Skip to content

Comment on Exploitation of an old Rails vulnerabilityparent

Comments

This is a botnet being ran, at least in part, by hacking group HTP.

ryan is one of its lead members. Other evidence is the fact that "starfall.cu.cc" is one domain being used to grab this script: http://starfall.cu.cc/chips.txt

Starfall is another one of their members.

They're the people who breached Linode, MIT, nmap, and a few other places recently. See: http://www.exploit-db.com/papers/25306/

I'm surprised no one's thought of mass exploiting all those RoR servers months ago, unless those have all been there for months.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.