| Who | When |
Messages | |
|
|
|
|
|
20
|
 |
|
02-05-2005 07:12 PM ET (US)
|
|
Deleted by topic administrator 04-03-2005 09:14 PM
|
Richard Akerman
|
19
|
 |
|
10-26-2002 12:23 PM ET (US)
|
|
I think the main www.blogger.com and pro.blogger.com should have at least a pointer to information on status.blogger.com about the hack, and all users should be contacted.
Particular attention should be paid to the paying Pro customers.
|
| Former User
|
18
|
 |
|
10-26-2002 11:58 AM ET (US)
|
|
Why isn't there a notice on Blogger.com about the system being compromised? When I logged back into my account, there wasn't any information there, either. It's my impression that status.blogger.com is just for techies, and everyday users don't visit there. But Blogger has never let all users know about the status of ftp user account information as well as credit card info, seeing fit to sort of sweep this under the rug. It's disturbing how irresponsible they are.
|
lometogo
|
17
|
 |
|
10-26-2002 12:28 AM ET (US)
|
|
Blimey, I smell a goose
|
| Kris
|
16
|
 |
|
10-25-2002 04:58 PM ET (US)
|
|
Like Sept. 11th all over again?
Dude, what the fuck is wrong with you? How can you imagine that a fucking WEBSITE being hacked is in any fashion similar to a loss of life?
Idiot.
|
TimmyT
|
15
|
 |
|
10-25-2002 04:45 PM ET (US)
|
|
Edited by author 10-25-2002 05:06 PM
Will you be emailing users whose accounts were affected?
Better yet, email all users, letting them know if they were affected or not.
|
| Ev.
|
14
|
 |
|
10-25-2002 03:57 PM ET (US)
|
|
Yes, turns out things weren't nearly as bad as they looked. We're fairly confident, while the attack affected a lot of users (um...all), it was relatively trivial compared to what it could have been. All information like ftp servers, etc., is in a different database than the one compromised. And we had a backup of all the data that was changed within a couple hours.
Thanks.
|
Danny O'Brien
|
13
|
 |
|
10-25-2002 03:49 PM ET (US)
|
|
New update by EV at http://status.blogger.com/Update: We have found the cause of the vulnerability and have patched it. Everything is back restored and back online with the exception of the API server and bSTATS.
|
| |
Messages 12-10 deleted by topic administrator between 10-25-2002 02:01 PM and 10-25-2002 01:59 PM |
Tim Hardy
|
9
|
 |
|
10-25-2002 02:22 PM ET (US)
|
|
I suspect it's progressing by Blogger ID number since I am very far from being "a big name" but was an early Pro subscriber.
I managed to get in touch with Jason Shellen an hour ago who let me know that they were on the case.
One thing this has highlighted (for me) is the lack of obvious means to alert Pyra if such an event occurs. Automated help systems are hopeless in such circumstances.
|
| Lynsey
|
8
|
 |
|
10-25-2002 02:20 PM ET (US)
|
|
Edited by author 10-25-2002 02:20 PM
It would appear that Blogger's status page has now addressed the problem. http://status.blogger.com/
|
| Oxymo
|
7
|
 |
|
10-25-2002 01:56 PM ET (US)
|
|
This is like September the 11th all over again.
|
Danny O'Brien
|
6
|
 |
|
10-25-2002 01:10 PM ET (US)
|
|
To summarise Anil's findings: it seems to have hit a lot of the earliest bloggers first (indicating it may be progressing by Blogger ID number, or else they're going after the bigger names). If you can log on, you should probably remove your host server and ftp password from the Blogger database now.
There's no indication that this data is being used; but it seems a good precaution to take at this stage.
|
| Tom Coates
|
5
|
 |
|
10-25-2002 01:09 PM ET (US)
|
|
|
| Anil Dash
|
4
|
 |
|
10-25-2002 01:05 PM ET (US)
|
|
I've been tracking this for about half an hour, and Ev's aware of the problem now. Details here.
|
| Dug
|
3
|
 |
|
10-25-2002 01:05 PM ET (US)
|
|
From what I can tell - I can still publish. The field in the Blogger database that holds my blog URL is hacked - I Can't do a "View Web Page" within blogger. If I surf directly to my page it works fine.
I can't update the field from within blogger because of the "full DB" error.
|
incuBLOGula
|
2
|
 |
|
10-25-2002 12:53 PM ET (US)
|
|
We're not locked out, but our default home URL is changed to "hacx0redbyme", so we won't be publishing until we can change it, which we can't because the Blogger DB is full and won't allow it. What sux the most is the absence of any kind of info on status.blogger.com
|
Danny O'Brien
|
1
|
 |
|
10-25-2002 12:43 PM ET (US)
|
|
Hi. It'd be great if we could keep the discussion here to "operational announcements" and links to other, more reputable sources of info. No conjecture without a link to a source, please, no flaming about services or people, no elbows, ear-biting, or giant inflatable hamburgers.
Thanks!
|