
LinuxPPC challenge rides again 56
jacobm writes "According to an announcement on their site, AntiOnline is going to host the LinuxPPC challenge (crack an out-of-the-box LinuxPPC install and you can keep the computer), which was taken down a few weeks back because of bad guys doing mean things to LinuxPPC's network. Gentlemen, start your port scanners! "
Re:Scanning ports (Score:2)
TCP sequence predition in nmap estimates the difficulty of guessing these TCP sequence numbers. In some OSs, such as Windows, it's a fixed increment between packets, so trivially easy to guess. In Linux, apparently, "random positive increments" are used, making it extremely difficult to guess the TCP sequence, thus making it extremely difficult to successfully spoof a TCP connection.
I've read some on Bugtraq recently about other weird things in Linux that will allow you to get a more accurate guess of the sequence numbers on a host that's otherwise idle (i think the id field in the IP packet increments by one each time or something of that nature). However, it's still not nearly as easy as Windows.
For a much more in-depth discussion, read daemon9's IP-Spoofing Demystified [2600.net] (Phrack Issue 48, Phile 14).
Re:Whose telling the truth (Score:1)
Don't be too surprised. A lot of people don't find sites like packetstorm or antionline very interesting or even care about them all that much.
Scanning ports (Score:2)
This is not needed its been done alredy http://crack.linuxppc.org/nmap.results [linuxppc.org].d on't waste your time and bandwith
Antionline doesnt belong anywhere near slashdot (Score:1)
1)Antionline has censored links. This means that if a site they dont like (hackernews.com, packetstorm, to name a mere few) links to them, you cannot follow that link to them. And censorship of any kind is bad.
2)John Vranesevich is a criminal. Proof:
http://www.attrition.org/negation/www/ao.040.html
http://www.attrition.org/negation/www/ao.030.html
http://www.attrition.org/news/content/ken.letter
http://www.attrition.org/negation/special/
He's no better than CPM. Hi Carolyn!
3)JP is a media whore, he'll say and do absolutely anything to get in your email or browser, even if it involves outright lies and breaking the law.
Yeah, im ranting, and im sure that some of you will claim that because i'm an NCState student, my rants are biased. However, I'm merely disappointed that slashdot would support anything antionline does. Makes me wonder if Hemos has some sort of Faustian deal signed with antionline....
Shoutouts to Ken Williams for coming out on top through all the bullshit, and all the ehap kids, especially zeno & dox.
Re:Antionline doesnt belong anywhere near slashdot (Score:1)
just setting the record straight... im not even going to touch that other comment about JP being a good guy. that user@juno.com obviously couldnt hack his way out of a paperbag, much less know anything about the scene.
Re: AntiOnline (Score:1)
That is your opinion. My opinion is that the
site is a really horrible one. Neither of us
are right nor wrong.
"John V is a really good guy"
Again opinion, however after the PacketStorm
situation, I personally will not support anything
associated with his name.
The rest of your post is immature, childish, and
deserves no comment.
And if you are going ahead anyway... (Score:1)
Leilah
Re:wow (Score:2)
I guess you could alternate that with how to hack root, but that would be a matter of discovering a heretofore unknown rootshell exploit, which would require more resources than just crashing it.
"Start your portscanners" (Score:3)
I've often told people, if someone hacks your system and leaves you an obscene calling card, that was basicly a scriptkiddy who got lucky. A genuine, serious security cracker prefers to leave as little evidence as possible.
Flailing away at this thing from remote isn't just a waste of time, it's embarrasing.
If I had any interest in all in cracking this box, here's what I'd do.
If i didn't already have access to a powermac, I'd borrow or rent one, as similar as possible to the one being used.
I'd install linuxppc on it, staying as close to their known configuration as possible. if this is truly the default installation, that makes it much easier.
I'd hook it up on a private segment with some other systems, and hammer away on it where noone can see, where noone else is generating traffic, examining the system for different sorts of problems depending on what i did to it.
I'm sure eventually I'd find some way to at least cause the thing to die. It might take weeks, or days. Hard to say.
As soon as i was 100% certian I'd found a way to kill it, then and only then would i begin to attack the machine in question.
All this portscanning and flooding is just noise. Even if they do bring it down, they won't be able to reproduce it. In that respect, this is a pretty good PR stunt, given that linux is reasonably secure and stable.
Publicity Stunt (Score:2)
Hi JP!! (Score:1)
No offence, my man, but this is really pitiful. If you're going to reply to a
God, what a loser!
Sorry for the flamage, but, god, somebody had to do it!
--Andrew Grossman
grossdog@dartmouth.edu
AntiOnline? (Score:1)
I personally will be avoiding this challenge, mainly because of the people hosting it.
Re:Antionline?? (Score:1)
August 30
--
"11:55 CST: Hello! Anti-online is about to host a new machine you can try to crack into. Please also send us information on any tests you might have done on your machines you may have tried to break into."
