wehavethewayout is running a f …

wehavethewayout is running a ftp server with anon logins allowed!

$ ftp
Connected to (
220 w2k1405 Microsoft FTP Service (Version 5.0).
Name ( ftp
331 Anonymous access allowed, send identity (e-mail name) as password.
230 Anonymous user logged in.
Remote system type is Windows_NT.

Earlier, the server also had “/bin/ls” available to download although that seems to have been removed now. To echo what Kevin says, it’s amazing how badly they misconfigured that box.

Even more evil thanks to Paul Jakma!

$ vncviewer
VNC server supports protocol version 3.3 (viewer 3.3)
Reading password failed

$ mysql -h
ERROR 1045: Access denied for user: 'docaoimh@' (Using password: NO)
$ mysql -u root -h
ERROR 1045: Access denied for user: 'root@' (Using password: NO)

By Donncha

Donncha Ó Caoimh is a software developer at Automattic and WordPress plugin developer. He posts photos at In Photos and can also be found on Twitter.

Leave a Reply