and all data &
| traces will get wiped).
|
| This does not seem to be entirely accurate (and it would also be
| very obnoxious, especially for use over Tor, if a dropped
| connection meant starting from scratch). The servers do allow
| reconnects, and data is preserved (presumably in encrypted form).
| bdcravens wrote:
| connection != session
| ghostly_s wrote:
| It does with ssh... maintaining a persistent session thru
| reconnect requires a wrapper utility like mosh.
| egberts1 wrote:
| Or tmux.
| sureglymop wrote:
| Pretty sure that mosh uses ssh initially and then the
| communication is over udp. Not sure if an ssh connection
| is even maintained then. Tmux I guess you would run
| locally and put in the background when you want to work
| on something else. But then your ssh connection could
| still drop or tmux could crash on your local machine.
| tony-allan wrote:
| I had a play and created a file and logged in and out and the
| file persisted as did my ability to look at the /onion
| directory via Tor after the ssh session was stopped.
| tony-allan wrote:
| The next morning, after being logged out overnight, I ssh'ed
| into the server and it had been reset (and my saved files
| removed).
|
| Credentials still worked but a fresh instance.
| ComputerGuru wrote:
| This is already being severely abused; system load jumped to 9.xx
| an hour ago and has stayed there.
| ghostly_s wrote:
| I don't see how it possibly could not be, seeing as they don't
| seem to have even made any effort to curtail it.
| floatinglotus wrote:
| I have a hard time understanding the target market for this.
|
| If you are so paranoid about your security and anonymity, why
| would you take promises made by a third party at face value?
|
| Why would you trust anyone or anything with an ounce of your
| identity?
| tgsovlerkhgsel wrote:
| Most places require payment, which is hard to do anonymously.
|
| Here, you don't have to take many promises at face value. You
| do have to assume that everything you do on that server is
| monitored if you don't trust it, but you can connect to it via
| Tor and/or a VPN.
| seba_dos1 wrote:
| This is a cute toy for hackers, not something that provides
| "security and anonymity".
| kxrm wrote:
| Agreed, I am not sure I understand the "how can you expect
| this to be secure" argument. I paid nothing, and it's
| sometimes fun to have a thing to play with that someone
| created. I am not using this to proxy a hack into Bank of
| America, nor am I storing my 20 page manifesto.
|
| If you do such a thing through here, you deserve whatever
| happens to you.
| [deleted]
| p4bl0 wrote:
| I can totally see the market for this. Imagine being a young
| person (let's say between 10 and 17), you read 2600 or
| something like it, you cannot pay for a server, you do not have
| your own Linux because the only family computer is running
| Windows and you're not an administrator on it. This is free and
| full of wonderful tools to try and explore.
| MontyCarloHall wrote:
| Seems like this situation would have been common 25 years
| ago, but even poor families today have more than one computer
| at home. Indeed, every family member probably owns a
| smartphone, which is way more powerful than the "family
| computers" of decades past, and a quite capable Linux box if
| rooted and paired with a Bluetooth keyboard. If you're a
| burgeoning hardware hacker, a Raspberry Pi is a few tens of
| dollars and a more than capable machine for that purpose.
| [deleted]
| wongarsu wrote:
| For a teenager in a poor family, spending $60 on an Orange
| Pi (good luck finding a Raspberry Pi for cheaper) with
| power supply and keyboard is a substantial investment (and
| that assumes you can get an old monitor for free from
| somewhere, your family PC is likely a $300 laptop after
| all)
|
| SSHing into a VPS from the family computer is definitely a
| lower barrier to entry. You can get dirt-cheap VPS for
| $3/month, but this free offer is even cheaper and comes
| without the hassle of payment methods (no explaining to
| your parents why you need to use their credit card for
| this).
| MichaelCollins wrote:
| Is dumpster diving for computers still viable? All the
| computers, monitors, etc I had when I was a teen were
| free, scavenged from dumpsters in commercial parks. Maybe
| this supply has dried up now that the pace of hardware
| obsolescence has slowed.
| p4bl0 wrote:
| I'm sorry, it's sad, but that's just not how it works. Even
| "a few tens of dollars" is too much for some people, much
| more than you can imagine. I teach at university and every
| year I have students who never had a personal computer and
| are still not able to afford one. And mind that this in
| France (not your typical third-world country) and that I
| teach _computer science_ ...
