Live data from Hacker News

Tumblr hacked?

tumblr.com

11–20 of 24 posts

Re: Tumblr hacked?

#11
post #5

Nothing particularly interesting seems to have actually happened. Some posts got onto the Dashboard, which was still running. In fact, everything was still working just fine. Script kiddies found a small crack and went for it.

It's not really a script kiddie if it's an original exploit, and is still a vulnerability that has cost businesses money.

Re: Tumblr hacked?

#12

The exploit uses a "data-uri script tag" in the video embed field. In other words, it runs some sort of script through the section of the site that's supposed to only allow video embed codes from sites like YouTube and Vimeo. A pretty serious security hole.

Mind sharing where you found this info? Did you figure it out yourself?

Re: Tumblr hacked?

#13

Keeping an eye on this. The post in question looks like this: https://dl.dropbox.com/u/58607934/Screen%20Shot%202012-12-03... It has nailed a number of major accounts, including The Verge, USA Today, Reuters and The Daily Dot. Buzzfeed has tips on how to keep safe: http://www.buzzfeed.com/ryanhatesthis/hacker-group-exploits-... Update: The GNAA says that the hack was part of an anti-blogging campaign. > This was just…

At the bottom of the spam post it says if you delete the post it will delete your Tumblr account. Since this spreads by people viewing it, it's probably important to point out that deleting the posts will not delete your tumblr account, and you should do it immediately so people viewing your blog don't get infected themselves.

Re: Tumblr hacked?

#14
post #9

If you suspect a site has been compromised, wouldn't a better approach be to submit this as a text article explaining your reasons rather than linking to the affected site? Depending on the nature of the hack, the title could easily have been: Was Tumblr hacked in order to do drive-by malware installs? (tumblr.com) Now everyone who clicks is potentially at risk.

Agreed!

TNW Article: http://thenextweb.com/insider/2012/12/03/a-worm-is-hijacking...

Re: Tumblr hacked?

#15

The exploit uses a "data-uri script tag" in the video embed field. In other words, it runs some sort of script through the section of the site that's supposed to only allow video embed codes from sites like YouTube and Vimeo. A pretty serious security hole.

Mind sharing where you found this info? Did you figure it out yourself?

See point #10 from http://www.buzzfeed.com/ryanhatesthis/hacker-group-exploits-...

Re: Tumblr hacked?

#16
post #11
post #5

Nothing particularly interesting seems to have actually happened. Some posts got onto the Dashboard, which was still running. In fact, everything was still working just fine. Script kiddies found a small crack and went for it.

It's not really a script kiddie if it's an original exploit, and is still a vulnerability that has cost businesses money.

What is your source for that info?

Also, whether or not it cost the business money has nothing to do with the quality of the break-in.

Re: Tumblr hacked?

#18
post #9

If you suspect a site has been compromised, wouldn't a better approach be to submit this as a text article explaining your reasons rather than linking to the affected site? Depending on the nature of the hack, the title could easily have been: Was Tumblr hacked in order to do drive-by malware installs? (tumblr.com) Now everyone who clicks is potentially at risk.

Thanks God I click on it while on Linux :)

Re: Tumblr hacked?

#19
post #16
post #11

Earlier quoted context omitted.

It's not really a script kiddie if it's an original exploit, and is still a vulnerability that has cost businesses money.

What is your source for that info? Also, whether or not it cost the business money has nothing to do with the quality of the break-in.

Who cares about the quality or the skill it took? If it's an unskilled attack, it's even worse. If script kiddies can break into your site, your security is alarmingly poor.

The things that matter during an attack: how much damage was caused, what kind of data was compromised, and how much it will cost to get things fixed. The quality of the attack is only a factor when it comes to cost/benefit of fixing the vulnerability.

Post reply on HN