Live data from Hacker News

Techcrunch hacked again

news.ycombinator.com

21–30 of 54 posts

Re: Techcrunch hacked again

#21
post #14
post #4

Earlier quoted context omitted.

That ad was planned before we were hacked, the timing was a total coincidence. Michael is out in Davos, Switzerland right now — he isn't masterminding an opportunistic ad campaign.

As long as you're here, do you have any details on the hack? Your only post about the attacks seems to be this one: http://www.techcrunch.com/2010/01/26/techcrunch-hacked/ Which hasn't been updated with details as promised. The lack of details here and the fact that you got hacked again makes it look either like you don't know how he got in, or that there were multiple vulnerabilities.

It seems as if the vulnerability is in Wordpress' rpc.php file.

http://www.wickedfire.com/shooting-shit/82271-shoemoney-com-...

Re: Techcrunch hacked again

#22
post #12

Earlier quoted context omitted.

That may be true, but unless you have some inside knowledge of the situation you can't know that.

They get hacked twice in a row, day after day has become the new routine. Someone there is totally doing their job you think?

Getting hacked twice in short time doesn't automatically mean incompetence. There could be literal dozens ways of entry - including all the third party javascript services they run. Also we don't even know if the attack was done using a 0day exploit.

A sign of incompetence would be if they had their whole database wiped out and they did'nt have any backup (ala codinghorror.com) or they got hacked exactly the same way 1 month from now.

Getting hacked 2 days in a row only means they couldn't find the weakness yet. 48 hours is not a long time. Twitter gets hacked more often than this.

They very well could be incompetent, but you are judging too soon.

Re: Techcrunch hacked again

#23
post #14

Earlier quoted context omitted.

As long as you're here, do you have any details on the hack? Your only post about the attacks seems to be this one: http://www.techcrunch.com/2010/01/26/techcrunch-hacked/ Which hasn't been updated with details as promised. The lack of details here and the fact that you got hacked again makes it look either like you don't know how he got in, or that there were multiple vulnerabilities.

It seems as if the vulnerability is in Wordpress' rpc.php file. http://www.wickedfire.com/shooting-shit/82271-shoemoney-com-...

Do we have anyone's word on that other than a semi-anonymous poster on a messageboard?

Re: Techcrunch hacked again

#24
post #20
post #16

Earlier quoted context omitted.

I absolutely dislike techcrunch, but the idea that they somehow took advantage of this situation and put up that ad it ludicrous. I can tell you from experience that interstitial ads are not done on the spot out of no where. They are high paying ad campaigns that is negotiated well in advance with (usually) only a single type of product/services. I don't visit techcrunch often (its actually hard-coded banned in my ho…

I have to disagree that this is out of the realm of possibility - TechCrunch's ad team is very creative and moves fast, and their inventory is IN DEMAND! They sold ads written on a WHITEBOARD shown on their streaming office cam for goodness sake. Nearly every modern ad serving platform allows for interstitials, so this is within the realm of imagination. But he didn't, so my crackpot theory is out the window. http://…

Interstitials ads are not the same thing as whiteboard ads. Like I said you just don't wake up one day and put them up within 24-48 hours.

Your theory is still a crackpot theory even if someone from TC didn't point it out. I doubt you have any IRL experience in selling online ad inventory.

Yes almost _all_ popular adservers allow interstitials, doesn't mean you see them all the time. Why? Because high paying inventory are only available in certain time of the year. Including, high-profile product launch and holiday shopping season.

Re: Techcrunch hacked again

#25
post #22

Earlier quoted context omitted.

They get hacked twice in a row, day after day has become the new routine. Someone there is totally doing their job you think?

Getting hacked twice in short time doesn't automatically mean incompetence. There could be literal dozens ways of entry - including all the third party javascript services they run. Also we don't even know if the attack was done using a 0day exploit. A sign of incompetence would be if they had their whole database wiped out and they did'nt have any backup (ala codinghorror.com) or they got hacked exactly the same way…

You've made some good points there. I must admit I agree. I'm being too hasty with my judgment here.

Re: Techcrunch hacked again

#26
post #8

Well since your submission is getting the upvotes... I went ahead and took a screen cap: http://imgur.com/koIso

Thats weird. I could have sworn there was a green 'share this' icon/link right below the hackers text. I was going to say maybe thats the source of the vulnerability.. its not in your screen cap though.

It is shown on the second screen cap. Why do you think it was the source of the vulnerability?

Re: Techcrunch hacked again

#28
At televised sporting events, a prankster, usually drunk, will sometimes run onto the field to make a spectacle. Yet, the broadcast always cuts away, so as not to encourage the behavior even more in the future.

Perhaps we could consider a similar policy on submissions and upvotes about site-defacements? The hack will already get plenty of attention from the normal visitors of the affected site, and coverage in other 'gotcha' outlets. Maybe we should dampen, rather than multiply, the coverage.

(A post-incident report with details of the vulnerability and valid countermeasures would be interesting. And if the normally-trusted site was at any point subverting visitors with malware, that too would warrant a warning submission. But racing to report and upvote each graffiti incident almost seems to be cheering it on.)

Re: Techcrunch hacked again

#29
post #22

Earlier quoted context omitted.

They get hacked twice in a row, day after day has become the new routine. Someone there is totally doing their job you think?

Getting hacked twice in short time doesn't automatically mean incompetence. There could be literal dozens ways of entry - including all the third party javascript services they run. Also we don't even know if the attack was done using a 0day exploit. A sign of incompetence would be if they had their whole database wiped out and they did'nt have any backup (ala codinghorror.com) or they got hacked exactly the same way…

>Twitter gets hacked more often than this. Really? I can remember only twice, in a bout a year, although admittedly I was not paying much attention

Re: Techcrunch hacked again

#30
post #22

Earlier quoted context omitted.

They get hacked twice in a row, day after day has become the new routine. Someone there is totally doing their job you think?

Getting hacked twice in short time doesn't automatically mean incompetence. There could be literal dozens ways of entry - including all the third party javascript services they run. Also we don't even know if the attack was done using a 0day exploit. A sign of incompetence would be if they had their whole database wiped out and they did'nt have any backup (ala codinghorror.com) or they got hacked exactly the same way…

Well I dont know whether have lost any data, but a link on the main page is broken - http://www.techcrunch.com/2010/01/26/ipad-touch-sensitive-ca...
Post reply on HN