| withinboredom wrote:
| A pi is not simply "a few tens of dollars" as you also need
| to buy a power supply, monitor/tv, keyboard, mouse, etc
| MontyCarloHall wrote:
| Those can also be had for tens of dollars. But my general
| point was not about the Pi; it was that even poor teens
| likely already have access to their own Linux-capable
| machine.
| baud147258 wrote:
| you don't really need another computer, just a bootable USB
| key with a Linux OS can be enough
| surfsvammel wrote:
| I might use this just for convenience if I need to test
| something away from my home network.
| nix23 wrote:
| Exactly, if i want to test my pf firewall with "triggers"
| then this is one way, test my IDS etc, and with installed
| Kali everything is possible ;) just perfect!
|
| Big Thanks to the Creators!!
| imhoguy wrote:
| `nmap` or pentesting from dedicated hosting or your home fiber
| may lead to permban from your service provider. Here you can
| experiment without much consequences.
| cercatrova wrote:
| You could use Firecracker VMs instead right?
| userbinator wrote:
| From the name I thought it would be something to do with DNS,
| since that's the first thing that comes to mind when I see the
| phrase "Root Servers".
| usr1106 wrote:
| A virtual root server is a cloud server giving you full access,
| root in Linux. As opposed to some web page hosting thing. I
| think has been mainstream for more than 10 years. DNS root
| servers just work, nobody talks about them. Well, unless there
| were a major incident some day.
| runlaszlorun wrote:
| aren't we talking about root servers here?
|
| or just me...
| [deleted]
| LinuxBender wrote:
| I've always known this as "root shell" vs. "root servers". I
| too automatically think root DNS servers. I would love to
| control the root servers.
| dudeinjapan wrote:
| "Well," said Pooh, "what I like best," and then he had to stop
| and think. Because although Eating Honey was a very good thing to
| do, there was a moment just before you began to eat it which was
| better than when you were, but he didn't know what it was
| called." - A. A. Milne
| totetsu wrote:
| Pooh was into Edge computing?
| sva_ wrote:
| I think he's into building the ultimate surveillance state
| nowadays.
| 867-5309 wrote:
| full of honeypot IoT cams
| joshxyz wrote:
| interesting, anyone know if there's a docker image available of
| that os with preinstalled hacking stuffs?
| Veve wrote:
| Yes there is: https://github.com/hackerschoice/segfault
| hezag wrote:
| About the creators: THC (The Hackers Choice) is a well known
| hacker group active since 1995. One of their most famous project
| is Hydra[0]. > "We research and publish tools and
| academic papers to expose fishy IT security that just isn't
| secure. We also develop and publish tools to help the IT Security
| movement."[1]
|
| 0. https://en.wikipedia.org/wiki/Hydra_%28software%29
|
| 1. https://www.thc.org/
| noduerme wrote:
| Not to piss in the honeypot here, but is there any assurance
| this collective hasn't been co-opted in the last 25 years?
| MichaelCollins wrote:
| How could there possibly be assurance of that? People who get
| coerced and turned into being informants don't go around
| advertising it to everybody else.
|
| Absolutely not, no assurance whatsoever.
| Havoc wrote:
| I hope it thrives. Not super optimistic given how even CI compute
| gets abused for crypto mining...but hopeful
| tony-allan wrote:
| The Hacker's Choice -- Disposable Root Servers
|
| https://www.thc.org/segfault/
|
| Deploy your own...
|
| https://github.com/hackerschoice/segfault
| cyanydeez wrote:
| Sounds like a public honeypot
| tony-allan wrote:
| You should always assume that for a service such as this and
| proceed accordingly.
| sally_glance wrote:
| Here's hoping that this is deliberately obvious but also not
| deliberately irresponsible...
| [deleted]
| IncRnd wrote:
| From the article: Is it safe? Nobody ever
| got arrested for choosing segfault.net.
|
| Take a close look at how that question isn't answered. It's best
| not to do any work on these, where you need to trust the
| platform. You might even get blamed for people's actions on their
| box next to you.
|
| Not much remains outside of this being a honeypot or for
| criminals.
