Live data from Hacker News

Tumblr hacked?

tumblr.com

21–24 of 24 posts

Re: Tumblr hacked?

#21
post #16

Earlier quoted context omitted.

What is your source for that info? Also, whether or not it cost the business money has nothing to do with the quality of the break-in.

Who cares about the quality or the skill it took? If it's an unskilled attack, it's even worse. If script kiddies can break into your site, your security is alarmingly poor. The things that matter during an attack: how much damage was caused, what kind of data was compromised, and how much it will cost to get things fixed. The quality of the attack is only a factor when it comes to cost/benefit of fixing the vulnerab…

My first comment actually addresses each of your points.

Re: Tumblr hacked?

#22
post #9

If you suspect a site has been compromised, wouldn't a better approach be to submit this as a text article explaining your reasons rather than linking to the affected site? Depending on the nature of the hack, the title could easily have been: Was Tumblr hacked in order to do drive-by malware installs? (tumblr.com) Now everyone who clicks is potentially at risk.

Thanks God I click on it while on Linux :)

It's a Javascript worm, your OS doesn't matter. (I think)

Re: Tumblr hacked?

#23
post #9

If you suspect a site has been compromised, wouldn't a better approach be to submit this as a text article explaining your reasons rather than linking to the affected site? Depending on the nature of the hack, the title could easily have been: Was Tumblr hacked in order to do drive-by malware installs? (tumblr.com) Now everyone who clicks is potentially at risk.

Thanks God I click on it while on Linux :)

Yes, Linux saves you from javascript malware.

Re: Tumblr hacked?

#24
post #5

Nothing particularly interesting seems to have actually happened. Some posts got onto the Dashboard, which was still running. In fact, everything was still working just fine. Script kiddies found a small crack and went for it.

"Script-kiddies" don't author exploits, or discover vulnerabilities.
Post reply on HN