Comment on Exploitation of an old Rails vulnerabilityparentComments−meowface13yThis is a botnet being ran, at least in part, by hacking group HTP.ryan is one of its lead members. Other evidence is the fact that "starfall.cu.cc" is one domain being used to grab this script: http://starfall.cu.cc/chips.txtStarfall is another one of their members.They're the people who breached Linode, MIT, nmap, and a few other places recently. See: http://www.exploit-db.com/papers/25306/I'm surprised no one's thought of mass exploiting all those RoR servers months ago, unless those have all been there for months.
Comments
This is a botnet being ran, at least in part, by hacking group HTP.
ryan is one of its lead members. Other evidence is the fact that "starfall.cu.cc" is one domain being used to grab this script: http://starfall.cu.cc/chips.txt
Starfall is another one of their members.
They're the people who breached Linode, MIT, nmap, and a few other places recently. See: http://www.exploit-db.com/papers/25306/
I'm surprised no one's thought of mass exploiting all those RoR servers months ago, unless those have all been there for months.