| tony-allan wrote:
| Of course, with no further information you should not use it
| for real data production work but I'm fine with that
| limitation.
| IncRnd wrote:
| The other part is that you may be liable for how others use
| these boxes, just by your logging into one. It's not only
| whether you use one at work.
| MacsHeadroom wrote:
| How is anyone going to know you, specifically, briefly
| logged into an ephemeral VM over Tor?
| IncRnd wrote:
| I'll treat that as an idle question on the technical
| aspects, not a question about how to evade law
| enforcement.
|
| There are people on this page talking about logging into
| other services from there, so I think you can see one
| very easy way.
|
| If you use a service that says they don't track anything,
| delete the machine upon logout, and so forth, who do you
| think will use that box?
| MacsHeadroom wrote:
| I will; to perform port scanning and other
| reconnaissance, to scrape data, and more. Nothing
| connected to my identity in any way.
| antonvs wrote:
| I can't see the easy way you mentioned - could you
| explain?
|
| I agree that a target of interest could be located to
| this service, but to correlate activity of two users
| would seem to require detailed logs from the provider -
| the logs they claim not to keep.
|
| Also, by visiting a bank, there's a chance you could end
| up being mistaken for a bank robber; or by jogging
| through a neighborhood, there's a chance you could be
| mistaken for a thief; etc. We don't usually give much
| thought to these possibilities, although they do
| sometimes happen. Is there any reason to treat this
| differently?
| woojoo666 wrote:
| > There are people on this page talking about logging
| into other services from there, so I think you can see
| one very easy way.
|
| I assume they are talking about logging into, say, your
| email, and thus linking the box to you
| jokethrowaway wrote:
| It's like visiting a bank wearing a balaclava
|
| Sure, it's perfectly reasonable from a privacy
| perspective but it raises questions: I don't run around
| showing my passport to everyone (except for my
| authoritarian government) and yet I drive around with an
| id that the authorities can link to my identity.
|
| Don't get me wrong, I'm all for removing layers of
| surveillance, but I will still assume tor users on my
| website are either trying to hack it or have something to
| hide from their government.
| tenebrisalietum wrote:
| A 100% valid non-clandestine use of Tor is to enable you
| to receive incoming traffic without needing to port
| forward or mess with firewall settings.
| stavros wrote:
| > It's best not to do any work on these, where you need to
| trust the platform.
|
| I don't mean to be snarky, but I don't think the target
| audience for these servers trusts them one bit, and the
| operators know this.
| bcook wrote:
| > Take a close look at how that question isn't answered.
|
| I think that's the joke. I prefer this non-answer over a long-
| winded bullshit answer that ultimately means nothing.
| pvitz wrote:
| This is a pun on the phrase "Nobody ever got fired for choosing
| IBM". Don't read too much into it...
| IncRnd wrote:
| That's the thing. You might just end up with Big Blue coming
| after you.
| lpgauth wrote:
| Pretty cool, useful if you need a SOCKS proxy to access blocked
| services.
|
| e.g. `ssh -v -D 30314 -q -C -N root@segfault.net`
| tux wrote:
| Interesting project thank you THC.
| tomschwiha wrote:
| Could you keep them permanently online if you circularly create
| another server, that logs back into the first server? Just
| wondering
| derefr wrote:
| > It shall be used for good purposes only.
|
| So, uh... how do you (the creator of the service) know that,
| without doing some sort of data tracking?
|
| For that matter, how do you know that someone's not grabbing
| 10,000 of these to run a botnet?
| javajosh wrote:
| "Good purpose" is ambiguous. Even if you start with a
| "reasonableness standard" that is something like a "test
| particle" that is white, male, raised in Minnesota to vaguely
| Christian parents born in the 80's watched Sponge Bob
| squarepants, it's less ambiguous. It means respecting the law,
| including ones you don't agree with. Including the laws that
| you think it would be good to break.
|
| This server sits there as a perfect vehicle from which to break
| the law. It's like someone leaving a fleet of getaway cars and
| guns, with tips on which banks are loaded right now left on the
| drivers side seat, and delivering it to a poor neighborhood,
| where it is rational to accept higher risk for a higher reward.
