Wikipedia was in read-only mode following mass admin account compromise
1–10 of 405 posts
Re: Wikipedia was in read-only mode following mass admin account compromise
#2Re: Wikipedia was in read-only mode following mass admin account compromise
#3"Закрываем проект" is Russian for "Closing the project"
Re: Wikipedia was in read-only mode following mass admin account compromise
#4Woah this looks like an old school XSS worm https://meta.wikimedia.org/wiki/Special:RecentChanges?hidebo...
I’ve always thought the fact that MediaWiki sometimes lets editors embed JavaScript could be dangerous.
Re: Wikipedia was in read-only mode following mass admin account compromise
#5Nice to see jQuery still getting used :)
Re: Wikipedia was in read-only mode following mass admin account compromise
#6[flagged]
Re: Wikipedia was in read-only mode following mass admin account compromise
#7[flagged]
"The Wikimedia Foundation, which operates Wikipedia, reported a total revenue of $185.4 million for the 2023–2024 fiscal year (ending June 2024). The majority of this funding comes from individual donations, with additional income from investments and the Wikimedia Enterprise commercial API service."
(Unless this was satire and I missed it)
Re: Wikipedia was in read-only mode following mass admin account compromise
#8Woah this looks like an old school XSS worm https://meta.wikimedia.org/wiki/Special:RecentChanges?hidebo... I’ve always thought the fact that MediaWiki sometimes lets editors embed JavaScript could be dangerous.
Also, I’m also surprised an XSS attack like hasn’t yet been actually used to harvest credentials like passwords through browser autofill[0].
It seems like the worm code/the replicated code only really attacks stuff on site. But leaking credentials (and obviously people reuse passwords across sites) could be sooo much worse.
Re: Wikipedia was in read-only mode following mass admin account compromise
#9Here before someone says that it's because MediaWiki is written in PHP.
Re: Wikipedia was in read-only mode following mass admin account compromise
#10[flagged]
[deleted]