|
|
|
..and how would that be Ironic Alex?
Anonymous |
06.02.08 - 2:25 pm | #
|
|
It's ironic because Metasploit bills itself as an "Open-source platform for developing, testing, and using exploit code"
Too funny 
Steve |
Homepage |
06.02.08 - 2:51 pm | #
|
|
Yeah, what Steve said.
Incidentally, this was done through ARP poisoning
alex |
06.02.08 - 3:17 pm | #
|
|
Yup. Another customer on the same ISP was compromised and used to ARP poison all servers in that subnet. I corrected the problem by setting a static ARP entry and notifying the ISP. To make it very clear -- the metasploit.com servers were not compromised, nor have been to this date.
HD |
06.02.08 - 8:18 pm | #
|
|
Cool, thanks for that HD.
alex eckelberry |
06.02.08 - 8:59 pm | #
|
|
hmmmm I wounder if they should add an ARP poisoning module?
DM |
06.03.08 - 10:12 am | #
|
|
Stupid question, but if the server was not compromised, what was the ARP poison used for? If it wasn't used to capture credentials to the metasploit.com servers, was it just used to somehow redirect users to the compromised servers?
send9 |
06.04.08 - 9:58 am | #
|
|
It was just used to "deface" metasploit.com for glory -- we don't offer any non-encrypted authentication services anyways
HD |
06.04.08 - 11:38 am | #
|
|
DataCenters should use private VLAN for it customer and encrypt the traffic.
Dr.Death |
06.06.08 - 1:04 pm | #
|
|
thank you
sevgi |
06.20.08 - 10:30 am | #
|
|
bulshit your were hacked
john |
07.06.08 - 6:15 am | #
|
|
Actually, they owned the ARP entry that resolv to metasploit websites IP.
I would say that you must not trust binaries that have been downloaded during the attack and you should check hashes now.
If they owned the ARP entry, they could have mirrored the website, and compromised binaries.
Also setting static ARP in hist host might not be a solution, as the entry must be statically set in the ISP router to be really trusted…
Regards
cO2 |
Homepage |
07.18.08 - 6:59 pm | #
|
|
thank you
sohbet |
Homepage |
07.21.08 - 8:16 pm | #
|
|
hohoho
Hoopajoops LTD |
Homepage |
03.07.09 - 10:34 am | #
|
|
Another customer on the same ISP was compromised and used to ARP poison all servers in that subnet. I corrected the problem by setting a static ARP entry and notifying the ISP.
club penguin |
Homepage |
05.24.09 - 9:38 pm | #
|
|
Another customer on the same ISP was compromised and used to ARP poison all servers in that subnet. I corrected the problem by setting a static ARP entry and notifying the ISP.
classic video games |
Homepage |
10.31.09 - 8:58 pm | #
|
|
|
Commenting by HaloScan
|