Live data from Hacker News

Techcrunch hacked again

news.ycombinator.com

51–54 of 54 posts

Re: Techcrunch hacked again

#51

My two cents: I guess they were using xmlrpc to post to the blog. The incutio xmlrpc library (or rather the metaweblog api which wordpress uses) requires that you send the username and password in the clear, so a man in the middle could easily gain access to their wordpress install.

I think a bigger problem is that they didn't separate the posting accounts from the admin accounts. Otherwise, the only damage that could have been incurred is to mess with posts.

Re: Techcrunch hacked again

#53
post #4
post #3

You do have to hand it to Arrington to run an interstitial welcome.html ad on there today based on the volume of traffic coming in to check out the hacking story . . .

That ad was planned before we were hacked, the timing was a total coincidence. Michael is out in Davos, Switzerland right now — he isn't masterminding an opportunistic ad campaign.

I gotta tell you, that interstitial is pretty poorly implemented anyways (was?).

Any time I try to visit a link to TC now, the interstitial comes up and then sends me to the front page. I'm not going to dig through to figure out where the actual content lives. Although, I've already dealt with the ads, so maybe it doesn't really matter.

Re: Techcrunch hacked again

#54
Eventually, the hacker got 'hacked' by the media. Amusing. Should he be remembered, he'll be 'the guy who wanted to promote his porn site'. Side effects, the new ad campaign benefits from the traffic peak and Techcrunch gains visibility. I suspect the kid behind the hack is actually working FOR techcrunch ;)
Post reply on HN