Live data from Hacker News

Skype blog hacked

blogs.skype.com

21–30 of 61 posts

Re: Skype blog hacked

#21

I'm not sure why the accent on "Stop using MS, it's spying on you!" is on MS. AFAIK every company is using your data and giving/selling it to the government. How is MS more evil than anyone else?

Microsoft is responsible for spying on 90% of all users of an Desktop (or laptop) operating system.

Simply put, because of their market share, their evil has a bigger impact than other companies evil.

footnote: One is always completely free to decided if evil with more market share than other evils are more evil.

Re: Skype blog hacked

#22
post #14

Here is the screenshot of the blog hacked. http://imgur.com/RGeTFWV So it looks like Skype doesn't host on its own server. It looks like this is wordpress.com but with custom domain? curl http://blogs.skype.com -v EDIT Okay it is New to wpscan. When it says plugins found are these the vulnerable plugins wordpress.com running? https://gist.github.com/yeukhon/8211580 And I found the username 7 pretty interesting.... wo…

You will find those usernames whenever you scan wordpress.com with wpscan.

Re: Skype blog hacked

#23

Its Twitter account was also hacked and a message posted, but it appears to have been deleted. Screenshot here: https://twitter.com/MikeElgan/status/418482819611230208

Looks to be one of those auto posters (i.e. content posted on the blog is automatically pushed out to twitter, facebook, others)

Re: Skype blog hacked

#24
post #22
post #14

Here is the screenshot of the blog hacked. http://imgur.com/RGeTFWV So it looks like Skype doesn't host on its own server. It looks like this is wordpress.com but with custom domain? curl http://blogs.skype.com -v EDIT Okay it is New to wpscan. When it says plugins found are these the vulnerable plugins wordpress.com running? https://gist.github.com/yeukhon/8211580 And I found the username 7 pretty interesting.... wo…

You will find those usernames whenever you scan wordpress.com with wpscan.

Wow you are right about that.

just did it on another blog.wordpress.com. How come? On Skype's blog I can access /author/7 or /author/ian but I can't do it on another blog, I get "Oops".

Re: Skype blog hacked

#25
post #10

I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".

Not sure why you say that. WordPress.com offers 2-Factor Auth:

http://en.support.wordpress.com/security/two-step-authentica...

There are also tons of available security plugins & pretty extensive documentation on hardening a self-hosted install:

http://wordpress.org/plugins/tags/security http://codex.wordpress.org/Hardening_WordPress

Re: Skype blog hacked

#28
post #10

I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".

I doubt the purported "insecurity" of Wordpress has anything to do with this. Given that they simultaneously defaced a multitude of social media outlets for Skype, it seems fairly likely that they phished or compromised someone who managed social media accounts.

Re: Skype blog hacked

#30
post #23

Its Twitter account was also hacked and a message posted, but it appears to have been deleted. Screenshot here: https://twitter.com/MikeElgan/status/418482819611230208

Looks to be one of those auto posters (i.e. content posted on the blog is automatically pushed out to twitter, facebook, others)

I thought so as well, until https://twitter.com/Skype/statuses/4184954534710681
Post reply on HN