The next tidbit is also nice
"12:00 CST: Microsoft posted stats today: 427,597 GET requests. Our stats:1,880,138 (and cron already rotated out the first few days, so it probably is closer to 2.5 million)"
Floris
Re:Anti-Online (Score:2)
Yep. I am sure that he is compiling a database of IP addresses from which attacks are being launched. Given his past behavior, I wouldn't be surprised to learn that this was the whole point of the exercise.
Kaa
Antionline?? (Score:3)
Kaa
Of course your IP is logged (Score:1)
Duh. Every time you view a web page on any host on any network your IP is being logged. Apache, IIS and every other Web server since the dawn of time tracks it.
AntiOnline & Hosting Anything (Score:1)
First, AntiOnline as others have mentioned has a nasty reputation. I'm sure that the IP of anyone even viewing a web page on a host in that network is logged.
Second, has anyone heard anything from the LinuxPPC folks confirming this? *I* certainly haven't, and as of the time of this posting, crack.linuxppc.org has no announcement about the box moving to AntiOnline's network. Until I see something offical from the LinuxPPC folks, I'm writing this off as another attempted publicity stunt by AntiOnline.
Re:Antionline?? (Score:1)
Yes, he did, and yes, he pretty much is in that category, as is his friend Carolyn Meinel.
The whole reason they host this stuff is so they get to see the attacks people use. You think they're just putting this box on the net with nothing between it and the pipe? Hah. They're packet sniffing, monitoring everything.
Why?
Well, so that in the off chance someone either writes his own exploit or gets ahold of a non-public one, and that person is stupid or naive enough to use it on them, they get to break the news, and claim the glory for it and use it themselves. Or better yet, have Carolyn write a book about it or turn the guy in to the FBI (which jaypee has said he will do and already has done, in fact, he's got an entire section of his website that is accessable only to law enforcement).
They (antionline) been doing a "contest" like this already, called happy hacker, for a while now. Its a scam, just like this is. The only thing you do by breaking into their machine is to give carolyn and jaypee knowledge that they didn't earn, and can't be trusted to use wisely.
I can't help feeling that the linuxppc folks got scammed. They probably didn't know who they were really dealing with.
Antionline, and the people who run it, are not to be trusted, folks. Jaypee has just enough of a clue to be dangerous, and carolyn, well, everything that one can say about her already has been said better than I can. Check out attrition.org's negation site [attrition.org] for a few examples.
ADenton (Score:1)
User Bio
I am a 36y/o in Georgia. I am a vice president for a rather large company. balh..blah..blah.. ADenton has posted 3 comments (this only counts the last few weeks)
1 Re:umm ok posted on Monday August 30, @08:41PM CDT (Score:1 Replies:1)
attached to LinuxPPC challenge rides again
2 Re:i can walk the walk posted on Monday August 30, @08:39PM CDT (Score:1)
attached to LinuxPPC challenge rides again
3 re: AntiOnline posted on Monday August 30, @06:32PM CDT (Score:1 Replies:4)
attached to LinuxPPC challenge rides again
Gee, I wonder who this could be??
"Subtle mind control? Why do all these HTML buttons say 'Submit' ?"
Re:Scanning ports (Score:1)
TCP Sequence Prediction: Class=random positive increments
Difficulty=3004658 (Good luck!)
because i have played with nmap for quite a while now and in all of my visits to the documentation i havent seen an explination for what TCP Sequence Prediction actualy is granted i might be missing the obvious but i would certanly apreciate somebody at least pointing me in the right direction
DO NOT DO THIS: The owner of AntiOnline is a nark (Score:1)
But then he later gives information about the hackers to the government. Whatever his incentive is, this guy is a total idiot and potentially dangerous.
I bet he's letting some government acency have full access to this LinuxPPC box's logs. The person who cracks the box will probably get noticed by the government.
And even if that's not true, why support an idiot like this?
Anti-Online (Score:1)
wow (Score:1)
As soon as i was 100% certian I'd found a way to kill it, then and only then would i begin to attack the machine in question. Apparently, I was mistaken on the "it," so I was wondering if someone could explain the "it" to a pitiful little ignorant person such as myself. Thank you. =)
AntiContest (Score:1)
Next, we'll see protesting sites publishing embarassing background and family histories of LinuxPPC coders.
This is kinda stupid (Score:1)
Cracking NT PWS contest # 70404939! (Score:1)
hack this dude's website and win a tshirt...
http://caffeinated.dynip.com
Not with a 10 foot pole (Score:1)
Anti* sucks.
Don't view their web page, you might be sued.
Don't try to hack the machine, you might be sued.
Oops, he might try to sue me for saying he sucks. Well, he blows too.
Linux Community? (Score:1)
Kspett
Crack the Linux PPC (Score:1)
Re:i can walk the walk (Score:1)
Re:umm ok (Score:1)
Re:Reply to delmoi (Score:1)
Re: reply to doomicon (Score:1)