|
| There may be some who use it out of intellectual curiosity, and
| who are careful not to run afoul of any laws. LEOs will be of
| this type, I assume. I'm curious to know what is in that 8GB of
| tools that is included in every shell, for example. So for me
| the appeal would be a "safe" place to play with tools that I
| may have concern about even installing myself and what lists
| that adds me too. So in that sense its quite a good thing, it
| is freeing from risk of state involvement if your
| experiment/exploration goes wrong.
|
| Presumably all serious hacking attempts originate from a remote
| process anyway, as only a very silly/young/foolish hacker would
| try certain tools from their actual home IP address and
| personal laptop. So one argument for this service is that it
| reduces the demand for (coerced) botnet nodes. If you squint
| your eyes it's a similar argument for providing clean needles
| and methodone to a community, no questions asked. No, it's ugly
| that people use, but it's even uglier that people use and
| reuse/share needles to avoid detection.
|
| So while I agree it's probably a honeypot, there is also a
| sound argument for it to exist, legitimately, as a public
| service - a hacker's hamsterdam.
| MichaelCollins wrote:
| > _with tips on which banks are loaded right now left on the
| drivers side seat_
|
| I don't think they're going that far (it doesn't come with a
| list of profitable organizations to hack.)
| derefr wrote:
| That wasn't really my point. It's clear from the feature-set
| what people are intended to use the service for.
|
| My point was -- without tracking users, how do you _ensure
| quality of service_ for this system, when someone could just
| generate 10k distinct SSH keys (= distinct "accounts" in
| this system) to run their botnet with, and so consume all
| your resources with purely their traffic? (Where "a botnet"
| here is just standing in as an example of a use-case that
| requires as many nodes as possible, rather than being
| satisfied with just one. Could be a distributed web scraper;
| could be a crypto-mining pool; etc.)
|
| If you're not requiring some kind of user registration that
| does enough KYC to deduplicate registration attempts -- _and_
| you 're not tracking usage with fine-enough granularity to be
| able to surface + ban people who are "taking more than their
| fair share" -- then this isn't going to be of benefit to the
| entire hacker community, but rather the whole thing is going
| to be gobbled up by the first person willing to write a
| script to do so.
|
| It's like making a large donation to a community in a war-
| torn developing nation, where as soon as you leave, the whole
| thing gets extracted out into the coffers of the largest
| local warlord.
|
| IMHO doing this model _correctly_ would necessitate something
| closer to the "a real person's going to manually verify your
| sign-up" process of e.g.
| https://www.nearlyfreespeech.net/signup/signup.
| javajosh wrote:
| Oh, well by misunderstanding your point I stumbled on what
| is, IMHO, a more interesting point. In theory its
| relatively straightforward to develop a "1 human per
| process" heuristic for a service like this, especially if
| you reserve the right to observe and interact with users at
| any time (which this service certainly does).
| derefr wrote:
| Doing any interactive external observation would put a
| lie to the claim that "all data & traces will get wiped"
| -- since there would then be "traces" (in the sense of
| "trace evidence" -- https://en.wikipedia.org/wiki/Locard%
| 27s_exchange_principle) left on the sysadmin-observer's
| workstation, that would have to be wiped in turn. (And
| which are unlikely to be, because the sysadmin is likely
| also the developer, and a DevOps workstation is usually
| persistent.)
|
| For that claim to actually be _true_ , the system has to
| be hermetically sealed against outside observation by any
| other than the user themselves. (Compare/contrast: the
| claims of a few VPN service providers, that their service
| is implemented effectively statelessly, in diskless +
| memory-constrained ASICs on network switches, such that
| there's no ability _even in theory_ for the machine
| itself to keep metrics on which user accounts are
| responsible for which kinds of upstream traffic flows;
| such that a state actor who wanted to know that would be
| stuck either replacing the hardware [and so extracting
| the credential store out of the TPM of the original
| hardware] or MITMing both sides of the VPN box and doing
| traffic analysis to match flows.)
|
| IMHO, it's probably very _unlikely_ that the claim is
| true -- but it 's interesting and fun to try to threat-
| model a service that _does_ try to make that guarantee.
