Patched. Every single mail server, web server, shared server, virtual server, streaming server, monitoring server, and backup server on our network. Every single one. Protected.
Category Archives: Systems Administration
Target Hack Phishing email scores a 9.00!
I’m super impressed with this Phishing email. Its the best I’ve seen and if it weren’t for just a couple of easy-to-fix mistakes it would have scored a perfect 10.00!
Here’s the back story: Target was hacked early last month. That was big news that most people are aware of. My wife and I were even sent new credit cards as a result. But what you might not have heard of was the impressive level of phishing emails that are being sent out now targeting (heh, get it?) these customers. So read along and I’ll dissect this particularly good one using our Olympic, Sochi-style scoring. First, a screen shot of the original email:
WordCamp Albuquerque and an excellent retweet!

We had a great time at WordCamp Albuquerque yesterday. As with all good conferences we attended excellent sessions, and met some very bright and enterprising people. And a bonus! The attendees at my session didn’t seem to fall asleep, laughed a couple of times, and asked great questions.
If you’d like to see my presentation it can be viewed here (obviously minus the live crimescene hack discovery): http://prezi.com/wl2mypixdkgn
And again, a big thanks to @awhitehatter for his excellent hackery work and documentation, which made the talk much more lively.
Added post-conference bonus: I got a nice retweet from Matt Mullenweg (the founder of WordPress):

Hacked, defaced and damn happy about it!

Thanks to the excellent work of @awhitehatter this site was penetrated and defaced! I’ve never been so happy to be violated.
You can see his work here: http://hacked.brownrice.com (that’s a full copy of this blog from shortly after it was hacked)
Want to know how he did it? Well you’ll just have to come to my session at Wordcamp Albuquerque tomorrow to see all of the details. It’ll be fun and very informative!
And don’t bother and try to break into this site any more – its been cleaned and updated to the newest version of WordPress!
Exploited!
I just received an email from a clearly smart fellow who demonstrated a Cross-Site Scripting (XSS) exploit using a vulnerability in this blog. A user would need to be tricked into clicking on a specially crafted link which would eventually infect their computer with bad stuff. Our up-to-now nameless white-hat hacker has got $50 in the bag, but for my presentation I need this blog’s file system or database modified. A defacement. I’d wager he gets it done since it looks like this exploit could lead to code injection if crafted correctly. If so he’d get another $100, which is still up for grabs!
I’ll post the exploit tomorrow if our hacker gives permission.
Good stuff.
TWO days to get hacked! Cash reward offered!
Ok, its officially desperation time. I’ve reached out to good-guy (and girl) hackers to hack this blog for $100 plus a small amount of fame. If one of these “white-hats” don’t get it done by tomorrow I’ll go to the dark side. But I’m afraid of the dark side!
Update 3: Netsparker seems to be the tool of choice for these white-hat bounty hunters to get into this blog.
Update 2: Increased VPS RAM and CPU to handle the server scan and hack attempts! Yes!
Update: I’m seeing hack attempts! Keep up the good work fellas! Hack this thing!
THREE days. Where art thou hacker?
If no one shows up to hack this thing tonight I’m going to start trolling the dark side of the web with a cash incentive.
FOUR days to hack this blog!
Come on now hackers, what the heck? Just like a mother-in-law you tend to show up at the worst moments. And now, when I need you, nothing!
I might have to start offering up incentives to get this done…
If you haven’t been following along here is the back story.
This blog has seven days to get hacked
I’m speaking at Wordcamp Albuquerque 2013 a week from today. My session is called Hacked! How they hack it and how you clean it where I’ll dissect a real-life WordPress hack and show everyone how I suavely and bravely root out the hacker, sleuthily determine how he got into the site, and then kick him out and slam the door behind him.
However, there’s a problem. I figured there would certainly be a WordPress hack on one of our hosted customer sites between when I signed up for the talk a few months ago and now. I’ve waited and waited, and shockingly, all of our customers have listened to us and have been keeping up with their WordPress updates. So we haven’t had a single WordPress hack to clean up.
So I need this blog to get hacked. The sooner the better.
Oh, and to speed this thing along and I’ve reverted this blog’s WordPress code back to WordPress 3.0. This blog currently has more vulnerabilities than a president asking congress to approve a bombing on a mideast country.
I’ll update this blog and our twitter account with daily updates on my situation. Stay tuned. This could get interesting. Or embarrassing.
The best streaming rates in the World!
Quick update: We now have the best bandwidth prices for Web Camera Hosting, Live Streaming, and Video on Demand (VOD) services in the world.
Yep.
Best in the world.
Stream more, pay less.
See here for details: http://hosting.brownrice.com/web-camera-software