QuickTopic (SM) free message boards QuickTopic (SM) free message boards
Skip to Messages
  Sign In to access your topic list  |New Topic |My Topics|Profile
Upgrade to Pro   Customize, show pictures, add an intro, and more:   QuickTopic Pro...and check out QuickThreadSM
Topic: blogger haxx0red?
Views: 5939, Unique: 3699 
Subscribers: 6
What's
this?
Printer-Friendly Page
Subscribe to get & post, or stop messages by email Subscribe
About these ads
Who | When
Messagessort recent-bottom   
Post a new message
 
   20
02-05-2005 07:12 PM ET (US)
Deleted by topic administrator 04-03-2005 09:14 PM
Richard AkermanPerson was signed in when posted  19
10-26-2002 12:23 PM ET (US)
I think the main www.blogger.com and pro.blogger.com should have at least a pointer to information on status.blogger.com about the hack, and all users should be contacted.

Particular attention should be paid to the paying Pro customers.
Former User  18
10-26-2002 11:58 AM ET (US)
Why isn't there a notice on Blogger.com about the system being compromised? When I logged back into my account, there wasn't any information there, either. It's my impression that status.blogger.com is just for techies, and everyday users don't visit there. But Blogger has never let all users know about the status of ftp user account information as well as credit card info, seeing fit to sort of sweep this under the rug. It's disturbing how irresponsible they are.
lometogoPerson was signed in when posted  17
10-26-2002 12:28 AM ET (US)
Blimey, I smell a goose
Kris  16
10-25-2002 04:58 PM ET (US)
Like Sept. 11th all over again?

Dude, what the fuck is wrong with you? How can you imagine that a fucking WEBSITE being hacked is in any fashion similar to a loss of life?

Idiot.
TimmyTPerson was signed in when posted  15
10-25-2002 04:45 PM ET (US)
Edited by author 10-25-2002 05:06 PM
Will you be emailing users whose accounts were affected?

Better yet, email all users, letting them know if they were affected or not.
Ev.  14
10-25-2002 03:57 PM ET (US)
Yes, turns out things weren't nearly as bad as they looked. We're fairly confident, while the attack affected a lot of users (um...all), it was relatively trivial compared to what it could have been. All information like ftp servers, etc., is in a different database than the one compromised. And we had a backup of all the data that was changed within a couple hours.

Thanks.
Danny O'BrienPerson was signed in when posted  13
10-25-2002 03:49 PM ET (US)
New update by EV at http://status.blogger.com/


Update: We have found the cause of the vulnerability and have patched it. Everything is back restored and back online with the exception of the API server and bSTATS.
 
Messages 12-10 deleted by topic administrator between 10-25-2002 02:01 PM and 10-25-2002 01:59 PM
Tim HardyPerson was signed in when posted  9
10-25-2002 02:22 PM ET (US)
I suspect it's progressing by Blogger ID number since I am very far from being "a big name" but was an early Pro subscriber.

I managed to get in touch with Jason Shellen an hour ago who let me know that they were on the case.

One thing this has highlighted (for me) is the lack of obvious means to alert Pyra if such an event occurs. Automated help systems are hopeless in such circumstances.
Lynsey  8
10-25-2002 02:20 PM ET (US)
Edited by author 10-25-2002 02:20 PM
It would appear that Blogger's status page has now addressed the problem. http://status.blogger.com/
Oxymo  7
10-25-2002 01:56 PM ET (US)
This is like September the 11th all over again.
Danny O'BrienPerson was signed in when posted  6
10-25-2002 01:10 PM ET (US)
To summarise Anil's findings: it seems to have hit a lot of the earliest bloggers first (indicating it may be progressing by Blogger ID number, or else they're going after the bigger names). If you can log on, you should probably remove your host server and ftp password from the Blogger database now.

There's no indication that this data is being used; but it seems a good precaution to take at this stage.
Tom Coates  5
10-25-2002 01:09 PM ET (US)
I've put up screen-caps of what I saw when I was logged into Blogger when the problems started happening at http://www.plasticbag.org/images/extra/hack.pdf, http://www.plasticbag.org/images/extra/hack2.pdf and http://www.plasticbag.org/images/extra/hack3.pdf
Anil Dash  4
10-25-2002 01:05 PM ET (US)
I've been tracking this for about half an hour, and Ev's aware of the problem now. Details here.
Dug  3
10-25-2002 01:05 PM ET (US)
From what I can tell - I can still publish. The field in the Blogger database that holds my blog URL is hacked - I Can't do a "View Web Page" within blogger. If I surf directly to my page it works fine.

I can't update the field from within blogger because of the "full DB" error.
incuBLOGulaPerson was signed in when posted  2
10-25-2002 12:53 PM ET (US)
We're not locked out, but our default home URL is changed to "hacx0redbyme", so we won't be publishing until we can change it, which we can't because the Blogger DB is full and won't allow it. What sux the most is the absence of any kind of info on status.blogger.com
Danny O'BrienPerson was signed in when posted  1
10-25-2002 12:43 PM ET (US)
Hi. It'd be great if we could keep the discussion here to "operational announcements" and links to other, more reputable sources of info. No conjecture without a link to a source, please, no flaming about services or people, no elbows, ear-biting, or giant inflatable hamburgers.

Thanks!
RSS link What's this?
QuickTopicSM message boards
Over 200,000 topics served
Learn more Frequently asked questions  Acknowledgements
What they're saying about QuickTopic
 Questions, comments, or suggestions? Contact Us
Read our use policy before beginning. We value your privacy; please read our privacy statement.
Copyright ©1999-2008 Internicity Inc. All rights reserved.