|
| Also, separately:
|
| > In theory its relatively straightforward to develop a
| "1 human per process" heuristic for a service like this
|
| You're forgetting that these accounts aren't strictly
| intended for use by humans, but rather scripting the
| system is an accepted (and encouraged!) use-case. Which
| means that you can't differentiate one user "botting" N
| accounts, running the same script (presumably bannable);
| from N users each "botting" their own single account by
| using the same popular open-source script (perfectly
| legitimate and protected!)
|
| This, by the way, is the reason that most VPS providers
| outright ban the deployment of certain types of software,
| e.g. IRC bouncer bots: it's impossible to tell whether N
| deployments of such a bot are N users intentionally
| deploying the same open-source bot, or one user (with N
| stolen user credentials) deploying a botnet that uses IRC
| for command-and-control. So they just make the assumption
| that such deployments are always malicious, and refuse
| the business of anyone who has a non-malicious use-case
| for such deployments.
| MichaelCollins wrote:
| Read that as a command or request, not a prediction.
| guessmyname wrote:
| I got excited for a moment reading the title thinking it was
| referring to (disposable) DNS Root Servers, since that is the
| only context in which I have heard about _"root servers"_ before.
| silisili wrote:
| Same. I'm guessing they're German, that's the only other times
| I've seen the term 'root server' used this way.
| justsomehnguy wrote:
| > Since 1995 we have had 3 of our members arrested (0
| convicted), we have had visits by the BKA (Germany's FBI) and
| BND (Germany's NSA), we were blackmailed by the British GCHQ
| and harassed and intimidated by many others
| antonvs wrote:
| I didn't realize that was a German thing - anyone who's done
| much renting of bare metal servers is likely to have
| encountered the term, but that seems to be because some of
| the biggest global providers of those services are German,
| like Hetzner and 1&1/Ionos.
| salmo wrote:
| A "root server" was a pre-cloud term for a rented server you
| had root on vs a mortal user account. The latter was typically
| for hosting a canned LAMP. Basically your own VM or physical
| instead of a user on a shared machine or a limited-use VM.
|
| There's a bunch of these comments. What would a disposable root
| DNS server mean? Stand up a DNS server and just claim authority
| for .?
|
| You could do that here fine I imagine. You have root. Until you
| log out, of course.
|
| If you can install stuff and listen on 53, you could make your
| own private DNS tree anywhere.
|
| Now, managing delegations will get weird if you want to
| delegate outside of what you manage. I'm seeing a spiderweb of
| stub zones.
| kiwijamo wrote:
| That was my thought too. I wondered why one would need
| disposable DNS Root Servers!
| [deleted]
| khanhquole wrote:
| Yeah, that's what I thought too
| dspillett wrote:
| I've seen the term used to mean dedicated servers or VMs, by
| European hosting companies. Possibly all German companies
| though that might not be a solid memory, but it does seem quite
| localised. I assume it is to differentiate between hosted
| servers where you have an account, multiple accounts, or a
| reseller account, but not full admin (root level) access.
|
| Always stuck me as a clunky term, but it was where my head went
| first on reading the title here (then I thought DNS servers,
| but that did not compute so the first thought "won").
| gertruded wrote:
| Was wondering what the limits are on this service - turns out
| they quite sensibly restrict the number of shells allowed per
| source IP address. This script shows it starts refusing new SSH
| sessions after a few connections back to itself:
| #!/usr/bin/expect set timeout -1 spawn
| torsocks ssh root@segfault.net while (true) {
| expect " password:" send "segfault\n"
| expect "\[~]" send "gsocket -s NzdlMWQxNGQM ssh
| root@segfault.net\n" expect "t\])? " send
| "yes\n" }
|
| Eventually starts showing this in response:
| [ERROR] --> You (172.22.0.21) have to many servers
| running --> Read
| https://www.thc.org/segfault/youcheapfuck --> Contact us
| on Telegram: https://t.me/thorg Connection to 127.31.33.7
| closed.
|
| Also their Tor hidden service currently seems to be inaccessible.
| Perhaps there's a hard limit on the number of connections via
| that route, given that one can't restrict per any individual
| source due to the design of Tor.
| imhoguy wrote:
| Over 20 years with Linux and I didn't `expect` to learn
| something new in the shell today. Thanks!
| sva_ wrote:
| Interesting project. $ nmap -sn 10.11.0.0/24
| Nmap done: 256 IP addresses (86 hosts up) scanned in 1.56 seconds
| $ uname -srv Linux 5.15.0-1011-aws #14-Ubuntu SMP Wed Jun 1
| 20:54:22 UTC 2022
| prmoustache wrote:
| What does "root server" even means? The only context where I saw
| servers being mentionned as root is in the domain name system.
| These aren't.
| [deleted]
| [deleted]
| MontyCarloHall wrote:
| It means you have root access.
| [deleted]
| gz5 wrote:
| > Reverse Port Forwards (forget ngrok. This is free & better).
|
| i assume this means the 'disposable root server' can send
| [whatever] encrypted data over the ssh tunnel to my machine (and
| my network if the machine is not properly segmented)?
|
| if so, what should i do to protect it?
| Tepix wrote:
| You can configure it (or not) the way you want it. It is not a
| security issue by itself.
| [deleted]
| runlaszlorun wrote:
| I've got a few beefy servers that are under fixed fee contracts
| and are underutilized at the moment.
|
| Anyone got an ideas on how I can support the cause?
| imhoguy wrote:
| If anyone worries it honeypot... well, you can self-host:
| https://github.com/hackerschoice/segfault
| efitz wrote:
| Hahaha "free h4x0r servers with no logs" hahaha
|
| That's exactly a thing the FBI would say.
|
| They should name the service "honeypot.com".
| antonvs wrote:
| If I'm doing something the FBI won't care about, then it's just
| a free resource. Woohoo
| ComputerGuru wrote:
| They've either been compromised or severely borked in an attempt
| to fight abuse. The entire? image is now read-only, or at least
| /tmp and the home directory both are. Their login script fails
| and errors out about read-only filesystems and you can't do
| anything useful with the machine without some extra hacking.
| gnarbarian wrote:
| honeypot
| jetbalsa wrote:
| Oh... these are inside a docker container... that sounds ripe for
| a kernel privesc -- Also its not /real/ root :V
| woodruffw wrote:
| It looks like they bind the Docker socket into the guest
| _controller_ [1], but maybe not the guest itself. But yeah:
| unrestricted container root plus _any_ capabilities means that
| they 're only one low-effort bug away from a container escape.
|
| [1]:
| https://github.com/hackerschoice/segfault/blob/main/docker-c...
| coderintherye wrote:
| Given how valuable 0-day container escape exploits are and
| how knowledgeable the people are who host this, it would seem
| to make sense economically to host this for free with the
| explicit hope that someone does in fact escape and pwn the
| box, assuming they can log enough to determine the method of
| exploit and be able to reproduce it.
| bigiain wrote:
| Paranoid me wonders if this is run by law enforcement,
| who've made the segfault.net owners/admins "an offer that
| can't refuse"?
| pinebox wrote:
| That was my first thought. Shut down voluntarily in 2019
| for no particular reason after 22 years? Mysteriously
| back and even better? Doesn't pass the smell test.
|
| The page talks a big game about hating criminals, but
| these days if you don't put up a cookie banner RoboCop
| will shoot you in the dick. And if someone _really_ isn
| 't a criminal we've got a fix for that, too: Just ship
| them to a country where they are!
|
| On the other hand maybe this post-HSA, post-Snowden world
| has made me jaded and the site really is just good clean
| fun.
| normaler wrote:
| Better term would be disposable root shell. I am interested in
| the networking part of it. How that is achieved.
| kxrm wrote:
| GitHub repo https://github.com/hackerschoice/segfault
|
| Not sure if it covers your question though.
| jedisct1 wrote:
| Too bad all the DNS traffic just goes to Cloudflare instead of
| using their own resolvers.
| 1vuio0pswjnm7 wrote:
| At first from the title I thought this was about DNS root
| servers. Oh well. It got me thinking.
| rexreed wrote:
| What are the CPU bandwidth and storage limits?
| imhoguy wrote:
| Just "Enforcing Memory Limit to 64MB for the free service." on
| telegram. Looks like they got HN hug of death.
| dd_fan wrote:
| chaz6 wrote:
| This is a great development. Sadly there is no support for IPv6.
| Hopefully that will come soon.
| ctb_ wrote:
| Own your own root, run it on your own machine or hardware.
___________________________________________________________________
(page generated 2022-10-15 23:01 UTC)